Core Cybersecurity Concepts Explained: CIA Triad, CISSP Domains, NIST CSF/RMF and OWASP Top 10
Four ideas that keep appearing in cybersecurity study and job interviews, explained in plain English. Each part has a definition, analogy, step-by-step, example, defences, how it appears in the Google Cybersecurity Certificate, exam-style questions and five further-learning links.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations, examples and questions are original. Confirm current course content on the official Coursera page.
How the four fit together
| Topic | What it is | Use it to |
|---|---|---|
| CIA triad | Three security goals | Describe what an incident or control affects |
| CISSP 8 domains | A map of the security profession | See the whole field and plan study or career steps |
| NIST CSF and RMF | A risk framework and an approval process | Organise a security programme and manage system risk |
| OWASP Top 10 | Top web application risks | Find and fix common web flaws |
Part 1: CIA triad explained
CIA triad explained: tap to open or close
1. Definition
The CIA triad is a model built on three security goals: confidentiality, integrity and availability. Almost every control, risk and incident can be described by which of these goals it protects or damages.
| Goal | Key question | Typical threats | Typical controls |
|---|---|---|---|
| Confidentiality | Can only the right people see it? | Data breach, shoulder surfing, phishing | Encryption, access control, MFA, data classification |
| Integrity | Is it accurate and unaltered? | Tampering, malware, accidental edits | Hashing, digital signatures, change control, audit logs |
| Availability | Can authorised people use it when needed? | Ransomware, DDoS, hardware failure | Backups, redundancy, patching, DDoS protection |
2. Real-world analogy
Think of a bank. The locked vault and ID checks are confidentiality. Tamper-evident sealed bags that show if anything was changed are integrity. Opening hours, backup generators and a second branch are availability. A bank that fails any one of the three is not doing its job.
3. How it works, step by step
- Identify the asset, such as customer records, a website or a payroll system.
- Rank the goals. A public news site cares most about availability and integrity; a medical file cares most about confidentiality.
- List threats to each goal.
- Choose controls that reduce those threats (technical, physical and administrative).
- Test and monitor with logs, audits and drills.
- Review after changes or incidents, because trade-offs shift over time.
Trade-offs: stricter access improves confidentiality but can slow people down, which hurts availability. Good security balances all three.
4. Real-world example: a hospital
- Confidentiality fails: a staff member’s stolen password lets an attacker read patient files.
- Integrity fails: someone changes a drug allergy in a record, so a nurse acts on wrong information.
- Availability fails: ransomware locks the system and doctors cannot reach records during emergencies.
One organisation, three different kinds of harm, which is why teams plan for all three.
5. How to defend and apply it
- Least privilege: give people only the access they need.
- MFA and strong passwords protect accounts.
- Encrypt data in transit and at rest.
- Check integrity with hashes and keep audit logs.
- Back up regularly and test restores; keep a copy offline.
- Patch and monitor systems; plan for outages.
- Use it when reading an incident: ask “which of C, I or A was affected?” before deciding severity.
6. How it appears in the Google Cybersecurity Certificate
The triad is one of the foundational ideas of the programme and mainly appears in the early risk and security frameworks material, then keeps returning in assets, incident response and interview scenarios. Course titles and ordering can change, so check the official syllabus.
- Classifying threats and controls by the goal they affect.
- Explaining incidents in plain language to managers.
- Pairing with frameworks such as the NIST CSF.
7. Common exam-style questions (tap to reveal)
Q1. A ransomware attack encrypts files so staff cannot open them. Which goal is hit most directly?
Availability. Confidentiality may also be affected if data was stolen first.
Q2. Which control best supports integrity?
Hashing or digital signatures, because they reveal unauthorised changes.
Q3. Name two controls for confidentiality.
Encryption and access control (also MFA or data classification).
Q4. Why can improving one goal harm another?
Extra restrictions or checks can slow or block legitimate users, reducing availability.
Q5. An employee accidentally edits a shared payroll sheet. Which goal is affected?
Integrity, since the data is no longer accurate. It is a threat even without malicious intent.
8. Further learning (5 links)
- NIST Cybersecurity Framework – how the triad fits a full framework
- NIST Computer Security Resource Center glossary – official definitions
- CISA cybersecurity best practices – practical guidance
- UK NCSC guidance – clear, plain-English advice
- CIS Controls – prioritised defensive actions
YouTube searches
Part 2: CISSP 8 domains explained
CISSP 8 domains explained: tap to open or close
1. Definition
The CISSP is a respected security certification from ISC2, and its exam content is organised into eight domains that together describe the breadth of a security career. Learning the domains gives beginners a map of the whole field, even before they plan to sit the exam.
See ISC2’s CISSP page for current requirements and exam details.
2. Real-world analogy
Picture a city. It needs a council and rules (domain 1), a register of what it owns (2), sound buildings (3), roads and communications (4), ID and keys for residents (5), inspectors (6), an emergency service (7) and safe construction rules (8). Security works the same way: many departments, one goal.
3. The eight domains, step by step
| # | Domain | Plain meaning | Examples |
|---|---|---|---|
| 1 | Security and Risk Management | Policies, law, ethics and risk decisions | Risk assessments, compliance, business continuity |
| 2 | Asset Security | Know and protect your data and devices | Classification, retention, disposal |
| 3 | Security Architecture and Engineering | Design systems securely | Cryptography, secure design, physical security |
| 4 | Communication and Network Security | Protect data moving across networks | Firewalls, VPNs, secure protocols |
| 5 | Identity and Access Management | Control who can do what | MFA, roles, single sign-on |
| 6 | Security Assessment and Testing | Check that controls work | Audits, vulnerability scans, penetration tests |
| 7 | Security Operations | Run security day to day | Monitoring, incident response, backups, recovery |
| 8 | Software Development Security | Build safe software | Secure coding, code review, testing |
Using the map: note which domains your current or past work touches, then spot gaps to study.
4. Real-world example: one phishing incident
- Domain 5: a stolen password is used; MFA would have helped.
- Domain 4: traffic to a malicious site is blocked.
- Domain 7: analysts detect, contain and recover.
- Domain 1: management decides on reporting duties.
- Domain 6: a later test checks the fix.
A single event touches several domains, which is why the map matters.
5. How to apply it
- As a study plan: cover one domain per week with notes and practice questions.
- As a career map: SOC work leans on domain 7; GRC on 1; engineering on 3 and 4; application security on 8.
- Pathway: the Google certificate, then a certificate such as Security+ or ISC2 Certified in Cybersecurity, then experience. CISSP requires several years of relevant work experience, so check ISC2 for current rules, including the associate route.
6. How it appears in the Google Cybersecurity Certificate
The programme introduces security domains early, in its risk-management material, and uses them to show how roles differ. Its labs and tools line up with several domains: Linux and networks (3, 4), access control (5), SIEM and incident response (7) and Python automation (8). Check the official syllabus for current wording.
7. Common exam-style questions (tap to reveal)
Q1. How many CISSP domains are there?
Eight.
Q2. Which domain covers MFA and role-based access?
Identity and Access Management (domain 5).
Q3. A penetration test mainly belongs to which domain?
Security Assessment and Testing (domain 6).
Q4. Which domain includes incident response and backups?
Security Operations (domain 7).
Q5. Is CISSP an entry-level certificate?
No. It is aimed at experienced professionals, but beginners can use the domains as a learning map.
8. Further learning (5 links)
- ISC2 CISSP overview – official requirements
- ISC2 Certified in Cybersecurity – entry-level option
- ISC2 home – study and community resources
- NIST Cybersecurity Framework – a companion framework
- CISA – government guidance and alerts
YouTube searches
Part 3: NIST CSF and RMF explained
NIST CSF and RMF explained: tap to open or close
1. Definition
The NIST Cybersecurity Framework (CSF) is a flexible set of outcomes that helps organisations understand and improve how they manage cyber risk. The NIST Risk Management Framework (RMF) is a step-by-step process for selecting, applying and approving security controls for a specific system.
Both come from the US National Institute of Standards and Technology. Start at NIST’s CSF page.
2. Real-world analogy
The CSF is like a checklist of areas every healthy business must cover: planning, knowing what you own, protection, alarms, emergency response and repair. The RMF is like the permit process for one building: classify it, choose safety features, build them, inspect, sign off, and keep inspecting.
3. How it works, step by step
CSF 2.0 functions (published 2024)
| Function | Question it answers | Example |
|---|---|---|
| Govern | Who decides and how is risk managed? | Policies, roles, risk appetite |
| Identify | What do we have and what could go wrong? | Asset inventory, risk assessment |
| Protect | How do we reduce the chance of harm? | MFA, patching, training |
| Detect | How do we notice problems? | Logging, SIEM alerts |
| Respond | What do we do during an incident? | Playbooks, escalation |
| Recover | How do we return to normal? | Backups, restoration, lessons learned |
Older versions (1.1) had five functions without Govern, so some training material still shows five.
RMF steps
- Prepare roles, priorities and context.
- Categorize the system by impact (low, moderate, high).
- Select controls, usually from NIST SP 800-53.
- Implement them and document how.
- Assess whether they work.
- Authorize: a leader accepts the remaining risk.
- Monitor continuously and repeat when things change.
4. Real-world example: a small clinic
- CSF view: the clinic has no inventory (Identify), staff share passwords (Protect), nobody reviews logs (Detect) and there is no ransomware plan (Respond, Recover). A leader assigns ownership (Govern).
- RMF view: for its new patient portal, the clinic rates data impact as high, selects controls such as MFA and encryption, tests them, gets sign-off, then monitors.
5. How to defend and apply it
- Use the CSF as a health check: rate each function and pick the weakest to improve.
- Use profiles to compare where you are with where you want to be.
- Use the RMF when a system needs formal approval, common in government and regulated work.
- Match incidents to functions: a missed alert is a Detect gap; slow restoration is Recover.
- Document everything: frameworks reward evidence.
6. How it appears in the Google Cybersecurity Certificate
The programme teaches the CSF and the RMF in its risk-management and frameworks material, then reuses their ideas in incident response and escalation. The course may show the five-function version; know both. Check the official syllabus for current wording.
7. Common exam-style questions (tap to reveal)
Q1. Name the six CSF 2.0 functions.
Govern, Identify, Protect, Detect, Respond, Recover.
Q2. Which function does a SIEM alert mainly support?
Detect.
Q3. What is the first RMF step?
Prepare.
Q4. Is the CSF a law?
No. It is voluntary guidance, though some rules or contracts may require using it.
Q5. What does Authorize mean in the RMF?
A responsible official formally accepts the remaining risk and allows the system to operate.
8. Further learning (5 links)
- NIST Cybersecurity Framework – CSF 2.0 and resources
- NIST RMF overview – official RMF page
- NIST SP 800-53 Rev. 5 – control catalogue
- NIST SP 800-37 Rev. 2 – RMF guide
- CISA – practical advice and alerts
YouTube searches
Part 4: OWASP Top 10 explained
OWASP Top 10 explained: tap to open or close
1. Definition
The OWASP Top 10 is a community-built awareness list of the most critical security risks to web applications, published by the Open Worldwide Application Security Project. It is updated every few years, and the 2025 edition is the latest at the time of writing.
Read the official list at owasp.org/Top10. Older material often shows the 2021 edition, so expect small differences.
2. Real-world analogy
Imagine building inspectors publishing a “top ten most common defects” list: unlocked doors, faulty wiring, rotten supplies. Builders who fix those first prevent most problems. The Top 10 does the same for web apps.
3. The ten risks, step by step
| # | Risk (2025) | Plain meaning | Main defence |
|---|---|---|---|
| A01 | Broken Access Control | Users can reach data or actions they should not | Server-side permission checks, deny by default |
| A02 | Security Misconfiguration | Unsafe settings, default accounts, open services | Hardened baselines, regular reviews |
| A03 | Software Supply Chain Failures | Compromised libraries, build tools or updates | Dependency tracking, trusted sources, signing |
| A04 | Cryptographic Failures | Weak or missing encryption | Modern algorithms, TLS, good key handling |
| A05 | Injection | Untrusted input treated as commands (e.g. SQL) | Parameterised queries, input validation |
| A06 | Insecure Design | Flaws in the plan, not just the code | Threat modelling, secure design patterns |
| A07 | Authentication Failures | Weak logins, session problems | MFA, rate limiting, secure sessions |
| A08 | Software or Data Integrity Failures | Trusting unverified code or data | Signature checks, protected pipelines |
| A09 | Security Logging and Alerting Failures | Attacks go unnoticed | Useful logs, alerts, review |
| A10 | Mishandling of Exceptional Conditions | Errors and odd states handled unsafely | Safe error handling, fail closed, testing |
Using it: review your app against each row, fix the highest-impact gaps, then retest.
4. Real-world example: changing a number in a URL
A shopper views an invoice at /invoice?id=1001. They change it to 1002 and see another customer’s invoice. The server checked that the user was logged in, but not that the invoice belonged to them. That is Broken Access Control. The fix is for the server to verify ownership on every request.
5. How to defend and apply it
- Developers: validate input, use parameterised queries, check permissions on the server, keep dependencies updated.
- Analysts: look for repeated odd requests, error spikes and unusual parameters in logs.
- Testers: use the list as a checklist, and practise only on intentionally vulnerable apps or systems you are authorised to test.
- Teams: include security in design, code review and release steps.
6. How it appears in the Google Cybersecurity Certificate
The programme introduces OWASP in its frameworks and security principles material, and links it to secure development and vulnerabilities. Course content may follow an earlier edition, so learn the ideas (access control, injection, misconfiguration) rather than only the numbering. Check the official syllabus.
7. Common exam-style questions (tap to reveal)
Q1. What is the top risk in the 2025 list?
Broken Access Control.
Q2. What defence best stops SQL injection?
Parameterised queries, supported by input validation.
Q3. Which category covers a poisoned third-party library?
Software Supply Chain Failures.
Q4. Why is missing logging a Top 10 issue?
Without logs and alerts, attacks go unnoticed and are hard to investigate.
Q5. Is the Top 10 a complete list of all web vulnerabilities?
No. It is an awareness document highlighting the most critical risks.
8. Further learning (5 links)
- OWASP Top 10:2025 – the official list
- OWASP Top 10 project – history and older versions
- OWASP Cheat Sheet Series – practical defences
- OWASP Juice Shop – legal practice target
- PortSwigger Web Security Academy – free hands-on labs
YouTube searches
One-screen revision summary
- CIA: confidentiality, integrity, availability; ask which one is affected.
- CISSP: eight domains from risk management to software development security.
- NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover. RMF: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.
- OWASP Top 10:2025: starts with Broken Access Control; also covers misconfiguration, supply chain, injection and logging failures.
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official sources. Last reviewed: October 2026.
