CYSE 200T – Analytical Perspective

Overview

This section reflects an analytical approach to cybersecurity, focusing on the evaluation of threats, frameworks, and system vulnerabilities. The entries below demonstrate structured reasoning and the application of cybersecurity concepts to real-world scenarios.


Journal Entry 1: Foundations of Security – The CIA Triad

Overview:
This entry analyzes the CIA Triad (confidentiality, integrity, and availability) as the foundational model for information security. It explains how each component contributes to protecting systems and data, while also introducing authentication and authorization as supporting mechanisms within secure environments.

Key Takeaways:

  • Established a working understanding of confidentiality, integrity, and availability as core security pillars
  • Connected security controls (encryption, MFA, backups, checksums) to each CIA component
  • Distinguished between authentication (identity verification) and authorization (access control)
  • Recognized how the CIA Triad functions as a unified framework for risk evaluation and system protection

Journal Entry 2: Framework Analysis – NIST CSF 1.1 vs 2.0

Overview:
This entry provides a structured comparison between NIST Cybersecurity Framework versions 1.1 and 2.0, emphasizing the expansion of scope, the introduction of the “Govern” function, and the shift toward enterprise-wide risk management and modern threat alignment.

Key Takeaways:

  • Identified the addition of the “Govern” function as a major structural shift toward executive-level accountability
  • Recognized the transition from sector-specific guidance to a universal cybersecurity framework
  • Analyzed improvements in supply chain risk management and third-party oversight
  • Connected framework updates to modern threats (cloud, ransomware, AI, Zero Trust concepts)
  • Understood how CSF 2.0 strengthens alignment between cybersecurity and overall business risk strategy

Journal Entry 3: Operational Focus – Protecting Availability

Overview:
This entry approaches cybersecurity from an operational leadership perspective, outlining strategies to maintain system availability in a corporate environment. It emphasizes redundancy, proactive monitoring, and DDoS mitigation as critical components of maintaining uptime and business continuity.

Key Takeaways:

  • Prioritized redundancy across systems to eliminate single points of failure
  • Identified DDoS mitigation and monitoring as essential for maintaining uptime
  • Connected availability directly to business impact (revenue, trust, shareholder confidence)
  • Reinforced the importance of patching and system maintenance as foundational security practices

Reflection

Through these journal entries, I strengthened my ability to analyze cybersecurity threats from both technical and organizational perspectives. I developed a deeper understanding of how foundational concepts like the CIA Triad support real-world security practices, and how frameworks such as NIST CSF guide structured risk management. These experiences reinforced the importance of availability, resilience, and proactive threat evaluation in maintaining secure systems.