CYSE 200T

CIA Triad

Shelton Jones 

February 15th, 2026

CYSE 200T

Professor Duvall

CIA Triad

BLUF: The CIA Triad is a framework for being secure to people. CIA stands for

confidentiality, integrity, and availability. Authentication proves the identity, authorization grants the permission, and together they help enforce the CIA Triad. Protecting data, preserving its accuracy, and ensuring access when needed increases the public’s trust in sensitive information. 

CIA Triad: A model designed to guide policies for information security within an

organization. The model is sometimes referred to as the AIC triad

(availability, integrity, and confidentiality) to avoid confusion with the Central Intelligence Agency. 

Authentication: The security process of verifying the identity of a user, device, or system before granting access. It is asking who you are? An example is when a student wants to log in to Canvas or Midus and enters their credentials, but the Duo Push (2FA) must be activated to grant access, ensuring the person who wants to log in has the authority to do so. 

Authorization: A security process of determining what actions or resources an authenticated user is allowed to access. It is asking what you are allowed to see or do? An example is after a student gets access to Canvas to view their grades and assignments, they can only access student view, not teacher view, to change grades or due dates for coursework. 

Conclusion:

The triad is important because it is a building block for cybersecurity; by maintaining

confidentiality, integrity, and availability, people will feel more secure with sensitive data &

Information. Authorization and authentication support the CIA Triad by controlling access to the systems and data: authentication verifies the user’s identity, while authorization determines the actions that the user is permitted to do, giving the public a sense of security. 

References: https://drive.google.com/file/d/1898r4pGpKHN6bmKcwlxPdVZpCC6Moy8l/view

https://securityscorecard.com/blog/what-is-the-cia-triad/

SCADA Systems

Shelton Jones

April 8th, 2026

CYSE 200T

Professor Duvall

SCADA Systems

BLUF: Supervisory Control and Data Acquisition (SCADA) systems are essential to the operation of critical infrastructure, but they also introduce significant cybersecurity vulnerabilities due to legacy design, connectivity, and a lack of security prioritization. These systems play a key role in monitoring and controlling infrastructure processes that must be modernized and secured to effectively mitigate risks. 

SCADA systems are widely used across critical infrastructure sectors such as energy, water treatment, transportation, and manufacturing to monitor and control industrial processes. According to the SCADA systems article, these systems were originally designed for efficiency and reliability rather than security, making them highly vulnerable in today’s interconnected environment. Many SCADA systems rely on hardware and software that lack encryption, authentication mechanisms, and regular patching. Attackers can exploit these weaknesses through unauthorized access, malware, or network intrusions. 

The vulnerabilities in SCADA systems create opportunities for various cyber threats, including ransomware attacks, insider threats, and nation-state cyber operations. The SCADA article highlights how attackers can manipulate system controls, disrupt operations, or extract sensitive data. A well-known example is the Stuxnet attack, which demonstrates how malware could specifically target industrial control systems to cause physical damage. Research from the Cybersecurity and Infrastructure Security Agency emphasizes that insufficient network segmentation and weak access controls are among the most critical risks in industrial environments. 

Despite their vulnerabilities, SCADA systems also play a critical role in mitigating risks when properly secured and managed. Modern SCADA applications can enable rapid response to anomalies or cyber incidents. Implementing security measures such as network segmentation, intrusion detection systems, multi-factor authentication, and regular patch management can significantly reduce risk. The National Institute of Standards and Technology Cybersecurity Framework helps organizations strengthen their defenses, and human factors play a key role in training personnel to recongize threats and follow security protocols. 

Conclusion: SCADA systems are both a critical asset and a significant vulnerability within modern infrastructure. Their design limitations and increased connectivity expose them to serious cyber risks, but these challenges can be addressed through strategic security improvements. By modernizing SCADA systems, implementing robust cybersecurity measures, and emphasizing human awareness. 

References: https://docs.google.com/document/d/1VnMlL2YmcW5Jg4MdDa1dt5fJpmQM0KVH/edit

https://www.cisa.gov/search?g=scada#gsc.tab=0&gsc.q=scada&gsc.page=1 https://www.nist.gov/search?s=scada

Human Factor in Cybersecurity

Shelton Jones 

April 15th, 2026 

CYSE 200T 

Professor Duvall

The Human Factor in Cybersecurity

BLUF: With a limited cybersecurity budget, the most effective strategy is to prioritize human- centered training while strategically investing in essential security technologies. Human error remains the leading cause of cyber incidents. Allocating a larger portion of funds to training supported by targeted technology provides the best balance of risk reduction and cost efficiency. 

Human Behavior:

Human behavior is consistently identified as a primary vulnerability in cybersecurity, making training a high-impact investment. Employees often fall victim to phishing, weak password practices, and social engineering attacks, which can bypass even advanced systems. By funding regular awareness programs, simulated phishing exercises, and role-based training, organizations can reduce these risks significantly. According to Verizon’s data breach investigations report, the majority of breaches involve the human element (Verizon, 2023). Dedicating a larger portion of the budget to training directly addresses the most common attack vector. 

Training & Tools:

Training alone is insufficient without foundational cybersecurity technologies. Essential tools such as firewalls, endpoint protection, and multi-factor authentication (MFA) act as critical safeguards when human error occurs. Rather than overspending on advanced or redundant technologies, organizations should focus on cost-effective, high-impact solutions. For example, implementing MFA can prevent unauthorized access even if credentials are compromised (NIST, 2020). A balanced budget should allocate funds to these baseline defenses to create a layered security approach. 

Risk-Based Budget:

The optimal allocation strategy is a risk-based balance that integrates both people and technology. For a limited budget, approximately 60% should be directed toward training and awareness, while 40% supports essential cybersecurity tools. This approach reflects the understanding that technology mitigates threats, but trained individuals prevent them. Combining training with technology, such as phishing simulations tied to email security tools, maximizes effectiveness. The integrated model aligns with the concept of “Human Firewall,” where employees actively contribute to organizational security (SANS Institute, 2022). 

Conclusion: 

Balancing cybersecurity spending requires prioritizing human-focused training while maintaining essential technological defenses. Since human error is the most significant contributor to cyber threats, investing in education yields the greatest return. When paired with strategic technology investments, this approach creates a resilient, cost-effective security posture that reduces risk even within a limited budget.