Skip to main content

Learning path3 levels8 steps

Cybersecurity basicsfrom staying safe online to testing for security.

Three levels, read in order: what security protects and the habits that stop most attacks, how testers find weaknesses before attackers do, and how organizations manage security risk across their own code and their vendors'.

Level 1

Start hereStudents, families, and anyone curious. No experience needed.

What security protects, the everyday habits that stop most attacks, and the common ways software gets broken into.

  1. 01ArticleWhat Is Cybersecurity? The Ideas Behind Keeping Systems SafeThe ideas the whole field is built on: confidentiality, integrity, availability, and risk.Read →
  2. 02ArticleStaying Safe Online: Passwords, Sign-In, Phishing, and UpdatesPasswords, multi-factor sign-in, phishing, and updates: the habits that stop most attacks.Read →
  3. 03ArticleHow Software Gets Attacked: Common Vulnerabilities in Plain EnglishThe common vulnerabilities in software, each with the defense that stops it.Read →

Level 2

FoundationsNew testers, developers, and career changers.

How testers find security weaknesses on purpose, legally and systematically, and how a development team reduces security risk end to end.

  1. 04ArticleSecurity Testing Basics: Finding Weaknesses Before Attackers DoThreat modeling, abuse cases, access control tests, and where scanners and penetration tests fit.Read →
  2. 05ArticleSeven Steps to Reducing Software Security RiskSeven steps that build security into the way a team designs, codes, and tests.Read →

Level 3

PractitionerTesters, engineers, and leads responsible for release quality.

Rank security alongside other quality risks, and manage the risk that arrives with outsourced code, vendors, and third-party components.

  1. 06ArticleQuality Risk Analysis: Five Techniques, Seven Lifecycle Benefits, One ProcessRank security and other quality risks by likelihood and impact, so effort goes where it matters.Read →
  2. 07ArticleQuality Risks in Integrating Outsourced and Third-Party ComponentsThe risks that arrive with outsourced and third-party components, and how to test for them.Read →
  3. 08ArticleVerifying Third-Party Quality: Entry and Exit Criteria Across the Vendor BoundaryEntry and exit criteria that hold vendors to a quality bar before their work reaches production.Read →

For teams

Taking a whole team through this?We teach it, coach it, and certify it.

Keep reading

Related reading

Practices

Where this leads

Working on something like this?Talk to the people who wrote it.

Book a call