TechKnowSurge
Cisco CCNA 5.1 Cisco CyberOps Associate 1.3 Cisco CCST Cybersecurity 1.1 Cisco CCST Cybersecurity 1.2 Cisco CyberOps Associate 1.5 CompTIA SecurityX 1.3 CompTIA Network+ 4.3 Cisco CCST Cybersecurity 4.3
VideoNetworkFree

Key Security Concepts

Core security concepts—assets, threats, threat agents, vulnerabilities, exploits, exposure, and risk—form the foundation of any effective cybersecurity strategy. Understanding how these terms relate to one another is essential for assessing and reducing organizational risk.

Complete this video to capture a CTF flag worth 1 point.

About this video

Every security program is built on a shared vocabulary that allows professionals to analyze, communicate, and address threats consistently. An asset is any resource of value to an organization, ranging from physical infrastructure and financial holdings to data, software, skilled personnel, and brand reputation. Because losing or compromising an asset can hinder operations or cause lasting damage, identifying and classifying assets is the starting point for any security analysis. Once assets are identified, the focus shifts to what can go wrong. A threat is any potential event that could harm an asset—data could be stolen, altered, deleted, or made unavailable, each of which maps directly to a breach of confidentiality, integrity, or availability within the CIA triad. A threat agent is the entity that carries out or enables that threat, whether a malicious hacker, a negligent insider, or an automated attack. Mitigation refers to the controls put in place to reduce the likelihood or impact of a threat, though every control introduces its own weaknesses. A vulnerability is a flaw or gap in a control or technology that can be targeted, and exploitation is the act of actively leveraging that weakness to gain unauthorized access or cause harm. Exposure occurs when an asset is left unprotected and accessible to potential threats, whether through a misconfiguration, a procedural failure, or an unpatched flaw. Risk ties these concepts together through a straightforward equation: risk equals the probability that a harmful event will occur multiplied by the impact that event would have on the organization. The level of acceptable risk drives decisions about how much effort and investment to apply to security controls. Because no single control is foolproof, the principle of defense in depth calls for layering multiple independent safeguards so that if one fails, others remain in place to prevent exposure and limit damage.

What you'll learn

What's covered

Key Security Concepts

Aligned to

Cisco CCNA
5.1 Define key security concepts
Cisco CyberOps Associate
1.3 Describe security terms
1.5 Describe the principles of the defense-in-depth strategy
Cisco CCST Cybersecurity
1.1 Define essential security principles
1.2 Explain common threats and vulnerabilities
4.3 Explain risk management
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise
CompTIA Network+
4.3 Given a scenario, apply network security features, defense techniques, and solutions

Key terms

Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Threat
Any potential event or action that could cause harm to a system, network, or organization.
Threat Actor
An individual or group responsible for a security incident or attack.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.
Exposure
A condition in which an asset is left unprotected and potentially accessible to threat actors, increasing the likelihood of harm. Exposure is often measured by the time window between a vulnerability being introduced and a control being applied.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Defense in Depth
A security strategy that applies multiple layers of controls so that if one layer fails, additional layers continue to protect the asset.

Transcript

Assets

An asset is something of value. If the company has things that are of value, those are assets for the company. An example of it would be a building; a building is an asset for the company. Straight out cash is obviously value for the company, if the company has a lot of cash on hand. The data that it stores could be an asset for the company that it can use. If that data is customer data, if it has a list of customers, whether potential customers or their own customers, that is an asset that the company has. The people: if you have really great people working for you, those people are assets to the company. If you have some sort of program or code, that code itself could be an asset for the company. If the company has a really strong reputation that's out there, a great reputation, then that reputation is an asset for the company.

So an asset is anything of value for the company that, if the company were to lose that resource, would be devastating to the company or would hinder the company from growing. Those are assets.

Threats

Whatever could happen to that asset is a threat. An example right here is, let's say we have data that we are storing and that data is considered an asset for the company. That asset could be stolen. It could be copied. It could be altered. It could be deleted. So something could happen to that asset that would hurt the company.

When we look at the security triad, deleted means that it's no longer available. When we see that it's altered, that's the integrity of the data. And when we see that it's stolen or copied, that's the confidentiality of that data. So it fits within that security triad.

Threat Agents

When it comes to threats, then we have the threat agent. The agent is what is actually causing the threat for this data. So in this example right here, we have a hacker that is trying to steal or alter this data right here. And so the hacker is the threat agent in this example.

Mitigation

We obviously want to protect our data, and so what we're going to do is put things up to protect that data. In this example right here, we're putting a fence up with a gate on it to protect that data so that a hacker cannot get to it. So that's mitigation. Mitigation is to lessen the threat of something happening.

Vulnerabilities

Then we have vulnerability. To be vulnerable means that it's open for attack or harm. Before, our data was sitting out and could be accessed by anyone because we didn't have it protected. That is what it means to be vulnerable. So what we did is we put a wall around it and we put a gate around it to protect the data so that a hacker would not be able to get to the data.

But the problem is that even these technologies that we put around it, a wall or a gate, have different vulnerabilities in themselves. There's ways to get through this. For instance, in this case right here, perhaps through this gate people still need to access this data. So this gate has some sort of lock on it so you can open it up and access that data. Well, that lock is probably a weak point. There's probably some way a hacker might be able to pick that lock and get into the gate. Or the gate is also not quite as strong as the rest of the wall, so perhaps there's something that can break that gate down so it can access the data.

So these are vulnerabilities of these different technologies that we implemented, and things that we will need to do mitigating with. We've already mitigated against it being out in the open, but there's still things that we need to tackle to see if we can solve for, to make sure that we're reducing the amount of threats there are to this data and reducing the vulnerability that it has.

Exploitation

An exploitation is when a hacker is going to exploit a vulnerability. So an example that we gave was there's a lock on this gate, and so maybe this hacker knows how to pick that particular lock that is on the gate. And so what that hacker is doing is exploiting a weakness in this technology to get to the data, and so that is exploitation.

Exposure

Exposure is when one of your assets is then put out there and exposed to these different threats. An example that I have right here is, let's say this person right here needs to access the data, but after they leave they forget to close the gate. And so now the data is open for anybody to come and grab it. And so now that is an exposure that's happening, that this data then is exposed to the outside world.

Defense in Depth

What we really want to do on our networks is take an approach of defense in depth. What that means is that we realize whatever we're going to put out there is susceptible to some sort of vulnerability. So we put a gate up there, but the lock can be picked, or maybe it's left open for somebody to walk in and grab that data. And so what we do is, instead of just relying on the gate, maybe we also put a guard out in front of that gate to protect that data. Or perhaps we encrypt the data that's on there, so even if it is stolen, they can't do anything with the data because it's all encrypted and you need the keys to that encryption. Maybe we put a camera so that if it is stolen, we're able to see who stole it and go and grab it and get it back.

So the idea behind this is we put in multiple layers. Any one of these layers could fail, and probably will fail at some point in time, because that's how technology goes. So we put in multiple layers, multiple lines of defense, so that we make sure that there is no exposure of the data.

Risk

When we implement all of these mitigation steps to ensure the security of our data, we're reducing the amount of risk. Risk is the chances that something is going to happen, and it also factors in, there's actually an equation for it. Risk equals the probability of something happening, how probable is it, times the impact that it's going to have to the company.

So as we take all of these steps to secure this data, what are the chances now that this hacker is going to be able to break into the system and get this data? And if they were to get that data, how impactful would it be to the business, and how devastating would it be to the business? That is the amount of risk, and the risk is going to determine how many steps we're going to take to actually protect this data.

In Summary

We have an asset that needs to be protected. So that is the asset. It is prone to some sort of threat. For instance, the data could be stolen, so the threat is the fact that it could be stolen. We have a threat agent, that is the who, whatever is going to be the perpetrator, whoever is going to steal the data. So in this case, we've got the hacker right there.

We take steps to mitigate the risk. So we put things in place to mitigate this risk and lessen the likelihood that this is going to be a problem. Each one of these things that we implement and put into place has some sort of vulnerability to it. For instance, the lock on the gate is a vulnerability because it's a single point that can fail or can be picked, or something that we can use to leverage that weak point to get into here.

If we were to leverage that vulnerability, that means that we're exploiting that vulnerability, so that we can hack this. If for some reason data gets out and this information is stolen, that's an exposure. Or if somebody leaves the gate open, that's an exposure. So we expose the data to the outside world.

We have then this idea of risk, the probability that this is going to happen and what the impact would be to the company. And then defense in depth. Defense in depth is the idea that we're going to put multiple safeguards on here to protect this data, realizing that each one of those safeguards that we put out there is going to help but has its own vulnerabilities that can be leveraged. So we are going to put in multiple walls and multiple steps in here to guard this data.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →