CYSE 201

Module 1 Journal Entry

Review the NICE Workforce Framework. Rank the categories based on how much
they interest you. Write about why your top three categories interest you. In
addition, write about your lowest ranked category and why you think it would
interest you the least?

Name: A’shaad Harris, class: CYSE201S
Date: 5/21/2026
For my assignment today, I am ranking the categories from the cybersecurity careers and
studies website that interest me. When it comes to my number one out of the 5 categories that
interest me, it is Protection and Defense (PD), followed by Investigation (IN), Oversight and
Governance (OG), Implementation and Operation (IO), and Design and Development (DD).
My top three are Protection and Defense (PD), Investigation (IN), and Oversight and
Governance (OG. Protection and Defense (PD) caught my eye because of the type of justice I
strove for. The job category helps protect against identity theft and helps analyze the risks. I was
never personally interested in being an officer; cyber defense fits my style of helping from a
distance. The second one, Investigation (IN), analyzes, processes, and collates information or
data from cyber systems or networks. I made this my second choice because it pairs well with
my first choice. I feel like I would enjoy the investigating party trying to get to the bottom of
things while also building a case. For my last choice, it would have to be Oversight and
Governance (OG). This is being in leadership while managing and directing an organization so that
they can effectively manage and handle cyber work. Being a leader or a manager isn’t easy at all.
Throughout my life, I have always been told I can be a leader, and since working jobs, I feel a
calling to it. Given my sense of justice and honor, I feel this one couldn’t make my top 3.
My bottom categories are Implementation and Operation (IO) and Design and Development
(DD). Implementation and Operation (IO) is the process of operation and maintenance that
helps ensure the effective, efficient security and performance of technology systems. This one
isn’t at the bottom because i under how important this category is, but it just isn’t for me. Even
though it is pretty close to how Oversight and Governance (OG) works, I just felt the job isn’t
really for me. The last one is Design and Development (DD), which conducts research, designs,
and helps develop technology systems. For me, I did design classes in high school like
architecture, and even though I enjoyed it at my heart, I am too much of a perfectionist. I can’t
put myself in that predicament because I would go crazy.
References
National Initiative for Cybersecurity Careers and Studies. (2025, May
29). NICE Workforce Framework for Cybersecurity (NICE Framework).
National Initiative for Cybersecurity Careers and Studies

Module 2 Journal Entry

Define each of the principals of science in your own words. Then, give an
example of how each of the principals relates to cybersecurity.

Name: Ashaad Harris
Date:5/29/2026
The principle of determinism means that events happen for a reason. It’s like fate or destiny that
events are the necessary result of preceding events, like a law of nature. An example of this in
cybersecurity is how data breaches happen randomly. The usual causes could be weak passwords,
weak software, and phishing emails.
The next principle I’m discussing is relativism, which holds that knowledge can change when new
evidence emerges. It’s like the principle is saying that not all knowledge is absolute or solidified. An
example is how cybersecurity experts will update or upgrade technology so it can keep changing to
combat hackers.
Next on the list is objectivity. To me, it means seeing facts or evidence through a biased lens. It’s
like being a judge, seeing all the evidence and making a decision without making assumptions. For
example, cyber analysts use data and evidence rather than assumptions or opinions.
The next principle is parsimony. To me, this means choosing the simple answer rather than
assuming the worst for situations. It feels like checking a box on a check like starting with 1 being the
lightest situation to 10 being the worst. An example of this is a cyber professional addressing a
computer system problem by checking for a software issue rather than assuming a cyberattack.
The next principle is skepticism. To me, it means to ask enough questions to get to the truth. It’s
like being a litigator in the court, trying to get answers. A good example of this is that a cyber
professional must verify emails or websites before trusting them.
The last principle is ethical neutrality. To me, it is studying problems without involving your feelings
in the answer or conclusion. An example would be how cyber investigations focus on analyzing
evidence and facts, and forming answers with just logic.
References
List your References in APA Format Below
National Academies of Sciences, Engineering, and Medicine. (2019).
Integrating social and behavioral sciences (SBS) research to enhance
security in cyberspace. In A decadal survey of the social and
behavioral sciences: A research agenda for advancing intelligence
analysis. National Academies Press

Module 3 Journal Entry

Visit PrivacyRights.org to see the types of publicly available information about
data breaches. How might researchers use this information to study breaches?
What branch or branches of Social Science do you think would benefit the most
from a site hosting this information?

Name: Ashaad Harris
Date:6/7/26
The website privacyright.org provided a lot of useful information about data breaches. It had info
about when breaches happen, which organizations or companies are affected by them, and how
people are affected, too. Researchers can use this information to look for patterns or trends in the
cyber incidents. A good example would be that cyber professionals can see which industries
experience the most data breaches and which data is targeted most often, and can also see the
trend if the breaches are becoming more common over time. This information can also help
researchers understand how cybersecurity policies and security measures are effective. By
comparing the data from different years, they can identify the weaknesses and recommend a better
way to protect sensitive information. They could also use this method to see how the data would
affect the public trust.
The branch of social science that would likely benefit me the most is sociology because researchers
can now examine how data breaches affect individuals, society, and organizations. I think another
one that benefits from this would be psychology. I say this because the study would show how
individuals react to the breaches emotionally and how they will act.
This website definitely shows how research from the social science form of cyber security helps
Researchers understand the high,amd and social impact of data breaches.
References
List your References in APA Format Below
Privacy Rights Clearinghouse. (n.d.). Data breaches.

Module 4 Journal Entry

Review Maslow’s Hierarchy of Needs and explain how each level relates to your
experiences with technology. Give specific examples of how your digital
experiences relate to each level of need.

Name: A’shaad Harris, class: CYSE201S
Date: 6/21/2026
Maslow’s Hierarchy of need an be connected to many of my experiences with technology. At the
physiological level, the technology can help me meet basic needs by giving access to information,
food delivery, and tools for communication. A good example for this would be using your phone to
order and track food or to even keep track of important tasks.
The second level is safety needs. As a cybersecurity student, technology plays a major role in
helping me stay safe online. I use strong passwords and multi-factor authentication, and with
antivirus software to protect my personal information and my account from cyber threats.
The third level is love and belonging. Technology allows me to stay connected with friends, family,
and classmates through social media, texting, and video calls. These tools help me maintain
relations even when people are far away.
The fourth level is esteem needs. Technology supports my education and helps me build confidence
in my skills. Completing cybersecurity assignments, learning Linux commands, and earning good
grades make me feel accomplished.
The highest level is self-actualization. Technology gives me opportunities to learn and
opportunities to count on to counte ro reach my personal goals. Through an online course, research,
and hands-on cyber labs. With this, I can develop new skills and prepare for my future. Technology
helps me grow both personally and professionally by providing access to knowledge and
opportunities that would otherwise be difficult to reach.
Overall, technology connects to every level of Maslow’s Hierarchy of Needs and plays an important
role in my daily life, education, and future career goals
References
Abraham Maslow. (1943). A theory of human motivation. Psychological Review, 50(4), 370–396.

Module 5 Journal Entry

Review the articles linked with each individual motive. Rank the motives from 1
to 7 as the motives that you think make the most sense (being 1) to the least
sense (being 7). Explain why you rank each motive the way you rank it.

Name: A’shaad Harris, class: CYSE201S
Date: 6/28/2026
For this journal entry, I ranked the motives for cybercrime based on what I believe are the most
common and understandable reasons people commit cybercrimes. I ranked money as my
number one on this list because financial gain is one of the biggest motivations behind
cybercrime. Many cybercriminals engage in activities such as identity theft, phishing scams, and
ransomware attacks to make money. I ranked multiple reasons as my second because many
cybercriminals are motivated by a combination of factors, including money, recognition, revenge,
or political beliefs. With that knowledge, political motives came third because some hackers use
cyberattacks to promote causes, influence public opinion, or protest governments and
organizations. I ranked revenge as my fourth because individuals who feel wronged may use
cybercrime to harm others or organizations. Recognition was ranked fifth because some
hackers want attention, status, or respect from others in the hacking community. While this can
be motivating, it is usually not as significant as financial or political goals. I ranked entertainment
sixth because some individuals hack simply for fun or to challenge themselves, but this seems
less common than other motives. Finally, I ranked boredom seventh because most cybercrimes
require planning, knowledge, and effort, making it unlikely that boredom alone is the primary
motivation. Overall, I believe financial gain and a combination of motives are the strongest
reasons people engage in cybercrime, while entertainment and boredom are less influential
factors.
References
9to5Mac. (2021, July 19). Man behind LinkedIn scraping.
https://9to5mac.com/2021/07/19/man-behind-linkedin-scraping/
Economic Times. (2021). New generation of angry, youthful hackers join the hacktivism wave,
adding to cyber security woes.
https://economictimes.indiatimes.com/magazines/panache/new-generation-of-angry-youthful-ha
ckers-join-the-hacktivism-wave-adding-to-cyber-security-woes/articleshow/81707844.cms
HeraldLIVE. (2021). Cyberbullying and online sexual grooming of children on the increase.
https://www.heraldlive.co.za/news/2021-05-31-cyberbullying-and-online-sexual-grooming-of-chil
dren-on-the-increase/

Module 6 Journal Entry

We have many misconceptions about cybersecurity. Here, hackers tell you
about some of our misconceptions. What personal misconceptions did you
have before you started to study cybersecurity? Have those been proven
right or wrong?

Name: A’shaad Harris
Date: 7/5/2026
Before I started studying cybersecurity, I thought hackers were mostly people who sat in dark rooms,
typing random code until they broke into a system. I also believed that only big companies or
governments were targeted because regular people weren’t important enough for hackers to care
about. After learning more about cybersecurity, I found out that both of those ideas were wrong. One
of the biggest things I’ve learned is that hackers often don’t need advanced coding skills to be
successful. Many attacks happen because people make simple mistakes, like clicking on phishing
emails, using weak passwords, or reusing the same password on multiple accounts. Social
engineering is one of the most effective ways hackers gain access because they take advantage of
human behavior instead of trying to break through security systems. I also learned that everyone can
be a target, not just large organizations. Personal information, bank accounts, social media
accounts, and even gaming accounts all have value to cybercriminals. Small businesses and
everyday people are often targeted because they may have fewer security protections in place. The
video also changed the way I think about hackers. I assumed they were all criminals, but I learned
that there are different types of hackers. Ethical hackers use their skills to find security weaknesses
and help organizations fix them before criminals can exploit them. This showed me that hacking
itself is not always bad—it depends on the person’s intentions.
Overall, studying cybersecurity has completely changed my perspective. I now understand that
cybersecurity is just as much about people as it is about technology. Staying safe online requires
good security habits, awareness, and constant learning because cyber threats continue to evolve.
References
YouTube Video
Unknown. (n.d.). Misconceptions about cybersecurity [Video]. YouTube.

Annotated Bibliography

Annotated Bibliography
Asmar, M., & Tuqan, A. (2024). Integrating machine
learning for sustaining cybersecurity in digital banks.
Heliyon, 10(17), e37571.
https://doi.org/10.1016/j.heliyon.2024.e37571
(ScienceDirect)

Annotation
This article explains how machine learning helps organizations improve cybersecurity by
detecting threats such as phishing, ransomware, insider threats, and distributed
denial-of-service (DDoS) attacks. The authors discuss several machine learning models and
explain how they can automatically recognize suspicious activity before it causes major
damage. They also examine the strengths and weaknesses of using machine learning in
cybersecurity.
This is a high-quality, peer-reviewed journal article published in Heliyon in 2024. It is directly
related to my research because it shows how automated machine learning can reduce cyber
risks and protect organizations from financial losses and operational disruptions.
Tian, X., Tian, Z., Khatib, S. F. A., & Wang, Y. (2024).
Machine learning in internet financial risk management: A
systematic literature review. PLOS ONE, 19(4), e0300195.
https://doi.org/10.1371/journal.pone.0300195 (PLOS)

Annotation
This systematic literature review examines how machine learning is used to identify and
manage financial risks across internet-based businesses. It compares different machine
learning techniques and explains how artificial intelligence improves fraud detection, risk
prediction, and security monitoring. The article also discusses current challenges and future
research opportunities.
This peer-reviewed article is valuable because it summarizes many studies instead of focusing
on only one. It supports my research by explaining how machine learning reduces financial risks
through faster and more accurate threat detection.
Identifying the most accurate machine learning
classification technique to detect network threats. (2024).
Neural Computing and Applications, 36, 8977-8994.
https://doi.org/10.1007/s00521-024-09562-9 (Springer
Link)

Annotation
This study compares several machine learning models to determine which ones are most
effective at identifying network attacks and insider threats. The researchers explain how
different algorithms perform when detecting malicious behavior while reducing false alarms. The
article also discusses the importance of choosing reliable models for real-world cybersecurity
environments.
This source is relevant because my research focuses on automated machine learning filtering.
The article provides evidence that selecting accurate machine learning models helps
organizations detect attacks earlier, reducing operational downtime and lowering the overall cost
of cyber incidents.
Bokolo, Z., & Daramola, O. (2024). Elicitation of security
threats and vulnerabilities in insurance chatbots using
STRIDE. Scientific Reports, 14, 17920.
https://doi.org/10.1038/s41598-024-68791-z (Nature)

Annotation
This article examines cybersecurity risks in AI-powered insurance chatbots using the STRIDE
threat modeling framework. The authors identify vulnerabilities that attackers can exploit and
recommend security controls to reduce those risks. The study demonstrates how organizations
can strengthen their cybersecurity posture while protecting customer information.
This is a peer-reviewed article published in Scientific Reports, making it a reliable source. It
connects to my research because it shows how organizations can use structured security
methods alongside machine learning to reduce operational and financial risks from
cyberattacks.
References
Asmar, M., & Tuqan, A. (2024). Integrating machine learning for sustaining cybersecurity in
digital banks. Heliyon, 10(17), e37571. https://doi.org/10.1016/j.heliyon.2024.e37571
(ScienceDirect)
Bokolo, Z., & Daramola, O. (2024). Elicitation of security threats and vulnerabilities in insurance
chatbots using STRIDE. Scientific Reports, 14, 17920. (Nature)
Identifying the most accurate machine learning classification technique to detect network
threats. (2024). Neural Computing and Applications, 36, 8977-8994. (Springer Link)
Tian, X., Tian, Z., Khatib, S. F. A., & Wang, Y. (2024). Machine learning in internet financial risk
management: A systematic literature review. PLOS ONE, 19(4), e0300195.
https://doi.org/10.1371/journal.pone.0300195 (PLOS)

Module 8 Journal Entry

After watching the video, write a journal entry about how
you think the media influences our understanding about
cybersecurity. Has this understanding changed over
time? What is different in the older pieces of media vs
more current media?

Name: A’shaad Harris
Date: 7/12/2026
Before this class, I always thought hacking was like it is in the movies. I figured hackers could type
really fast, press a few buttons, and get into any computer in just a couple of minutes. After watching
the videos and learning more about cybersecurity, I realized that’s not how it really works. Most
hacks take a lot of time, planning, and usually happen because someone made a mistake, like
clicking a fake email or using a weak password. The videos showed that movies make hacking look
way more exciting than it actually is. They add cool graphics, countdowns, and make it seem like
hackers can do anything almost instantly. In real life, hacking is much slower and takes a lot of
research. Hackers usually spend time looking for weak spots instead of just magically breaking into
a system. I also think the way hacking is shown has changed over the years. Older movies made
hackers seem like they had unlimited powers and could control everything with a keyboard. Newer
movies and TV shows are a little more realistic because people know more about cybersecurity now.
They include things like phishing, ransomware, and multi-factor authentication, even if they still make
it more dramatic than it really is.
Overall, I think the media has a big impact on how people see cybersecurity. It can be entertaining,
but it doesn’t always show what hacking is really like. These videos helped me understand that
cybersecurity is more about protecting systems, preventing attacks, and teaching people how to stay
safe online than the fast-paced hacking scenes you see in movies.
References
List your References in APA Format Below
Greenberg, A. (Host). (2022, May 11). Hacker breaks down 26 hacking scenes from
movies & TV [Video]. WIRED. https://www.youtube.com/watch?v=6BqpU4V0Ypk
WIRED. (2020). Hacker breaks down hacking scenes from movies & TV [Video].
YouTube.
https://www.youtube.com/results?search_query=WIRED+Hacker+Breaks+Down+Hacki
ng+Scenes+From+Movies+%26+TV

Module 10 Journal Entry 1

Watch this video. As you watch the video
https://www.youtube.com/watch?v=iYtmuHbhmS0, think about
how the description of the cybersecurity analyst job relates to
social behaviors. Write a journal entry describing social themes
that arise in the presentation.

Name: A’shaad Harris
Date: 7/18/2026
After watching the video about cybersecurity analysts, I realized that this career is about much
more than just working with computers. One of the biggest social themes in the presentation is
communication. Cybersecurity analysts must explain security risks to people without a technical
background, so they need to communicate clearly and collaborate effectively. Teamwork is also
important because analysts often work with different departments to protect an organization’s
information and respond to security incidents. Another social theme is trust. Employees,
customers, and businesses all depend on cybersecurity analysts to keep sensitive information
safe. This means analysts must act ethically and make responsible decisions when handling
private data. The video also showed that many cyberattacks take advantage of human behavior
instead of technology. For example, phishing attacks rely on people being tricked into clicking
fake links or giving away personal information. Because of this, cybersecurity analysts must
understand how people think and behave to help prevent such attacks through security
awareness and employee training.
The presentation also emphasized the importance of networking and continuous learning.
Building professional relationships can help people find job opportunities, learn from others, and
stay current with new cybersecurity threats. Since technology changes so quickly, analysts must
be willing to keep learning throughout their careers. Overall, the video showed that being a
cybersecurity analyst requires both technical knowledge and strong people skills. Understanding
human behavior, working with others, communicating effectively, and acting ethically are all
important parts of being successful in this field. These social behaviors are just as important as
technical skills when it comes to protecting organizations from cyber threats
References
List your References in APA Format Below
Enesse, N. (2020). What does a cybersecurity analyst do? Salaries, skills & job outlook [Video].
YouTube. https://www.youtube.com/watch?v=iYtmuHbhmS0
Coursera Staff. (2025, April 7). Career spotlight: Cybersecurity analyst in 60 seconds. Coursera.

Module 10 Journal Entry 2

Read the following and write a journal entry
summarizing your response to the article on social
cybersecurity
https://www.armyupress.army.mil/Journals/Military-Revi
ew/English-Edition-Archives/Mar-Apr-2019/117-Cybers
ecurity/b/
Name: A’shaad Harris
Date: 7/18/2026
After reading Social Cybersecurity: An Emerging National Security Requirement, I learned that
cybersecurity is about much more than protecting computers and networks. The article explained
that social cybersecurity focuses on protecting people from being manipulated through technology
and social media. Instead of attacking computer systems directly, attackers can spread false
information, create fake accounts, and use bots to influence how people think and behave. I thought
this was one of the most interesting parts of the article because it shows that people can become
targets just as easily as computers. The article also explained how social media has changed the
way information spreads. Since almost anyone can post content online, it is much easier for
misinformation to spread quickly. This can create confusion, divide communities, and reduce trust in
governments, organizations, and even the military. I did not realize how much influence social media
can have on national security until reading this article. Another point that stood out to me was the
importance of educating people. Technology alone cannot stop these types of attacks because they
are designed to manipulate human behavior. People need to learn how to recognize misinformation,
fact-check sources, and think critically before sharing information online. I believe this is just as
important as using firewalls, antivirus software, or other cybersecurity tools.
Overall, this article changed the way I think about cybersecurity. I used to think cybersecurity was
mostly about hackers breaking into systems, but now I understand that protecting people from
Misinformation and manipulation are also a major part of keeping organizations and countries secure.
As I continue studying cybersecurity, I think understanding the human side of cyber threats will be
Just as important as learning the technical skills.
References
List your References in APA Format Below
Beskow, D. M., & Carley, K. M. (2019). Social cybersecurity: An emerging national
security requirement. Military Review

Module 11 Journal Entry 1

Read this
https://dojmt.gov/wp-content/uploads/Glasswasherparts.com_.pd
f sample breach letter “SAMPLE DATA BREACH NOTIFICATION”
and describe how two different economics theories and two
different social sciences theories relate to the letter.
Name: Ashaad Harris
Date:7/26/2026
The Sample Data Breach Notification explains that the company discovered unauthorized access to
customer payment card information through its online shopping system. After learning about the
breach, the company investigated the incident, worked with law enforcement, hired a computer
security firm, and notified customers about the possible exposure of their personal information. The
letter also encourages customers to replace their payment cards and monitor their accounts for
suspicious activity. One economic theory that relates to this letter is Rational Choice Theory. This
theory explains that people and businesses make decisions based on what they believe will produce
the best outcome. The company chose to investigate the breach, notify customers, and recommend
replacing payment cards because these actions help reduce financial losses and maintain customer
trust. Taking these steps can also help protect the company’s reputation.
Another economic theory is Cost-Benefit Analysis. The company likely considered that the cost of
notifying customers, investigating the breach, and improving security was much lower than the
potential cost of additional fraud, lawsuits, and losing customers. Responding quickly helps reduce
future financial damage. One social science theory shown in the letter is the Social Contract Theory.
Customers expect companies to protect their personal and financial information when making
purchases online. When a data breach happens, that trust is broken. By explaining the incident and
providing guidance, the company is attempting to rebuild trust with its customers.
Another social science theory is Routine Activities Theory. This theory states that crime occurs when
a motivated offender finds a suitable target without enough protection. The cybercriminals targeted
customer payment information, showing the importance of strong cybersecurity measures to prevent
unauthorized access and protect sensitive customer data.
References
Montana Department of Justice. (2017). Sample data breach notification.

Module 11 Journal Entry 2

A later module addresses cybersecurity policy through a social
science framework. At this point, attention can be drawn to one type
of policy, known as bug bounty policies. These policies pay
individuals for identifying vulnerabilities in a company’s cyber
infrastructure. To identify the vulnerabilities, ethical hackers are
invited to try explore the cyber infrastructure using their penetration
testing skills. The policies relate to economics in that they are based
on cost/benefits principles. Read this article
https://academic.oup.com/cybersecurity/article/7/1/tyab007/6168453?l
ogin=true and write a summary reaction to the use of the policies in
your journal. Focus primarily on the literature review and the
discussion of the findings.
Name: A’shaad Harris
Date: 7/26/2026
The article “Hacking for Good: Leveraging HackerOne Data to Develop an Economic Model of Bug
Bounties” explains how bug bounty programs help organizations improve cybersecurity by paying
ethical hackers to identify security vulnerabilities before malicious hackers can exploit them. The
literature review explains that bug bounty programs have become more popular because
organizations cannot always find every weakness with their own security teams. The authors also
discuss how previous research suggested that bug bounty programs were beneficial, but there was
little real-world evidence showing how effective they actually were. To address this gap, the
researchers analyzed a large HackerOne dataset to better understand what influences bug bounty
success and what motivates ethical hackers to participate. The discussion of the findings showed
several important results. One of the biggest findings was that ethical hackers are not motivated only
by money. Many also participate to gain experience, build their reputation, and improve their
cybersecurity skills. The study also found that companies of all sizes can benefit from bug bounty
programs because a company’s size or reputation does not significantly affect the number of valid
vulnerability reports it receives. Another finding was that bug bounty programs receive fewer reports
as they get older because many of the easier vulnerabilities have already been discovered.
However, expanding the scope of the program can help attract researchers and uncover additional
security issues. The researchers also concluded that more research is needed to better understand
what motivates ethical hackers and how bug bounty programs can continue to improve
cybersecurity. I think bug bounty policies are a smart way for companies to improve security while
saving money. Instead of waiting for cybercriminals to discover vulnerabilities, organizations can
reward ethical hackers for finding them first. This approach benefits both the company and the
researchers while making the internet safer for everyone. Based on the article, I believe bug bounty
programs are an effective and cost-efficient cybersecurity strategy
References
Sridhar, K., & Ng, M. (2021). Hacking for good: Leveraging HackerOne data to develop an
economic model of bug bounties. Journal of Cybersecurity, 7(1), tyab007.

Article Analysis

Cyber Security and Criminal Justice Programs in
the United States: Exploring the Intersections

The article “Cyber Security and Criminal Justice Programs in the United States: Exploring the
Intersections” by Brian K. Payne and Lora Hadzhidimova discusses the connection between
cybersecurity, cybercrime, criminal justice, and the social sciences. The authors explain that
cybersecurity is usually connected to STEM fields, such as computer science and information
technology, but it is also related to social science because cybercrime involves people, society,
behavior, laws, and the criminal justice system. The purpose of the study was to find out how
much criminal justice programs and criminal justice research include cybersecurity and
cybercrime. The researchers found that many criminal justice programs offer courses about
cybercrime, but there are still not many cybercrime studies published in major criminal justice
journals.
This topic relates to several principles of social science. Social science studies people, groups,
institutions, and how they interact with society. Cybersecurity involves human behavior because
many cyberattacks happen when people make mistakes, share personal information, or fall for
scams. It also involves social institutions, such as schools, businesses, law enforcement
agencies, and the government. Another social science principle connected to this article is crime
and deviance. Cybercriminals use technology to break laws, steal information, and harm
individuals or organizations. The article shows that cybersecurity should not only be studied as
a technology issue because understanding people and their behavior is also important.
The main research question focused on how cybersecurity and cybercrime are included in
criminal justice education and research. The researchers wanted to know if criminal justice
programs were teaching students about cybercrime and whether criminal justice scholars were
conducting enough research about cybersecurity. The study did not appear to test one specific
hypothesis. Instead, it examined the relationship between cybersecurity and criminal justice and
looked for evidence showing how much these subjects overlap.
The researchers used a content analysis and comparative research method. They examined
criminal justice programs and looked at the courses that were offered. They also reviewed
articles published in major criminal justice journals to see how often cybercrime and
cybersecurity were included. This method allowed the researchers to compare cybersecurity
education with cybersecurity research. The study used mostly secondary and quantitative data
because the researchers collected information that was already available, such as course
information and published research articles. They organized and compared the information to
determine how common cybersecurity and cybercrime were in criminal justice education and
scholarship.
The results showed that cybersecurity and cybercrime were included in a number of criminal
justice programs. This means that colleges recognize that students studying criminal justice
should learn about crimes involving technology. However, the researchers also found that
cybercrime was not studied very often in mainstream criminal justice journals. This shows a
difference between what is being taught in criminal justice programs and what is being
researched by criminal justice scholars. The authors believe that more research is needed
because cybercrime continues to grow and affects many parts of society.
This article connects to several concepts discussed in class. The first concept is social
institutions because colleges, the criminal justice system, law enforcement, and the government
all have responsibilities related to cybersecurity. The second concept is social change because
technology has changed how people communicate, work, learn, and commit crimes. The third
concept is crime and deviance because cybercrime involves behavior that breaks laws and
causes harm to others. The fourth concept is social inequality because not everyone has the
same access to technology, cybersecurity education, or protection from cyber threats. Another
concept is globalization because cybercrime can cross national borders and affect people and
organizations around the world.
Cybersecurity can also create challenges and concerns for marginalized groups. Some people
may have less access to computers, internet services, cybersecurity education, and
technology-related careers. People with fewer resources may also have a harder time protecting
themselves from online scams, identity theft, and other cybercrimes. Older adults, low-income
communities, and people with limited technology experience may be more vulnerable to certain
online threats. Increasing cybersecurity education could help these groups understand online
risks and protect their personal information. It could also create more opportunities for people
from different backgrounds to enter cybersecurity and criminal justice careers.
The study makes several important contributions to society. First, it shows that cybersecurity
should be included more in criminal justice education because future criminal justice
professionals need to understand cybercrime. Second, the study points out that more research
is needed about cybersecurity in criminal justice. More research could help law enforcement
agencies, policymakers, businesses, and schools develop better ways to prevent and respond
to cybercrime. Overall, this article shows that cybersecurity is not only a technology issue. It is
also a social issue because it involves people, behavior, laws, education, institutions, and the
safety of society.
Reference
Payne, B. K., & Hadzhidimova, L. (2018). Cyber security and criminal justice programs in the
United States: Exploring the intersections. International Journal of Criminal Justice
Sciences, 13(2), 385–404.

Module 12 Journal Entry 

Andriy Slynchuk Links to an external site. has described eleven things Internet users do that may be illegal.  Review what the author says and write a journal

After reading Andriy Slynchuk’s article, 11 Things Internet Users Do That May Be Illegal, I learned
that many actions people commonly do online may have legal consequences. Some people may not
realize that activities such as downloading copyrighted music or movies, using unofficial streaming
websites, or sharing images without permission can violate laws. The article also discussed more
serious actions, including cyberbullying, sharing another person’s private information, and pretending
to be someone else online. The information that stood out to me the most was how easily people
can violate someone’s privacy online. Sharing a person’s address, private pictures, passwords, or
other personal information without permission can cause emotional harm and put that person in
danger. People may believe that posting information online is harmless, but once something is
shared, it can be difficult or impossible to completely remove it. This shows why internet users
should think carefully before posting or sharing information. The article also made me realize that the
internet is not separate from the real world. Laws still apply when people are online, and people can
face consequences for their actions. Technology makes it easy to download, copy, or share content,
but that does not mean those actions are always legal. I believe that internet users should learn
more about online laws and practice responsible digital behavior.
Overall, this article helped me understand that cybersecurity is not only about protecting computers
and networks. It also involves protecting privacy, respecting other people, and following laws. In the
future, I will be more careful about what I download, post, search for, and share online.
References
Slynchuk, A. (2026, January 4). 11 things internet users do that may be illegal. Clario

Career Paper

Human Behavior, Criminology, and Cyber
Defense: The Social Science of Threat
Intelligence Analysis
Introduction to the Role
When people think of cybersecurity, they usually imagine software developers writing code,
configuring firewalls, or setting up network defenses. However, working as a Threat Intelligence
Analyst is much closer to being a digital detective. A threat intelligence analyst spends their day
searching open-source intelligence (OSINT), dark web forums, and network logs to figure out
who is attacking a system, how they operate, and why.
While technical tools track IP addresses and malware hashes, effective threat intelligence
fundamentally depends on social science. Technical data only reveals what happened; social
science principles explain why human adversaries act, how illicit digital communities organize,
and where organizational vulnerabilities emerge.
In their daily work, threat intelligence analysts constantly rely on Cyber Routine Activities Theory
(CRAT). Derived from classic criminological theory, CRAT explains that cybercrime occurs when
three elements converge in digital space: a motivated offender, a suitable target, and the
absence of a capable guardian. Daily Routine Application: Instead of simply waiting to react
after a breach occurs, threat analysts evaluate how an organization’s daily digital activities might
expose them. For instance, if employees routinely post sensitive operational details on social
media or leave remote database ports exposed, they create a “suitable target.” Analysts act as
“capable guardians” by identifying these vulnerabilities and strengthening defenses before a
motivated threat actor discovers the opportunity. The social science concept of Determinism
holds that human behavior is not random; rather, decisions and actions are driven by prior
experiences, environmental factors, and established patterns. Daily Routine Application: Threat
analysts apply determinism when profiling hacker collectives and nation-state threat groups.
Instead of treating cyberattacks as erratic, unpredictable events, analysts map adversary
behavior using standardized frameworks like the MITRE ATT&CK matrix. By assuming an
attacker’s actions are deterministic, analysts can evaluate past tactics, techniques, and
procedures (TTPs) to predict an adversary’s next logical move during an ongoing intrusion.
Applied Class Concepts in Daily Operations
To anticipate incoming threats, analysts use criminological principles like General Strain Theory.
This theory posits that individuals often turn to crime when experiencing severe economic,
political, or social pressures (strain) paired with a lack of legitimate opportunities . Daily Routine
Application: When monitoring dark web marketplaces where illicit access and ransomware tools
are sold, analysts evaluate the socioeconomic background of threat actors. In regions marked
by high unemployment, systemic poverty, or geopolitical isolation, cybercrime often becomes an
accessible economic alternative. Recognizing these socioeconomic strains helps analysts
differentiate between low-level financially motivated scammers, political hacktivists, and heavily
funded state-sponsored groups. Social science stresses the importance of Ethical
Neutrality—the practice of setting aside personal biases, political opinions, and moral judgments
to analyze evidence objectively. The daily Routine Application: Threat intelligence analysts must
maintain strict objectivity when investigating attack origin and attribution. Media headlines or
international political tensions can easily tempt an analyst to jump to conclusions. However,
practicing ethical neutrality forces analysts to rely strictly on verifiable indicators—such as code
compiler timestamps, language artifacts, and infrastructure overlap—preventing cognitive bias
from corrupting their intelligence reports.
Career Connection to Society and Marginalized Groups
Threat intelligence analysts play an essential role in protecting modern society. By identifying
and disrupting cybercrime syndicates early, analysts defend critical infrastructure—including
healthcare networks, municipal water systems, power grids, and financial institutions. A
successful ransomware defense on a hospital system, for example, directly prevents
life-threatening disruptions to emergency medical care.
However, cybersecurity defenses do not affect all communities equally, making it critical for
threat analysts to understand societal inequities. Digital Equity and Economic Vulnerability:
Non-profit organizations, public schools, and healthcare clinics in lower-income communities
rarely have the financial resources to hire dedicated threat intelligence teams or buy high-end
defensive software. Cybercriminals frequently exploit these under-defended institutions as “easy
targets,” widening existing socioeconomic divides. Algorithmic and Geographic Bias: Automated
threat detection systems that automatically block network traffic based strictly on geographic
region or IP ranges risk systematically cutting off innocent citizens in developing nations or
marginalized regions from global digital platforms and economic opportunities. Targeting of
Vulnerable Communities: Analysts regularly track malicious actors who specifically target
minority groups, human rights activists, or journalists with spyware and doxxing campaigns.
Threat intelligence professionals have a social responsibility to partner with civil society
organizations to spot these targeted campaigns and help protect vulnerable populations from
online harassment and state surveillance.
Conclusion
A successful Threat Intelligence Analyst requires far more than technical fluency. By applying
core social science concepts—such as Cyber Routine Activities Theory, Determinism, Strain
Theory, and Ethical Neutrality—analysts gain a complete, human-centered view of cyber
threats. Combining technical skills with an understanding of human behavior allows these
professionals to protect not only enterprise networks, but also the broader society and its most
vulnerable populations.
References
Jaishankar, K. (2011). Cyber Criminology: Exploring Internet Crimes and Criminal Behavior.
CRC Press.
Parti, K., & Dearden, T. (2025). Cybercrime and Strain Theory: An Examination of Online Crime
and Gender. Journal of Criminology and Criminal Justice Studies, 3(2), 163–183.
Vakhitova, Z. (2025). Cyber Routine Activity Theory. In Oxford Research Encyclopedia of
Criminology and Criminal Justice. Oxford University Press.

Module 14 Journal Entry 

Digital Forensics | Davin Teo | TEDxHongKongSalon – YouTube Watch this video and think about how the career of digital forensics investigators relate to the social sciences.  Write a journal entry describing what you think about the speaker’s pathway to his career.

Name: A’shaad Harris
Date: 8/16/2026
After watching Davin Teo’s TEDx talk about digital forensics, I thought his pathway to his career was
interesting because he did not follow a straight path. He started in a different area and eventually
found his way into technology and digital forensics. What stood out to me was that he took
advantage of opportunities to learn new skills instead of limiting himself to what he originally studied.
I think this is important because careers in cybersecurity can change as technology develops, and
people may discover new areas that they are interested in along the way.
I also think digital forensics has a strong connection to the social sciences because investigators are
not only looking at computers and digital evidence. They are also trying to understand human
behavior. When someone commits a cybercrime, there is usually a reason or motivation behind their
actions. This can connect digital forensics to criminology, psychology, and sociology. For example,
criminology can help investigators understand why someone may commit a cybercrime, while
psychology can help explain a person’s decision-making and behavior. Sociology can also help
explain how people’s interactions with other people and society can influence their behavior.
In my opinion, understanding people is just as important as understanding technology in digital
forensics. An investigator might find evidence on a computer or phone, but they still need to
understand what the evidence means and how it connects to the person’s actions. This shows how
cybersecurity is an interdisciplinary field because technical knowledge alone does not explain every
cybercrime. Social science concepts can help investigators understand the human side of the
evidence they find.
Teo’s career path also showed me that people do not always have to know exactly what career they
want from the beginning. He was able to use his previous experience and combine it with new skills
to move into digital forensics. I found that encouraging because cybersecurity has many different
career options, and learning skills from different fields can be useful. Overall, I think his story
demonstrates how digital forensics connects technology with human behavior and why having an
understanding of the social sciences can make someone a better cybersecurity professional.
References
List your References in APA Format Below
TEDx Talks. (2015, December 9). Digital forensics | Davin Teo | TEDxHongKongSalon [Video].