Principles of Cyber Defense and Ethics offers students a comprehensive introduction to the critical role cybersecurity plays across all areas of an organization. Through hands-on exploration and real-world scenarios, students will learn how to leverage the built-in security features of modern operating systems, identify and mitigate vulnerabilities in both wired and wireless networks, and implement strategies to protect personal and organizational information assets. The course also introduces students to key cybersecurity domains such as ethical hacking, incident response, and difital forensics, while providing insight into career pathways and industry certifications. Emphasis is placed on developing technical proficiency, analytical thinking, and effective communication skills essential for success in the rapidly evolving field of cybersecurity.
Core Standards of the Course
STRAND 1 Understand Security Careers and Ethics
Principles of Cyber Defense and Ethics Core
Standard 1 Understand Careers and Professional organizations in Cybersecurity.
Identify careers in Cybersecurity.
Identify education and/or certifications needed to work in the Cybersecurity field.
Identify Cybersecurity professional organizations.
Standard 2 Understand Ethics of Cybersecurity
Understand the different categories of hacking including: authorized hacker, unauthorized hacker, semi authorized hacker.
Understand the purpose of an Acceptable Use Policy.
Understand the major events in Cybersecurity that have influenced the laws and governance of Cybersecurity.
STRAND 2 Understanding Security Basics.
Principles of Cyber Defense and Ethics Core
Standard 1 Understand core security principles.
Understand the concepts of the cia triad (confidentiality, integrity, availability).
Understand how threat and risk impact principles; principles of least privilege.
Understand the purpose ofthe NIST Security Framework.
Understand what Personally Identifiable Information (PII) is and the importance of securing it.
Standard 2 Understand physical security.
Understand site security - tailgating, limited access, door locks, server locks, cable locks.
Understand device security -
Removable devices and drives - juice jacking and evil usbs
Access control - remote device wipe, password lockout, data recovery on lost/ stolen devices, and device destruction.
Reformatting a device - partial vs full write.
Standard 3 Understand Internet security.
Understand browser settings including things like password management, cookies, and storing personal information.
Understand the difference between http and https. How to identify if a website is secure.
STRAND 3 Understand Social Engineering
Principles of Cyber Defense and Ethics Core
Standard 1 Understand Social Engineering
Understand the definition and intent of social engineering.
Understand the principles of social engineering - authority, intimidation, consensus, scarcity, urgency, familiarity/ trust.
Standard 2 Understand types of Social Engineering
Understand the methods and prevention of the following social engineering methods - Phishing (and similar attacks), tailgating, shoulder surfing, dumpster diving, reconnaissance, and watering holes.
STRAND 4 Authentication Methods
Principles of Cyber Defense and Ethics Core
Standard 1 Understand user authentication.
Understand multifactor, smart cards, and RADIUS (Remote Authentication Dial-In User Service)
Understand the certificate chain, biometrics, Kerberos, and time skew using Run As to perform administrative tasks and password reset procedures.
Disable Log On Locally and guest accounts.
Standard 2 Understand permissions.
Understand the following: file; share; registry; Active Directory; enabling or disabling inheritance.
Understand behavior when copying and moving files within the same disk or onto another disk.
Understand basic and advanced user permissions; take ownership; delegation.
Understand multiple user groups and that users can belong to multiple groups.
Understand operating systems native encryption options.
Standard 3 Understand password policies.
Understand password policies: password complexity; account lockout; password length; password history; enforce by using group policies; and common attack methods; avoid common passwords or phrases.
STRAND 5 Encryption
Principles of Cyber Defense and Ethics Core
Standard 1 Understand encryption.
Understand the history of encryption - Caesar, Enigma, Vigenere ciphers.
Understand public key and private keys and how they are implemented.
Understand the implementation and recognize the following encryption algorithms - MDS, SHA-256, AES, RSA.
Understand device isolation: DMZ(Demilitarized zone); Server and Domain Isolation.
Understand the purpose of a honeypot.
Standard 4 Understand protocol security.
Understand the following: protocol spoofing; IPsec; tunneling; DNSsec (Domain Name System Security Extensions)
Understand how a network sniffer works and how to use one on a network.
Standard 5 Understand wireless security.
Understand advantages and disadvantages of specific security types; network keys, SSID (Service Set Identifier), and MAC (Message Authentication Code or Mandatory Access Code) filters.
Workplace Skills
Problem Solving
Critical Thinking
Legal Requirements/Expectations
http://www.uen.org - in partnership with Utah State Board of Education
(USBE) and Utah System of Higher Education (USHE). Send questions or comments to USBE
Specialist -
Kristina Yamada
and see the
CTE/Digital Technology website.
For general questions about Utah's Core Standards contact the Director -
THALEA LONGHURST.
These materials have been produced by and for the teachers of the
State of Utah. Copies of these materials may be freely reproduced
for teacher and classroom use. When distributing these materials,
credit should be given to Utah State Board of Education. These
materials may not be published, in whole or part, or in any other
format, without the written permission of the Utah State Board of
Education, 250 East 500 South, PO Box 144200, Salt Lake City, Utah
84114-4200.