| Lecture 1Security and Safety Fundamentals | Introductory Concepts | Introduction to CyBOKView mapped subsections- 1.1 Cyber Security Definition
- 1.3.1 Means and Objectives of Cyber Security
- 1.3.2 Failures and Incidents
- 1.3.3 Risk
- 1.4.3 Latent Design Conditions
| Full |
| Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1 Cyber-Physical Systems and Their Security Risks
- 21.1.1 Characteristics of CPS
- 21.1.2 Protections Against Natural Events and Accidents
- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
| Full |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.2 What Is Risk?
- 2.6.1 Component vs. Systems Perspectives
- 2.6.2 Elements of Risk
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
| Partial |
| Attacks & Defences | Adversarial BehavioursView mapped subsections- 7.1 A Characterisation of Adversaries
- 7.2 The Elements of a Malicious Operation
| Partial |
| Lecture 2Security-Informed Safety | Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1.2 Protections Against Natural Events and Accidents
- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
- 21.1.3.2 High-Profile, Real-World Attacks Against CPSs
- 21.2 Crosscutting Security
- 21.2.1 Preventing Attacks
- 21.2.2 Detecting Attacks
- 21.2.3 Mitigating Attacks
| Full |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.6.1 Component vs. Systems Perspectives
- 2.6.2 Elements of Risk
- 2.6.3 Risk Assessment and Management Methods
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
| Partial |
| Attacks & Defences | Adversarial BehavioursView mapped subsections- 7.1 A Characterisation of Adversaries
- 7.2 The Elements of a Malicious Operation
- 7.3 Models to Understand Malicious Operations
| Partial |
| Lecture 3Hazard Analysis and Assurance | Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.2 What Is Risk?
- 2.3 Why Is Risk Assessment and Management Important?
- 2.4 What Is Cyber Risk Assessment and Management?
- 2.6 Risk Assessment and Management Principles
- 2.6.1 Component vs. Systems Perspectives
- 2.6.2 Elements of Risk
- 2.6.3 Risk Assessment and Management Methods
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
- 2.6.6 Security Metrics
| Full |
| Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1 Cyber-Physical Systems and Their Security Risks
- 21.1.2 Protections Against Natural Events and Accidents
- 21.1.3 Security and Privacy Concerns
- 21.2 Crosscutting Security
| Partial |
| Human, Organisational & Regulatory Aspects | Human FactorsView mapped subsections- 4.2.1 Fitting the Task to the Human
- 4.3 Human Error
- 4.4.2 Mental Models of Cyber Risks and Defences
- 4.6 Stakeholder Engagement
| Partial |
| Lecture 4IoT, Cyber-Physical Systems and Security | Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1 Cyber-Physical Systems and Their Security Risks
- 21.1.1 Characteristics of CPS
- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
- 21.2 Crosscutting Security
- 21.2.1 Preventing Attacks
- 21.2.2 Detecting Attacks
- 21.2.3 Mitigating Attacks
- 21.3.5 Medical Devices
- 21.3.6 The Internet of Things
| Full |
| Infrastructure Security | Network SecurityView mapped subsections- 19.1.1 Security Goals in Networked Systems
- 19.1.2 Attacker Models
- 19.2.4 Wireless Networks
- 19.3 Network Protocols and Their Security
- 19.3.3.2 IPv6 Security
- 19.3.4.5 Network Segmentation
- 19.3.4.6 Wireless Security
| Partial |
| Systems Security | Authentication, Authorisation & AccountabilityView mapped subsections- 14.3.1 Access Control
- 14.3.2 Enforcing Access Control
- 14.5 Authentication
- 14.6 Accountability
| Partial |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.6.1 Component vs. Systems Perspectives
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
| Partial |
| Lecture 5Wireless and Short-Range Threats | Infrastructure Security | Network SecurityView mapped subsections- 19.1 Security Goals and Attacker Models
- 19.1.1 Security Goals in Networked Systems
- 19.1.2 Attacker Models
- 19.2.4 Wireless Networks
- 19.3 Network Protocols and Their Security
- 19.3.4 Security on the Link Layer
- 19.3.4.1 Port-Based Network Access Control
- 19.3.4.6 Wireless Security
- 19.4.3 Network Security Monitoring
- 19.4.5 Network Access Control
- 19.4.7 DoS Countermeasures
| Full |
| Infrastructure Security | Physical Layer and Telecommunications SecurityView mapped subsections- 22.2 Jamming and Jamming-Resilient Communication
- 22.2.1 Coordinated Spread Spectrum Techniques
- 22.2.2 Uncoordinated Spread Spectrum Techniques
- 22.2.3 Signal Annihilation and Overshadowing
- 22.3 Physical-Layer Identification
- 22.4 Distance Bounding and Secure Positioning
- 22.4.1 Distance Bounding Protocols
- 22.4.3 Physical-Layer Attacks on Secure Distance Measurement
- 22.6.1 Near-Field Communication
| Full |
| Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
- 21.3.5 Medical Devices
- 21.3.6 The Internet of Things
| Partial |
| Systems Security | Authentication, Authorisation & AccountabilityView mapped subsections- 14.3.1 Access Control
- 14.5 Authentication
- 14.5.4 Facets of Authentication
| Partial |
| Infrastructure Security | Applied CryptographyView mapped subsections- 18.1.5 Message Authentication Code Schemes
- 18.1.6 Authenticated Encryption Schemes
- 18.1.8 Diffie-Hellman Key Exchange
- 18.3 Key Management
- 18.5.1 Transport Layer Security
| Partial |
| Lecture 6IoT in Safety-Critical Contexts | Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1 Cyber-Physical Systems and Their Security Risks
- 21.1.1 Characteristics of CPS
- 21.1.2 Protections Against Natural Events and Accidents
- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
- 21.1.3.2 High-Profile, Real-World Attacks Against CPSs
- 21.2 Crosscutting Security
- 21.3 CPS Domains
- 21.3.1 Industrial Control Systems
- 21.3.2 Electric Power Grids
- 21.3.3 Transportation Systems and Autonomous Vehicles
- 21.3.4 Robotics and Advanced Manufacturing
- 21.3.5 Medical Devices
- 21.3.6 The Internet of Things
| Full |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.6.1 Component vs. Systems Perspectives
- 2.6.2 Elements of Risk
- 2.6.3 Risk Assessment and Management Methods
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
| Full |
| Infrastructure Security | Network SecurityView mapped subsections- 19.1.1 Security Goals in Networked Systems
- 19.1.2 Attacker Models
- 19.2.4 Wireless Networks
- 19.3.3.2 IPv6 Security
- 19.3.4.5 Network Segmentation
- 19.3.4.6 Wireless Security
- 19.4.3 Network Security Monitoring
- 19.4.7 DoS Countermeasures
| Partial |
| Infrastructure Security | Physical Layer and Telecommunications SecurityView mapped subsections- 22.2 Jamming and Jamming-Resilient Communication
- 22.4 Distance Bounding and Secure Positioning
- 22.5 Compromising Emanations and Sensor Spoofing
- 22.5.2 Sensor Compromise
- 22.6 Physical Layer Security of Selected Communication Technologies
| Partial |
| Lecture 7Resilience and Mitigation | Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.2 Crosscutting Security
- 21.2.1 Preventing Attacks
- 21.2.2 Detecting Attacks
- 21.2.3 Mitigating Attacks
| Full |
| Attacks & Defences | Security Operations & Incident ManagementView mapped subsections- 8.1 Fundamental Concepts
- 8.2 Monitor: Data Sources
- 8.2.1 Network Traffic
- 8.3 Analyse: Analysis Methods
- 8.3.1 Misuse Detection
- 8.3.2 Anomaly Detection
- 8.4 Plan: Security Information and Event Management
- 8.5 Execute: Mitigation and Countermeasures
- 8.5.2 Denial-of-Service
- 8.6.4 Situational Awareness
- 8.7 Human Factors: Incident Management
- 8.7.1 Prepare: Incident Management Planning
- 8.7.2 Handle: Actual Incident Response
- 8.7.3 Follow-Up: Post-Incident Activities
| Full |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.6.1 Component vs. Systems Perspectives
- 2.6.3 Risk Assessment and Management Methods
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
- 2.6.6 Security Metrics
- 2.7 Business Continuity: Incident Response and Recovery Planning
| Full |
| Infrastructure Security | Network SecurityView mapped subsections- 19.3.4.5 Network Segmentation
- 19.3.4.6 Wireless Security
- 19.4.1 Firewalling
- 19.4.2 Intrusion Detection and Prevention Systems
- 19.4.3 Network Security Monitoring
- 19.4.5 Network Access Control
- 19.4.6 Zero Trust Networking
- 19.4.7 DoS Countermeasures
| Partial |
| Infrastructure Security | Physical Layer and Telecommunications SecurityView mapped subsections- 22.2 Jamming and Jamming-Resilient Communication
| Partial |
| Systems Security | Authentication, Authorisation & AccountabilityView mapped subsections- 14.3 Authorisation
- 14.3.1 Access Control
- 14.3.2 Enforcing Access Control
- 14.5 Authentication
- 14.6 Accountability
- 14.6.1.1 Audit Policies
- 14.6.1.2 Preserving the Evidence
| Partial |
| Lecture 8Applied Case Studies | Infrastructure Security | Cyber-Physical Systems SecurityView mapped subsections- 21.1 Cyber-Physical Systems and Their Security Risks
- 21.1.2 Protections Against Natural Events and Accidents
- 21.1.3 Security and Privacy Concerns
- 21.1.3.1 Attacks Against CPSs
- 21.2 Crosscutting Security
- 21.2.1 Preventing Attacks
- 21.2.2 Detecting Attacks
- 21.2.3 Mitigating Attacks
- 21.3.5 Medical Devices
- 21.3.6 The Internet of Things
| Full |
| Human, Organisational & Regulatory Aspects | Risk Management & GovernanceView mapped subsections- 2.6.1 Component vs. Systems Perspectives
- 2.6.2 Elements of Risk
- 2.6.3 Risk Assessment and Management Methods
- 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
| Full |
| Infrastructure Security | Network SecurityView mapped subsections- 19.1.1 Security Goals in Networked Systems
- 19.1.2 Attacker Models
- 19.2.4 Wireless Networks
- 19.3 Network Protocols and Their Security
- 19.3.3.2 IPv6 Security
- 19.3.4.6 Wireless Security
- 19.4.3 Network Security Monitoring
- 19.4.7 DoS Countermeasures
| Partial |
| Attacks & Defences | Security Operations & Incident ManagementView mapped subsections- 8.1 Fundamental Concepts
- 8.2 Monitor: Data Sources
- 8.2.1 Network Traffic
- 8.3 Analyse: Analysis Methods
- 8.5 Execute: Mitigation and Countermeasures
- 8.6.4 Situational Awareness
- 8.7.2 Handle: Actual Incident Response
- 8.7.3 Follow-Up: Post-Incident Activities
| Partial |
| Human, Organisational & Regulatory Aspects | Human FactorsView mapped subsections- 4.2.1 Fitting the Task to the Human
- 4.3 Human Error
- 4.4.2 Mental Models of Cyber Risks and Defences
- 4.6 Stakeholder Engagement
| Partial |