computer security
Let an agent explain computer security concepts and practices, help people and organisations protect systems and respond to incidents, explain standards and law, and decline requests to attack or compromise systems without authorisation.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent explain computer security concepts and practices, help people and organisations protect systems and respond to incidents, explain standards and law, and decline requests to attack or compromise systems without authorisation.
The protection of computer systems, networks, software and data from unauthorised access, damage, disruption and theft, through practices such as access control, encryption, patching, monitoring, secure design and user education, and disciplines including hardware security, internet safety and cyber resilience; it is governed by standards and law and practised defensively by organisations and individuals.
What it is for: Protecting systems and data.
It can be explain threats and defences; give practical security guidance; support incident response and reporting; explain standards and legal obligations.
Distinguishing features
Protects confidentiality, integrity and availability
Technical and human measures
Standards-based
Legally regulated
What it looks like
Not physical; practices, controls and policies.
How it is recognised
Defensive measures and controls
Standards and audits
Attacking systems without authorisation is a crime, not security
Related models
is a kind of - category
is a kind of - category
protects - hardware
is related to - systems protected
In practice
Families and kinds
network and internet security
application and software security
hardware security
identity and access management
cyber resilience and incident response
Standards and regulation
ISO/IEC 27001 and NIST Cybersecurity Framework
Data protection and breach notification laws
Computer misuse and cybercrime laws
Failure modes and hazards
Breaches and data loss
Facilitating attacks
Security theatre without real protection
Also called
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Limits Agent conduct.
Defensive only.
Authorisation
Authorised work.
Authorisation
Authorisation.
- Is the request defensive, or does it seek to attack, access or disrupt systems without clear authorisation? boundary
- How should the agent decline unauthorised requests and support lawful security work? action
Incident
Active incidents.
Incident
Incidents.
- Is a breach or attack under way? boundary
- Which immediate containment steps and reporting duties apply? action
Protect Practical security.
Basics first.
Individuals
Personal security.
Individuals
Personal security.
- Which measures protect a person, such as strong authentication, updates and phishing awareness? provenance
- How can accounts be secured after compromise? action
Organisations
Organisational security.
Organisations
Organisational security.
- Which controls and frameworks should an organisation of this size adopt? provenance
- How are risks assessed? action
Threats Understanding threats.
Know the risks.
Types
Threat types.
Types
Threats.
- What are the main threat types, such as malware, phishing and ransomware, and how do defences address them? definition
- Which current advisories are relevant? provenance
Hardware
Hardware and supply chain.
Hardware
Hardware security.
- What is hardware security, and why do supply chains matter? definition
- Which standards apply? provenance
Govern Standards and law.
Compliance.
Standards
Frameworks.
Standards
Frameworks.
- Which security standards and certifications apply, and what do they require? provenance
- How is compliance audited? provenance
Law
Legal duties.
Law
Legal duties.
- Which breach notification, data protection and cybercrime laws apply here? provenance
- Where can incidents be reported? provenance
What the second pass must settle
- Should each subfield be a separate entry?
- How should advisories be linked?
- How should legal obligations be localised?