Journal Entries

Journal 1

The areas of the NICE Workforce Framework that appeal to me the most are Oversight and Governance as well as Implementation and Operation. These two areas appeal to me the most because they are what I think I would feel the most comfortable and at ease doing. I have always been one to look at situations from a more analytical view. A lot of the positions in these two areas revolve around analyzing many different aspects of cybersecurity. I also have lost of experience in managerial positions and would like to continue down that path. The area that lease interests me would have to be Investigation. It is not that it completely disinterests me, it is just the area I feel like I would enjoy the least.

Journal 2

There are plenty of relations between the principles of science and cybersecurity. When it comes to relativism, as the world has advanced, so has technology and cybersecurity. The advancement of technology have also in return caused changes in society. This can especially be seen in the legal system since there has been an increase in the types of crimes that are able to be committed. Using objectivity in the field of cybersecurity is very important. Cybersecurity is a field that affects so much. Therefore, it is important that all research in the field be conducted with no bias. Any sort of bias could have big negative consequences. Parsimony is also important for such a wide field such as cybersecurity. Since cybersecurity affects anyone who uses technology, it is important to keeps the explanations pertaining to the field as simple as possible so that people can easily understand them and keep themselves well protected. Making assumptions in any field is usually never a good idea. This is where empiricism comes into play. Assuming anything about how a system may act could lead to huge errors down the road. Ethical neutrality is important in all lines of work. it goes without saying that bias when it comes to anything will usually lead to issues for other parties involved. some assumptions, like that if a system has flaws then they will be exploited, can lead to beneficial changes. By relying on ethical hackers to identify flaws in a system, cybersecurity professionals can then make changes to fix and strengthen its defenses. Skepticism is also important in most fields. Without questioning ideas, we would not know many of the things that we know today. Skepticism does not only apply to ideas and concepts. It can also apply to system security. This is another principle that ethical hackers play a key role in. They can test a system to find any possible flaws instead of just believing that is is completely secure.

Journal 3

Privacyrights.org shares information on data breaches in the United States to the public. The main way that researchers can use this information to study breaches is by examining past breaches to see if there are any common patterns. These patters could be between the techniques used to execute the breech or the type of data accessed using the breach. If there are any common patters, this can help them determine some new policies and protects that could possibly protect others in the future. This information does not only help researchers though. This can help educate the public on data breaches. This information can let them know if their data has possibly been leaked due to a breach if they were not already notified. It can also show them how often a business that they plan on having information in has been breached. Privacyrights.org is full of useful information that all people can use.

Journal 4

Maslow’s Hierarchy of Needs

Self-Actualization: One way that I have interacted with technology in the level is with my drawing tablet. I have recently been wanting to get back into drawing so I ended up getting a drawing tablet so that I could start back up and draw on my computer.

Self-Esteem: I have been participating in ranked matches of different online games to fulfill this level. The game that I have been playing recently is Street Fighter 6.

Love and Belonging: For this level, I am frequently in Discord call with my friends. We are usually playing games but sometimes we just hang out and talk.

Safety and Security: For my safety needs, I have been monitoring my finances to make sure that I and financially stable. I do this buy putting money aside from every paycheck for bills and other necessities.

Physiological Needs: A way that I use technology to fulfill my physiological needs everyday is my alarm. I use my alarm every morning to make sure that I wake up on time. I also use technology to order food.

Journal 5

It was difficult for me to rank most of these motives because I feel that most of them make around the same amount of sense.

  1. Multiple Reasons: I think this motive makes the most sense because I believe that there are usually multiple reasons that people do a lot of things.
  2. Revenge: This motive makes the next most sense to me because revenge has always been around. With the creation of the internet and its advancement, a new avenue for revenge was created. There are now many different ways that someone can take revenge on someone.
  3. For Money: Next is money for the obvious reason, people need money. Without money, people can’t fulfill many of life’s necessities.
  4. Entertainment: People do a lot of things for entertainment. This is one of the motives that i think is reasonable but would not come before the others.
  5. Boredom: I think that boredom and entertainment can be interchanged. Both boredom and entertainment can be satisfied in someone’s free time when they have nothing else to do. I also feel like they tie into each other because people usually tend to do something they enjoy when they are bored.
  6. Political: I put political motives towards the bottom because I believe that most of the times, cybercrimes executed behind this motive end up in vain. They usually either affect something that can be reversed or redone, or its effects get postponed until they are no longer relevant. People in politics usually have too much power to be affected by a small cybercrime. It would have to be a big one for the results to be seen.
  7. Recognition: I think this is the least reasonable because getting recognized for a crime is not a good thing in my opinion. The only way I see this as reasonable is if you they are trying to get recognized by a cybersecurity professional to possibly work in the field.

Journal 8

There are many different aspects of hacking and cybersecurity as a whole. When is comes to cybersecurity being portrayed in media, there is honestly a wide variety of representations. There are numerous times where cybersecurity is represented spot on as well as numerous time where it is not. I can say that most depictions of cybersecurity do have at least some realistic aspects to them. This can range from the type of environment to the systems or tools used. When it comes to hacking specifically, one of the most common things to be wrongly represented is just the look of the hacking. By this I mean the representation how the database or files being hacked look like in “Skyfall”. There are also instances where the devices used for hacking might be based off of real devices but are slightly different and exaggerate the devices capabilities. I believe that these subtle changes are to help draw people into the world of cybersecurity and maybe make them interested in becoming a part of it.

Journal 9

I scored a 0 out of 9 on the Social Media Disorder scale. When it comes to social media, I rarely use it. I have a few social media accounts but I really only use them to communicate with some of my friends or just to look at cool things other people post. I do not have any posts on any of my social media accounts. I found some of the items on the scale to be a little disturbing. As someone who rarely uses social media, I do not get how someone could get to the point of being a disordered social media user. I believe that different patterns are found around the world due to a few factors. The factor that I think plays the biggest role is peer/family influence. Depending on the social media usage of the people around you, you might feel the need to keep up with them. Another important factor is someone’s priorities. Depending on how high on their priority list things like popularity are, they might feel the need to use social media to stay popular or “relevant”.

Journal 10

Social cybersecurity is a very interesting and important topic to study. As mentioned in the article, it is different from traditional cybersecurity, which studies the hacking of technology. Social cybersecurity looks at the “hacking” of humans. While this might sound bizarre, it makes perfect sense what you look at it. “Hacking” humans means manipulating them in some way by introducing certain information to them, whether it is true or not. This can not only just affect individuals, but it can also affect society as a whole. I think that is is especially important to study social cybersecurity now that many people are heavily influenced by what they see online, especially younger people. With the creation of more and more social media platforms, there are more and more platforms for information to be spread. It is alarming to see the amount of false information on the internet that people end up believing.

Journal 11

When it comes to being a cybersecurity analyst, there are a lot of social concepts involved. As mention in the video, volunteer work and networking are a great way to get started and gain experience. A cybersecurity analyst can protect any information, whether it be the information of induvials or a large company. Making connections to the people or businesses that you work with is a great thing to do as a cybersecurity analyst. not only does this help you get closer to them, which in return might make working with them go smoother, but this could also help you network to possibly gain more work or move up in the field. Good communication is another important social skill to have as a cybersecurity analyst. Being able to simply and clearly explain your findings and suggested practices, not only will this help your customers easily apply them, but it could also leads to them more likely recommending you to other people or businesses.

Journal 12

One economic theory that I thing relates to the sample breach letter is the theory of tragedy of the commons. This is because the attackers had access to user information for about ten months. With this information, the attackers probably took/used some of the users’ money. This ultimately lead to the harm of those who’s information was taken. The second economic theory that I think relates to the letter is the moral hazard theory. This theory can possibly be applicable because there is a chance that the company, while trying to maximize profit, knowingly exposed themselves to risks using their platform provider since it was the providers system being used and not their own. Doing this means that they would not necessarily be at fault for and possible risks. On the social science side of things, I think that the rational choice theory relates to the letter. I think this theory can relate to both the attackers and the company. It can relate to the attacker because they made the choice to attack the server and it can relate to the company because they chose to use the server. it is also possible for conflict theory to relate to the letter. There is a chance that the attackers resorted to these measure due to social inequalities cause them to be worse off than those around them.

Journal 13

The part of the article that piqued my interest the most was the fact that most new hackers are not incentivized by monetary gain. I always assumed that most new hackers, both positive and negative, did what they did for the money. This data was honestly very surprising to me. However, after reading the article, it makes more since to me now. Gaining exposure as a hacker is very important to start whatever career path you want to follow. Most people would not trust, let alone hire, and inexperienced hacker. This is true for both attackers and defenders. I also found it interesting that even with al of this research, there are still over 96% of variations in reports still unexplained. This shows just how must still needs to be studied about this particular area.

Journal 14

I think that the five most serious violations talked about in the blog, in no particular order, are bullying and trolling, sharing passwords and etc. of others, faking your identity, illegal searching, and collecting information about children. I think that bullying and trolling is extremely serious. There are plenty of cases of people causing harm to themselves and/or others due to being bullied online. Bullying, whether it be offline or online, is not ok. Sharing other peoples personal information, especially password, is also very serious. This is especially true now with all of the technological advancements that we have. There are numerous crimes that someone could commit with this information. Faking your identity is another violation that I see as serious. There are lots of possible consequences of someone faking their identity. The mane ones are the cases where people commit identity fraud to gain access to somebody else’s assets. There are also cases where people are just pretending to be other people to gain money or gain emotional connections to people. A good example of this the show Catfish. There are many cases where people make connections with someone, sometimes for years, and then they find out that the person that they have been talking to has been lying the entire time. This does not always end up badly, but usually does. Illegal searching somewhat speaks for itself. If someone is searching illegal things, it is usually because they plan to partake in such illegal acts. This is not always true, but this is usually the case. collecting the information of children is also a very serious issue. Who know what people might use this information for. Depending on what the information is, it could lead to serious repercussions. I am not saying that the other actions talked about are not serious, these are just the five that I believe are more serious.