InfoSec
- Network Security
- Application Security
- Operational Security
- Disaster Recovery and Business Continuity
- Cloud Security
- Physical Security
- Mobile Security
- Internet of Things (IoT) Security
Roles in Information Security
Network Security
Application Security
- Threat modeling: Like imagining all the ways someone might break into your house, threat modeling helps developers figure out potential risks to the app early on.
- Secure code reviews: After writing the code, developers carefully check it to make sure there are no weak spots, similar to inspecting the house’s foundation for cracks before finishing construction.
- Servers and databases: These are like the land your house sits on and the water supply it uses. If they aren’t secure, the whole system is at risk.
- Authentication and authorization: Think of these as high-quality locks on your doors. Authentication ensures only the right people can get in, while authorization makes sure they can only access the rooms (data) they’re allowed to.
Disaster Recovery & Business Continuity
Cloud Security
DDoS attacks
Ransomware
Social Engineering
- Phishing
- Pretexting
- Baiting
- Tailgating
- Quid Pro Quo
Advanced Persistent Threats
Cybersecurity Teams
- Threat Actors: Black hat hackers that do the exploitation part for extorsion and blackmail or even espionage, basically outlaws.
- Red Team: They simulate real-world attack scenarios under the approval of the enterprise, the whole point is to enhance the corporate security not exploit it.
- Blue Team: Blue team serves as the frontline defense in cybersecurity, collaborating on keeping an organization’s digital infrastructure safe and sound.
- Purple Team: Basically both red and blue teams working together simulating real world attacks and the whole point behind this team, is to improve security defenses and enhance detection and response.


