Manning Early Access Program (MEAP)
Read chapters as they are written, get the finished eBook as soon as it’s ready, and receive the pBook long before it's in bookstores.
Whether you work in finance, HR, operations, or law, you need to understand the vocabulary, mental models, and practical judgments of cybersecurity. Fundamentals of Cybersecurity introduces cybersecurity fundamentals in plain English, with practical examples, clear illustrations, and real-world scenarios. Based on their experience teaching over 25,000 students, authors Paulo Carreira and Andreé Miranda Louraço align cybersecurity concepts with practical skills like recognizing a phishing attempt, knowing what to do when a staff member leaves, and understanding why a firewall rule matters.
You’ll start with the fundamentals: assets, threats, vulnerabilities, and how risk is identified, assessed, and treated. From there, you’ll work through security controls and defense in-depth, discover governance frameworks, and learn the full incident response lifecycle, business impact analysis, and disaster recovery. You’ll also dive into access control and understand networking from the ground up, and even understand the attacker’s playbook: malware, phishing, social engineering, on-path attacks, DoS, insider threats, and more.
The final chapters cover the security operations that hold everything together, from cryptography, to system hardening, to the awareness programs that turn employees into a first line of defense. Each chapter builds on the last, moving from core security principles, through risk and governance, into the operational disciplines that keep real organizations safe.
Best of all, the book follows the six knowledge domains of the ISC2 Certified in Cybersecurity (CC) exam, making it an ideal starting point for anyone pursuing their first credential. As an added bonus, full practice exams ensure that you’re ready to tackle the ISC2 and get fully certified in cybersecurity!
The CIA triad—confidentiality, integrity, and availability—forms the foundation of cybersecurity by ensuring information is protected from unauthorized access, alteration, and disruption.
[1]
Data classification organizes information into categories such as sensitive, confidential, PII, and PHI, enabling organizations to apply appropriate protections and comply with regulations.
[1]
Risk management enables organizations to identify, assess, and prioritize risks, ensuring that resources are focused on the most significant threats to assets and operations.
[1]
Risks are prioritized based on their likelihood and potential impact, with the highest priority given to those that could cause the most harm to critical assets.
[1]
Risk treatment strategies include mitigation, transfer, avoidance, and acceptance, each chosen based on cost-benefit analysis and organizational risk tolerance.
[1]
Security controls are categorized as physical, technical, or administrative, and are layered in a defense-in-depth strategy to provide comprehensive protection.
[1]
Defense-in-depth layers multiple security controls so that if one fails, others remain to prevent, detect, or respond to incidents, creating a resilient security posture.
[1]
Cybersecurity governance ensures alignment with laws, regulations, and standards, and establishes policies and procedures that support business objectives and compliance.
[1]
Regulations like GDPR and HIPAA require organizations to implement strict data protection measures and influence how personal and sensitive data is managed.
[1]
A BCP outlines procedures to maintain essential business functions during and after disruptions, ensuring operational resilience and rapid recovery.
[1]
A BIA assesses the potential effects of disruptions on critical operations, helping organizations prioritize recovery efforts and allocate resources effectively.
[1]
A DRP includes strategies for backup and recovery, types of recovery sites, and regular testing through exercises to ensure quick restoration of critical systems after a disaster.
[1]
what's inside
The CIA triad, risk assessment, and governance frameworks
Identity, authentication, authorization, and physical access controls
Networking fundamentals, common attacks, and layered defensive controls
The full incident response, business continuity, and disaster recovery lifecycle
Two complete ISC2 CC practice exams
about the reader
For HR, finance, legal, operations, and IT professionals who need to understand cybersecurity to do their jobs well—and for anyone considering cybersecurity as a career.
about the authors
Paulo Carreira, PhD, is Associate Professor of Information Systems at Instituto Superior Técnico, University of Lisbon, and holds the CISSP, ISO 27001, ISO 27701, and IAPP Fellow of Information Privacy certifications.
Andreé Miranda Louraço, MSc, is a Cybersecurity Manager who leads the global security awareness program for one of the world’s largest energy drink brands, spanning more than 180 countries. He holds the CISSP and multiple information privacy management certifications.
eBook
pdf, ePub, online
$47.99
$28.79
you save $19.20 (40%)
print
includes eBook
$59.99
$35.99
you save $24.00 (40%)
with subscription
free or 50% off
$24.99
pro $24.99 per month
access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!