Core Cybersecurity Concepts Explained: CIA Triad, CISSP Domains, NIST CSF/RMF and OWASP Top 10

    Four ideas that keep appearing in cybersecurity study and job interviews, explained in plain English. Each part has a definition, analogy, step-by-step, example, defences, how it appears in the Google Cybersecurity Certificate, exam-style questions and five further-learning links.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations, examples and questions are original. Confirm current course content on the official Coursera page.

    How the four fit together

    TopicWhat it isUse it to
    CIA triadThree security goalsDescribe what an incident or control affects
    CISSP 8 domainsA map of the security professionSee the whole field and plan study or career steps
    NIST CSF and RMFA risk framework and an approval processOrganise a security programme and manage system risk
    OWASP Top 10Top web application risksFind and fix common web flaws

    Part 1: CIA triad explained

    CIA triad explained: tap to open or close

    1. Definition

    The CIA triad is a model built on three security goals: confidentiality, integrity and availability. Almost every control, risk and incident can be described by which of these goals it protects or damages.

    GoalKey questionTypical threatsTypical controls
    ConfidentialityCan only the right people see it?Data breach, shoulder surfing, phishingEncryption, access control, MFA, data classification
    IntegrityIs it accurate and unaltered?Tampering, malware, accidental editsHashing, digital signatures, change control, audit logs
    AvailabilityCan authorised people use it when needed?Ransomware, DDoS, hardware failureBackups, redundancy, patching, DDoS protection

    2. Real-world analogy

    Think of a bank. The locked vault and ID checks are confidentiality. Tamper-evident sealed bags that show if anything was changed are integrity. Opening hours, backup generators and a second branch are availability. A bank that fails any one of the three is not doing its job.

    3. How it works, step by step

    1. Identify the asset, such as customer records, a website or a payroll system.
    2. Rank the goals. A public news site cares most about availability and integrity; a medical file cares most about confidentiality.
    3. List threats to each goal.
    4. Choose controls that reduce those threats (technical, physical and administrative).
    5. Test and monitor with logs, audits and drills.
    6. Review after changes or incidents, because trade-offs shift over time.

    Trade-offs: stricter access improves confidentiality but can slow people down, which hurts availability. Good security balances all three.

    4. Real-world example: a hospital

    • Confidentiality fails: a staff member’s stolen password lets an attacker read patient files.
    • Integrity fails: someone changes a drug allergy in a record, so a nurse acts on wrong information.
    • Availability fails: ransomware locks the system and doctors cannot reach records during emergencies.

    One organisation, three different kinds of harm, which is why teams plan for all three.

    5. How to defend and apply it

    • Least privilege: give people only the access they need.
    • MFA and strong passwords protect accounts.
    • Encrypt data in transit and at rest.
    • Check integrity with hashes and keep audit logs.
    • Back up regularly and test restores; keep a copy offline.
    • Patch and monitor systems; plan for outages.
    • Use it when reading an incident: ask “which of C, I or A was affected?” before deciding severity.

    6. How it appears in the Google Cybersecurity Certificate

    The triad is one of the foundational ideas of the programme and mainly appears in the early risk and security frameworks material, then keeps returning in assets, incident response and interview scenarios. Course titles and ordering can change, so check the official syllabus.

    • Classifying threats and controls by the goal they affect.
    • Explaining incidents in plain language to managers.
    • Pairing with frameworks such as the NIST CSF.

    7. Common exam-style questions (tap to reveal)

    Q1. A ransomware attack encrypts files so staff cannot open them. Which goal is hit most directly?

    Availability. Confidentiality may also be affected if data was stolen first.

    Q2. Which control best supports integrity?

    Hashing or digital signatures, because they reveal unauthorised changes.

    Q3. Name two controls for confidentiality.

    Encryption and access control (also MFA or data classification).

    Q4. Why can improving one goal harm another?

    Extra restrictions or checks can slow or block legitimate users, reducing availability.

    Q5. An employee accidentally edits a shared payroll sheet. Which goal is affected?

    Integrity, since the data is no longer accurate. It is a threat even without malicious intent.

    8. Further learning (5 links)

    YouTube searches

    Part 2: CISSP 8 domains explained

    CISSP 8 domains explained: tap to open or close

    1. Definition

    The CISSP is a respected security certification from ISC2, and its exam content is organised into eight domains that together describe the breadth of a security career. Learning the domains gives beginners a map of the whole field, even before they plan to sit the exam.

    See ISC2’s CISSP page for current requirements and exam details.

    2. Real-world analogy

    Picture a city. It needs a council and rules (domain 1), a register of what it owns (2), sound buildings (3), roads and communications (4), ID and keys for residents (5), inspectors (6), an emergency service (7) and safe construction rules (8). Security works the same way: many departments, one goal.

    3. The eight domains, step by step

    #DomainPlain meaningExamples
    1Security and Risk ManagementPolicies, law, ethics and risk decisionsRisk assessments, compliance, business continuity
    2Asset SecurityKnow and protect your data and devicesClassification, retention, disposal
    3Security Architecture and EngineeringDesign systems securelyCryptography, secure design, physical security
    4Communication and Network SecurityProtect data moving across networksFirewalls, VPNs, secure protocols
    5Identity and Access ManagementControl who can do whatMFA, roles, single sign-on
    6Security Assessment and TestingCheck that controls workAudits, vulnerability scans, penetration tests
    7Security OperationsRun security day to dayMonitoring, incident response, backups, recovery
    8Software Development SecurityBuild safe softwareSecure coding, code review, testing

    Using the map: note which domains your current or past work touches, then spot gaps to study.

    4. Real-world example: one phishing incident

    • Domain 5: a stolen password is used; MFA would have helped.
    • Domain 4: traffic to a malicious site is blocked.
    • Domain 7: analysts detect, contain and recover.
    • Domain 1: management decides on reporting duties.
    • Domain 6: a later test checks the fix.

    A single event touches several domains, which is why the map matters.

    5. How to apply it

    • As a study plan: cover one domain per week with notes and practice questions.
    • As a career map: SOC work leans on domain 7; GRC on 1; engineering on 3 and 4; application security on 8.
    • Pathway: the Google certificate, then a certificate such as Security+ or ISC2 Certified in Cybersecurity, then experience. CISSP requires several years of relevant work experience, so check ISC2 for current rules, including the associate route.

    6. How it appears in the Google Cybersecurity Certificate

    The programme introduces security domains early, in its risk-management material, and uses them to show how roles differ. Its labs and tools line up with several domains: Linux and networks (3, 4), access control (5), SIEM and incident response (7) and Python automation (8). Check the official syllabus for current wording.

    7. Common exam-style questions (tap to reveal)

    Q1. How many CISSP domains are there?

    Eight.

    Q2. Which domain covers MFA and role-based access?

    Identity and Access Management (domain 5).

    Q3. A penetration test mainly belongs to which domain?

    Security Assessment and Testing (domain 6).

    Q4. Which domain includes incident response and backups?

    Security Operations (domain 7).

    Q5. Is CISSP an entry-level certificate?

    No. It is aimed at experienced professionals, but beginners can use the domains as a learning map.

    8. Further learning (5 links)

    YouTube searches

    Part 3: NIST CSF and RMF explained

    NIST CSF and RMF explained: tap to open or close

    1. Definition

    The NIST Cybersecurity Framework (CSF) is a flexible set of outcomes that helps organisations understand and improve how they manage cyber risk. The NIST Risk Management Framework (RMF) is a step-by-step process for selecting, applying and approving security controls for a specific system.

    Both come from the US National Institute of Standards and Technology. Start at NIST’s CSF page.

    2. Real-world analogy

    The CSF is like a checklist of areas every healthy business must cover: planning, knowing what you own, protection, alarms, emergency response and repair. The RMF is like the permit process for one building: classify it, choose safety features, build them, inspect, sign off, and keep inspecting.

    3. How it works, step by step

    CSF 2.0 functions (published 2024)

    FunctionQuestion it answersExample
    GovernWho decides and how is risk managed?Policies, roles, risk appetite
    IdentifyWhat do we have and what could go wrong?Asset inventory, risk assessment
    ProtectHow do we reduce the chance of harm?MFA, patching, training
    DetectHow do we notice problems?Logging, SIEM alerts
    RespondWhat do we do during an incident?Playbooks, escalation
    RecoverHow do we return to normal?Backups, restoration, lessons learned

    Older versions (1.1) had five functions without Govern, so some training material still shows five.

    RMF steps

    1. Prepare roles, priorities and context.
    2. Categorize the system by impact (low, moderate, high).
    3. Select controls, usually from NIST SP 800-53.
    4. Implement them and document how.
    5. Assess whether they work.
    6. Authorize: a leader accepts the remaining risk.
    7. Monitor continuously and repeat when things change.

    4. Real-world example: a small clinic

    • CSF view: the clinic has no inventory (Identify), staff share passwords (Protect), nobody reviews logs (Detect) and there is no ransomware plan (Respond, Recover). A leader assigns ownership (Govern).
    • RMF view: for its new patient portal, the clinic rates data impact as high, selects controls such as MFA and encryption, tests them, gets sign-off, then monitors.

    5. How to defend and apply it

    • Use the CSF as a health check: rate each function and pick the weakest to improve.
    • Use profiles to compare where you are with where you want to be.
    • Use the RMF when a system needs formal approval, common in government and regulated work.
    • Match incidents to functions: a missed alert is a Detect gap; slow restoration is Recover.
    • Document everything: frameworks reward evidence.

    6. How it appears in the Google Cybersecurity Certificate

    The programme teaches the CSF and the RMF in its risk-management and frameworks material, then reuses their ideas in incident response and escalation. The course may show the five-function version; know both. Check the official syllabus for current wording.

    7. Common exam-style questions (tap to reveal)

    Q1. Name the six CSF 2.0 functions.

    Govern, Identify, Protect, Detect, Respond, Recover.

    Q2. Which function does a SIEM alert mainly support?

    Detect.

    Q3. What is the first RMF step?

    Prepare.

    Q4. Is the CSF a law?

    No. It is voluntary guidance, though some rules or contracts may require using it.

    Q5. What does Authorize mean in the RMF?

    A responsible official formally accepts the remaining risk and allows the system to operate.

    8. Further learning (5 links)

    YouTube searches

    Part 4: OWASP Top 10 explained

    OWASP Top 10 explained: tap to open or close

    1. Definition

    The OWASP Top 10 is a community-built awareness list of the most critical security risks to web applications, published by the Open Worldwide Application Security Project. It is updated every few years, and the 2025 edition is the latest at the time of writing.

    Read the official list at owasp.org/Top10. Older material often shows the 2021 edition, so expect small differences.

    2. Real-world analogy

    Imagine building inspectors publishing a “top ten most common defects” list: unlocked doors, faulty wiring, rotten supplies. Builders who fix those first prevent most problems. The Top 10 does the same for web apps.

    3. The ten risks, step by step

    #Risk (2025)Plain meaningMain defence
    A01Broken Access ControlUsers can reach data or actions they should notServer-side permission checks, deny by default
    A02Security MisconfigurationUnsafe settings, default accounts, open servicesHardened baselines, regular reviews
    A03Software Supply Chain FailuresCompromised libraries, build tools or updatesDependency tracking, trusted sources, signing
    A04Cryptographic FailuresWeak or missing encryptionModern algorithms, TLS, good key handling
    A05InjectionUntrusted input treated as commands (e.g. SQL)Parameterised queries, input validation
    A06Insecure DesignFlaws in the plan, not just the codeThreat modelling, secure design patterns
    A07Authentication FailuresWeak logins, session problemsMFA, rate limiting, secure sessions
    A08Software or Data Integrity FailuresTrusting unverified code or dataSignature checks, protected pipelines
    A09Security Logging and Alerting FailuresAttacks go unnoticedUseful logs, alerts, review
    A10Mishandling of Exceptional ConditionsErrors and odd states handled unsafelySafe error handling, fail closed, testing

    Using it: review your app against each row, fix the highest-impact gaps, then retest.

    4. Real-world example: changing a number in a URL

    A shopper views an invoice at /invoice?id=1001. They change it to 1002 and see another customer’s invoice. The server checked that the user was logged in, but not that the invoice belonged to them. That is Broken Access Control. The fix is for the server to verify ownership on every request.

    5. How to defend and apply it

    • Developers: validate input, use parameterised queries, check permissions on the server, keep dependencies updated.
    • Analysts: look for repeated odd requests, error spikes and unusual parameters in logs.
    • Testers: use the list as a checklist, and practise only on intentionally vulnerable apps or systems you are authorised to test.
    • Teams: include security in design, code review and release steps.

    6. How it appears in the Google Cybersecurity Certificate

    The programme introduces OWASP in its frameworks and security principles material, and links it to secure development and vulnerabilities. Course content may follow an earlier edition, so learn the ideas (access control, injection, misconfiguration) rather than only the numbering. Check the official syllabus.

    7. Common exam-style questions (tap to reveal)

    Q1. What is the top risk in the 2025 list?

    Broken Access Control.

    Q2. What defence best stops SQL injection?

    Parameterised queries, supported by input validation.

    Q3. Which category covers a poisoned third-party library?

    Software Supply Chain Failures.

    Q4. Why is missing logging a Top 10 issue?

    Without logs and alerts, attacks go unnoticed and are hard to investigate.

    Q5. Is the Top 10 a complete list of all web vulnerabilities?

    No. It is an awareness document highlighting the most critical risks.

    8. Further learning (5 links)

    YouTube searches

    One-screen revision summary

    • CIA: confidentiality, integrity, availability; ask which one is affected.
    • CISSP: eight domains from risk management to software development security.
    • NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover. RMF: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.
    • OWASP Top 10:2025: starts with Broken Access Control; also covers misconfiguration, supply chain, injection and logging failures.

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official sources. Last reviewed: October 2026.