TechKnowSurge
NIST CSF GV.RM-02 ISC2 CC 1.2 NIST 800-53 PM-9 Cisco CCST Cybersecurity 4.3 ISC2 CC 1.1 ISC2 CC 1.4 NIST CSF GV.PO-01 Cisco CCST Cybersecurity 1.1
VideoSecurityFree

Protection - Protecting a Cybersecurity Domain

Protecting a cybersecurity domain requires balancing accessibility with security, layering technical and organizational controls, and making informed risk management decisions. This overview introduces the core principles that shape an effective cybersecurity program.

Complete this video to capture a CTF flag worth 1 point.

About this video

One of the foundational challenges in cybersecurity is the inherent tension between security and accessibility. The most secure system is one that no one can reach — but that also makes it useless. Organizations must continuously calibrate how much friction is acceptable, pushing back when users demand exceptions that compromise security, while also relaxing controls when they unnecessarily obstruct legitimate work. Getting that balance right is one of the defining responsibilities of any security function. A cybersecurity domain encompasses everything an organization is expected to secure and manage, from networks and data to people and processes. Defense in depth is the principle that no single control is sufficient on its own — multiple overlapping safeguards should protect any given resource, so that if one layer fails, others remain. Technical solutions form a significant part of this layered approach, covering areas such as network architecture, data confidentiality, integrity, and availability. A formal cybersecurity program provides the structure needed to coordinate people, processes, and systems at scale. Without it, security depends entirely on the individual knowledge of each employee, and a single uninformed decision can expose the entire organization. Policies must be backed by enforceable controls and real consequences to carry any weight. Frameworks help establish the standards and procedures that define what an acceptable security posture looks like for a given business. Underlying all of it is risk management — the recognition that security is never absolute, and that decisions about which controls to implement must be based on a clear-eyed assessment of cost versus risk.

What you'll learn

What's covered

Protecting Your Cyber Security Domain

Aligned to

NIST CSF
GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained.
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
ISC2 CC
1.2 Understand risk management concepts
1.1 Understand cybersecurity concepts
1.4 Understand cybersecurity controls
NIST 800-53
PM-9 Risk Management Strategy
Cisco CCST Cybersecurity
4.3 Explain risk management
1.1 Define essential security principles

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Technical Controls
Security measures implemented through hardware or software to protect systems and data, such as firewalls, encryption, and access controls.
Security Program
An organized set of policies, processes, people, and controls managed holistically to protect an organization's cybersecurity domain.

Topics

Cybersecurity Defense In Depth Risk Management Security Controls Access Control Security Program

Transcript

Security Versus Accessibility

There's this real tug-of-war between security and accessibility. What I mean by that is that when you increase one, you're actually decreasing the other, and so there's a real problem with this.

So let me give you an example. Let's say we have some data and we need users to be able to access that data, so we network all these computers so these users have access to that data. But because that data is confidential and only certain users can have access to it, we put these controls in place to be able to screen or protect that data from unauthorized access, from threats out there that want to access that data. So the most secure thing we can actually do to protect that data is just unplug everything. Just don't give anybody access to that data. That is the most secure thing that we can do. And so there's this real tug-of-war, with: well, that's not reasonable, because now what good is that data? It's useless data if people can't access it and use that data. And so we really have to find this balance between the two.

One reason why I bring this up is because it's a real challenge of IT departments and security departments, and your cybersecurity program, finding this right balance. So there are going to be times when you're going to have to listen to your users and find out what they're complaining about, and either pull back some of the security measures, or change some of the security measures, or maybe implement new security measures. There's some changes that you're going to have to make, because you have to facilitate the business doing business. That's what they're there for. And if you constantly are putting up blockers, then that's going to be problematic.

But the flip side is true as well. The flip side is, if you never say no to anyone, then is it really a security program? If every exception that comes along the way you approve, is it really a security program? So finding that right balance between security and accessibility is a pretty critical part to all of this.

The Cybersecurity Domain

Just a quick reminder: when I'm talking about cybersecurity, we can think of it in as strict a sense of the term as what cybersecurity is, or we're going to actually just define this as anything that falls under your umbrella. Anything that falls under your purview of control, anything that's expected that you are going to help implement security measures for. So that's how we're defining cybersecurity domain: anything that you're going to have to manage and be in charge of.

Defense in Depth

We'd also talked about that term defense in depth, which just means that we're going to put multiple safeguards in place for any particular resource. So for instance, if that resource is data, we're not going to just put the gate there, because the gate could be left open. We're going to also put a guard there, but the guard could also be bribed or blackmailed. And so we're going to also encrypt the data. So we're putting multiple measures in place to safeguard this data.

Technical Solutions

There are a lot of technical solutions that we're going to want to put in place to make sure we're safeguarding that data. We actually have a whole module on the technology, specifically around networking. And we're also going to talk about that when we talk about confidentiality, integrity, and availability.

A Cybersecurity Program

You're going to want to have a fully functioning security program, because the only way that you're going to get a group of people and processes and systems all set up to be as secure as possible is if you have somebody that is looking at the overall picture from a security standpoint and figuring out where the weaknesses are, and doing the training and making sure the training is happening. Otherwise, you're relying all on the individual knowledge, from a security standpoint, of all the individuals. And one person who doesn't really know what they're doing can expose the whole company.

That security program has a bunch of controls on there to make sure that people are actually following through with what the policies say that they're going to follow through. It's not just enough to have a policy out there, but that the control actually backs it up to reinforce it, that there's some sort of disciplinary actions or some sort of consequences if things are not done in a secure manner.

One of the things that can help us implement those controls is some sort of framework — a framework that helps us set up our policies, standards, procedures, and controls to make sure that they're at a level that's acceptable for that business.

Risk Management

Really, a lot of this boils down to risk management. And that's because you could do everything right and things still go wrong, or you could do everything wrong and things still go right for you. So it's not as clear-cut as you would think it would be. There are certain things that you'll implement that help protect your networks, help protect your cybersecurity domain, but it's not foolproof.

And so what you do is you assess: what is the cost of implementing this? What is the risk if I don't implement this? And then you weigh those out to determine what things you're going to implement and what things you're not going to implement, or at least put things into a priority order. So a lot of this is around risk management.

In Review

What we went over is things like security versus accessibility and how there's a balance between those two. We talked about the cybersecurity domain and what that looks like. We talked about defense in depth, and making sure you're protecting your resources from multiple angles, multiple ways. We just briefly mentioned technical solutions. And then we talked about a cybersecurity program, the fact that you really need a cybersecurity program for businesses. And then we wrap things up talking about, or just mentioning really, risk management.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →