Spring 2023 Semester
Journal Entry #1
In my career, I would like to focus on many areas. I want to focus on many because I would like my career to go as far as I can take it and become as successful as I can in the world of technology. The areas I want to mainly focus on are Operate and Maintaining, Overseeing and Governing and Analyzation. I want to focus mainly on these as they appeal to me the most as they seem to be the most interesting and ones I would enjoy the most. The least appealing to me is Collect and Operate because you don’t seem to have the most freedom as you might have to use specific strategies.
Journal Entry #2
The Principles of science relate to cybersecurity in many ways and ways that you might not have thought of. These can be applied to cybersecurity through a social science framework. With technology being a very important piece of everyday life it relates to many things. A lot of things that happen in the real world will turn around and relate to technology as technology is connected with how we see the world and what we do in the world. The ethical side of technology is a huge one and one that we still today are trying to solve for what is right and what is wrong. You may think you are doing something right by logging onto a friend’s account but technically you can be committing a cybercrime even if it was with good intention. Overall the whole world is what makes social science relate to cybersecurity.
Journal Entry #3
Researchers can use data breach information to look for many things. They can look for the commonalities in types of breaches. This websites Data Breach log can help a researcher because this contains where, when, what was used, how much was taken for data from companies. This log tells researchers what is the most commonly used breach and how often it happens and what specifically is taken during these breaches. This is all very important information when researching breaches and wanting to prevent future breaches.
Journal Entry #4
Maslow’s Hierarchy of Needs relate to my experiences with technology in many ways. Technology can be used for all five of the hierarchy levels. Personally, I use technology to order my food and have it delivered which falls under the Physiological needs level. In the safety level, my phone plays a major role as it is your best bet when out in public for safety because it allows me to stay in contact with people and law enforcement if something were to happen to me. The relationships level, I use technology everyday to stay in contact with my family and girlfriend. I use my phone for my esteem needs as it gives me access to my grades which makes me feel accomplished when I can see my progress and far I have come. And finally, for the top level of the hierarchy, technology gives me the freedom to do almost what ever I want. I use technology to help fulfill my creativeness and I will do graphic design when I feel like it. These are just some specific examples of how the Hierarchy is involved with my technological life.
Journal Entry #5
Ranking 7 motives of hackers from most sense to least sense:
1.) Anti Racist Politics – I rank this one high because its good to get the clean message out and not make everything about race and or culture
2.) DDOS – Personally this makes sense. Yes its agaisnt the law but it was a harmless hack to get ahead of the compitition. It still does not make it right though.
3.) Spending stolen money – Makes sense because you steal it to spend it but it probably isnt the best idea to use stolen money on important/big purchases
4.) Technical Skill – thhis makes sense as they want to teach themselves but it is the wrong way of doing it.
5.) For Fun – I dont put this one last because he was just seeing what he could do for fun. So it was some good practice for him I guess.
6.) Revenge Porn – It makes sense in a way of getting what you want but some people also lie or create fake porn that looks like them to scare them and that just is not needed.
7.) Cyber Bullying/Sexual grooming of children – This just does not make sense and should not ever be done for any reason.
Journal Entry #6
Fake websites:
Real Websites:
Things that make these websites fake are simple misspellings like an extra “o” in google. This can confuse many people who don’t pay close attention and then on the fake website they are grabbing what you type in there and using it against you. Your internet browser letting you know the website isn’t a private or trusted browser can also mean that it can be a fake website. News websites can fool a lot of people. You want to make sure that you are on the proper trusted website as fake news sites post fake death and articles related to that to trick people.
Journal Entry #7

A Human integrations Story:
1: When you have to optimize functions for Automation of tasks but you are out at the coffee shop
2: When you get an email from the Nuclear Regulation to update human factors
3: When you finish updating the factors for the nuclear regulators
4: You go to the roof unhappy because they did not like the updates you made
5: Having to go talk to HR because you acted out when they didn’t like your nuclear factors update
6: The humans system integration liked the updates so they hire you and you are happy
7: You are happy because the new integration system works on your phone now
8: They made him into a stick guy for new integration logo cause it was so good
9: Becoming the team leader for the integration team because you did a good job
10: The team does so good you go on vacation together
Journal Entry #8
After watching the required video, I beleive Hollywood and the media influence our understanding of technology and cybersecurity. The media including movies and tv shows,like to show advanced technology in their storylines. A lot of the simple things like phones and computer styles are real life accurate. The influence comes in when you look into those devices. They like to show a highly advanced UI system or codeing interface. Although they show real life accurate things, they also show more advanced things and like to dramatize certain aspects. This influences your normal non technology persons knowledge as they always see this and start to think that technology and cybersecurity is really complicated. But, they might also think it is cooler.
Journal Entry #9
On the Social Media Disorder scale I only have had an issue with one topic and that is trying to spend less time on social media but failing to do so. I think that the topics on the scale are good topics for people to have to answer as every year social media seems to grow larger and younger kids begin to use it. As more people use social media and more kids grow up through social media we will see an increase in people being addicted to it and not being able to go long periods of times without social media. I think we have different patterns around the world with this because social media is still growing. The PowerPoint states that girls spend more time on social media because of being put into a more aggressive role of role models and because they report more problematic use on it. While boys tend to use social media at a younger age and use it to play games. I think the patterns start to form based of the type of people in certain areas. Areas like cities are going to have more people using social media rather than in the country where they have less of an opportunity to be introduced to it at at a younger age.
Journal Entry # 10
Based on this article, social cybersecurity is just as important as physical cybersecurity. Social Cybersecurity is an emerging problem with national security and it will affect all levels of warfare. Social cybersecurity is focused on changes in human behavior, social, behavior, and even political outcomes. Being able to learn more about social cybersecurity will help us better understand and defend our internal weaknesses within our national security. With this being a potential issue they say ” If left unchecked, this emerging information blitzkrieg will have strategic effects on par with the physical blitzkrieg unleashed at the outset of World War 1″. In order to prevent this we must shift some of our focus to the social side of cybersecurity to better understand people before they pull out the physical cyberattacks such as hacking networks. I way to do this is through social-cyber maneuver. This is when you manipulate information and the network. Networks such as your friends on social media and hashtags used.
Journal Entry #11
Social themes that arose in this video are team work, problem solving skills, and critical thinking. She talked about how you will have to do a lot of working with others and collaboration which falls under the teamwork and the critical thinking theme. Being able to work with others and have to come up with new solutions for problems are a big thing in not just technology but in any job and social atmosphere. Really, all three of these themes come with any job and work well together. Once you master these skills mixed with your technical skills you can land yourself a great job with good pay and enjoy what you do. She also goes over standards in the video which is a big one. When looking for jobs you want to take yourself and your future into consideration. You want to make sure you look for a job in a good cost of living location and with a high paycheck.
Journal Entry #12
In this sample data breach, they connected between two social science theories and two economic theories. The two social theories were Business and phycology. Business because of the management of this breach. They didn’t protect themselves enough to prevent an attack but they contacted who they needed to and investigated the matter in the correct way. Psychology, because of the development that they offered. They developed a plan of attack and recommend that you cancel your cards and provide a link with more help. They connect with the economic theories of Laisse-fare and the classical economic theory. They connect with the classical theory because they contact a cyber firm first and not the government. Stemming from this, after the firm they decided to contact the federal law which breaks off of the classical theory and ended up deciding to have the government help because of the personal data that was stolen.
Journal Entry #13
A company did studies on bug bounties. Bug bounties are when ethical hackers are paid by small or large businesses to purposefully hack into their companies website and or data base. They do this in order to find weaknesses in their system so they can know what needs to be upgraded and defended. Surprisingly, they found that health, finance, and retail companies are notified less of these vulnerabilities that are found within the systems. Through the study they discovered 50,000 valid reports made by the ethical hackers. This information shows why it is important to try and hack yourself. Offering a reward for someone to try their best to hack into your companies database is a smart and effective way of making sure your defense is up to date with the latest technology and making sure your clients data is safe.
Journal Entry #14
After reviewing this article, I believe the five most dangerous things we unknowingly do on the internet are bullying, faking an identity, pirating movies, sharing personal information, and collecting childrens information. My reasons for these being the most serious are because it is concerning. Bullying is a serious problem and it doesnt just lead to someone feeling bad about themselves in order to make someone else feel better, it can lead to suicide. Bullying can turn into something very bad even if you dont mean it that is why this is such a serious matter. Faking an identity is another serious matter. This can break down to multiuple issues, having someones person information and ruining their life with your actions under their identity. So many things can go wrong with this, not just an identity but it can stem all the way into their bank account with loans and other serious things. Next is sharing personal information. This one speaks for itself from the previous sentence. Sharing your personal inforamtion can lead to identity theft, stolen data, stolen items, and unwanted crime to you personally. This is also the same as collecting childrens information. Young children should not be on the internet as they have their whole life ahead of them that can easily get ruined by the internet. Finally is pirated movies and streaming services. This one is not as serious as the ones that involve peoples personal information but it is still serious. If caught you can face a hefty fine and even jail time. There is no difference from pirating a movie online than stealing a jacket from a store. All these crimes are very serious and people need to know where the line is when they cross it with handling the internet in these such ways.
Journal Entry #15
Davin Teo works in digital forensics. People often mix him up with someone who works in a lab with a lab coat. In reality, digital forensics is someone who collects, analys, and reports electronic data that can be presented in the court of law. Davin’s pathway to his digital forensics job is not the usual pathway. His main profession is accounting. He started off in a small accounting firm and decided he could help his firm out on the IT side of things because he knew some stuff about computers and networks. As his career progressed he continued to do this and got better at it and wanted to shift more towards the IT side of work. He then took a new job opportnuity he recieved which was the digital forensics job and he said that is where he found his niche. I think his pathway is definielty not traditional but still a good one. He has strong experience now in both professions which puts him ahead and he ended up finding a job he really loved.
Article Reviews
Article Review #1
This article review is about the Cyber Security Readiness in Iraq. This article explains the role of the human rights activists within cybersecurity. The Iraqi human rights fraternity is not complying with the Iraqi constitution with anti-cyber crime. A bill has been introduced many times since 2011 yet it still has not passed. The bill consists of the government wanting to change the anti cybercrime laws to put more restrictions on human rights activists and they want to criminalize the promotion of human rights through social media. Within this problem of natural rights, they say “human rights as a privilege of all human beings by virtue of being human”. They believe the role of the government is to safeguard and protect those rights to the people. With this bill they want to shut down that human rights aspect within the cyber world because they want to change the cybercrime laws to restrict the rights of human activists and or groups. Dating back to 2011 the bill has been introduced several times yet it still has not passed. This seems to be the inevitable result for this bill. This article relates to our class because the problem here messes with people’s human rights. In class we have discussed what ethics are and mean within the world of cybersecurity. Accepting this bill would not just put peoples rights in jeopardy but also their lives. The bill takes away people’s freedom and confines them to not speak up and lock them up if they do.
Article Review 2
For my second article review, I have decided to read an article that is based on phishing. The article is titled Categorizing human phishing difficulty: a Phish Scale. This article relates to the principles of social sciences in the cyber world as they want to learn the behavior of employees when getting sent fake phishing emails and learning how they can prevent employees from clicking on them through a new phish scale. The goal is to create a Phish scale to easily be able to rate the difficulty of their phishing attacks related to how many clicks that they receive. Through their research they found that phishing emails related to employees’ work company’s are more likely to get clicks. In order to Analyze this, they made the Phish scale in order to detect the difficulty of the actual threat and to see if phishing training has paid off. The Phish Scale is made of two elements. The cues contained inside the email and who the target audience is. Being able to create a scale is an efficient way to tackle real world challenges as this is a major issue with people who don’t know the difference between emails and phishing. Not only can this help the challenge but it can teach more people about the concerns of what can happen to them and their personal information if they don’t know what the difference is. Knowing the difference and obtaining a better understanding of the Phish Scale can help a large group of people like the older communities and put them at less of a risk when using technology. Overall, the Phish Scale is a big step in the right direction for the technology world as we can continue to improve it and push it out to the right people in order to protect them and others from scams.
Article : https://academic.oup.com/cybersecurity/article/6/1/tyaa009/5905453?searchresult=1
Career Paper
Responsibilities of a Chief Information Security Officer
Cybersecurity is becoming a crucial aspect of our daily lives. A lot of people don’t realize but technology is growing and advancing every single day and it impacts nearly everyone dramatically. The majority of jobs all handle the use of technology, and with the rapid growth of technology comes the rapid growth of cybercrime. The rate of cybercrimes grows every day which has caused the need for a CISO to become important. CISO stands for Chief Information Security Officer, and this is a crucial role in the world of cybersecurity and technology. This role is crucial because the Chief Information Security Officer is “responsible for developing and implementing an information security program that protects an organizations data and systems” (“The Ciso Role” Splunk, www.splunk.com , 2022 ). Essentially, the CISO manages the risk and the security of the organization they work for. The CISO role is at the top of the ladder due to the high knowledge of the position. The role is someone who has extensive knowledge in technology, security technology, and risk management of a business. A CISO has the ability to understand the risks and how vulnerabilities contribute to the risks. A CISO has experience in the field and in the office space, and they have extensive knowledge of how everything connects within the cyber world such as the social science aspect of cybersecurity as well as the hands-on cyber-attacks.
With the extensive knowledge and experience of a CISO, they depend on social science research and social science principles. A CISO does a great job at analyzing reports given to them. They are able to work with executives from across multiple departments and analyze a problem and come up with a solution to mitigate the potential risk at hand. In order to be great at this part of the job they have an understanding of the social science principles. For example, when looking at a potential risk they must use rationalism in order to make the next decision. When using rationalism, they view the problem with justification for why a risk might be a risk (USF, www.digitalcommons.usf.edu , 2023). While making these decisions they will use the Agency Theory. The agency theory is a theory whose goal is to help minimize the effect of congruence (USF, www.digitalcommons.usf.edu , 2023). They understand if the risk is done from a self-interested individual or an organization.
Having the ability to understand the ins and outs of the cybersecurity world through different aspects, a CISO can apply key concepts we learned to their work when facing a problem. For example, the CIA triad; the ability to understand and apply this concept is a crucial part of everyday cybersecurity decisions. This is one of the most important concepts we learned and not only does it apply to the CISO position but to every position. A CISO has to make decisions being the top of the ladder and to do so they use this concept to fully understand what the problem they are facing is and how they can attack it to make sure it withholds to the CIA triad standards. Another concept that falls into the decision-making process is rationalization. This adds to the ability to understand the whole situation and then consider all options and figure out which one is the best. They have the decision to follow the principles of the work world and life and make the correct tough decisions when implementing new policies and overlooking their company.
With the CISO being a crucial role in this workforce, they are a marginalized group. This is because the corporate community cannot afford to lose even one good CISO (“CISO MISALIGNMENT” LinkedIn, www.linkedin.com , 2023). Challenges a CISO might face are their boss giving them a budget and telling them no matter what cyber attack may happen no matter the size it will still come back as a major loss for them. This puts the CISO in a position where they can be in good nature or in bad to make sure what needs to be done gets done. This makes the stakes much larger for the CISO positions as there is an unknown amount of “bad guys” trying to hack into their systems or seeking to harm the company. Because of the high stakes and important position, they are put in with very little wiggle room for error which relates them to marginalized groups.
As we can now see, a CISO is a very crucial role in the world of cybersecurity. A Chief Information Security Officer goes through a lot and can be put in positions where they have to be tough on others. Although this can seem bad this is why a CISO is very good at their job and why you don’t want to let one go unless you need to. A CISO holds extensive knowledge of a variety of cybersecurity information, cyber concepts, social concepts and aspects, and the business side of a company. A CISO’s ability to make these decisions and to do it within the principle and uphold business standards shows why they are at the top of the ladder in position.
Sources
“The Ciso Role: What Does a Chief Information Security Officer Do?” Splunk, 22 Nov. 2022, https://www.splunk.com/en_us/blog/learn/chief-information-security-officer-ciso-role.html#:~:text=A%20CISO%20is%20responsible%20for,security%20teams%20at%20larger%20organizations
Digital Commons University of South Florida (USF). https://digitalcommons.usf.edu/cgi/viewcontent.cgi?article=1002&context=oa_textbooks
Spagnuolo, Stephen. “CISO MISALIGNMENT & Marginalization: It’s Bad and It Must Be Stopped.” LinkedIn, https://www.linkedin.com/pulse/ciso-misalignment-marginalization-its-bad-must-stephen-spagnuolo/