Week 1 · Topic 1 — Digital Security Foundations
CIA Triad, Threats & a Real Incident
Benchmark 11.4.2.1 Apply the CIA triad to real cases · Duration 3 periods (≈120 min)
Name:
Class:
Date:
Learning intentions
- I can define Confidentiality, Integrity and Availability.
- I can tell apart threat, vulnerability, risk and attack.
- I can apply CIA to analyse a real case.
Success criteria
- My CIA classification of 6 scenarios is 100% correct.
- My 4 definitions are in my own words.
- My case-study response links to at least 2 of C, I, A.
Materials
News article on a recent cyber incident · Pen · Sticky notes
Task 1 — Classify against CIA
- Read each scenario. Tick which pillar(s) it breaks: C, I or A.
- Scenarios: stolen exam paper · deleted photos · site down 4 hrs · edited grade · phishing password · dropped USB.
| Scenario | C | I | A | Why |
|---|---|---|---|---|
Task 2 — 4 key definitions
- In your own words, define: threat, vulnerability, risk, attack.
- Give one school example for each.
| Term | Definition | School example |
|---|---|---|
Task 3 — Case study response
- Read the incident handout. In 6–8 sentences: what happened, which CIA pillars were broken, one control that could have prevented it.
Reflection
The pillar I understand best is:
The pillar I find hardest is:
One control I will suggest at home: