MÓDULO 3 - Video 1: Fundamentos y principios de ciberseguridad
Welcome to this video
about cybersecurity fundamentals and principles
.
Throughout this session you will learn
basic concepts related to
information protection, the
main digital threats and some
essential measures that every user should
know in today's digital environment.
Before we begin, I invite you to consider
a situation that will help us understand
why this topic is more relevant than it
seems. Remember to take notes and
pause the video when you need to.
A medical practice has digitized
medical records, appointments,
patient data, and billing.
One morning, the system begins to
display strange messages, [music]
raising concerns about
information security. What went
wrong and how could it have been prevented?
Throughout this video we will find
the answers. In our daily lives
we use social networks,
emails, mobile applications and
online services to communicate,
work and share
personal and professional information [music]. All
this digital interconnection exposes us to
cybercriminals who seek to steal our
information, passwords, money
[music] and identity. This
hyperconnectivity has transformed the
world, offering unprecedented conveniences
. [music]
However, it has also opened an
invisible and constant door to new
risks, for example, data theft,
fraud and unauthorized access. The
safest method [music] to protect
our systems and data is
prevention.
Cybersecurity is the set of
technologies, processes, and practices
designed to protect systems, networks,
and data against damage, theft, or
unauthorized access. Its goal is not to
generate fear of technology, but to
give us the knowledge necessary to
use it safely. Now,
let's take the first step by exploring the
basic theory. But what do we mean by
cybersecurity? Cybersecurity is the
practice of protecting systems, networks,
devices, and data against
digital attacks, unauthorized access, and
damage. It goes beyond simply
installing
security software. It is a comprehensive approach that
combines technology, processes, and people.
One way to protect data is
through passwords, which are
access keys used to log in to
applications and websites. Its security
depends on the variety of characters
we use. Permissions are
authorizations that an app requests to
access device functions,
such as the camera or [music] location.
The current digital landscape shows us
that we are all susceptible to
information theft,
identity theft, and damage to our
systems. That's why acquiring
knowledge to prevent these
cyberattacks is more
important than ever. A clear example
of this risk is
social engineering, a set of
manipulation techniques used by
cybercriminals to deceive
users in order to obtain
personal data, passwords, or
bank access.
Faced with this challenging reality,
cybersecurity does not act blindly. It is
based on three
fundamental principles specifically designed
to protect our information.
Next, we will review what they are.
All computer security boils down
to three essential concepts.
Let's explore the pillars that shape
the cybersecurity triad.
Observe each one of them on the screen.
Confidentiality ensures that
information is only accessible to
authorized individuals, protecting it
against unauthorized disclosure
through encryption and access controls.
Integrity ensures that data
remains complete, accurate, and free from
unauthorized alteration during
storage and transmission.
Availability ensures that
systems and data are accessible when
authorized users need them,
preventing interruptions. These
principles help us understand what we
need to protect. Now let's see
what we need to protect ourselves against.
Information security
is one of the
fundamental pillars for the operation of
any modern organization.
The increasing dependence on
digital systems, coupled with the
sophistication of malicious actors,
demands a precise understanding of the
threats facing
computer assets and the ways in which they
can materialize. [music]
Understanding this duality, what the
attacker is looking for and how they enter, is the basis
for designing effective preventive,
detective, and corrective controls.
Next, we will describe the
most frequent threats in
everyday life. and the main
attack vectors used to carry them out.
A threat is any event, agent,
or circumstance with the potential to cause
harm to the confidentiality, integrity,
or availability of
information. Among the most common are
malware, which includes viruses,
worms, Trojans, spyware [music] and
ransomware. The latter encrypts
the victim's data to demand a ransom
[music] with impacts ranging from
loss of information to
total operational paralysis. Phishing
and identity theft are
scams designed to trick the
user into revealing credentials or performing
improper actions.
Denial-of-service attacks saturate
network or computing resources to prevent
legitimate access to services,
directly affecting
availability. Internal threats
originating from employees, contractors, or
former employees, whether due to malice,
negligence, or
compromised credentials, are especially
dangerous because they bypass a large part of
the perimeter controls.
Data leakage and exfiltration is the
unauthorized extraction of
sensitive information with regulatory,
economic [music]
and reputational consequences.
An attack vector is the means or
route that an adversary uses to
achieve their objective. The most frequent
are email, the main
entry point for phishing,
malicious attachments, and fraudulent links.
Weak or reused credentials
facilitate brute-force,
dictionary, and credential stuffing attacks
[music] based on
previous leaks.
Outdated software exposes
known and
exploitable vulnerabilities.
Social engineering [music] is the
psychological manipulation of the user by
phone, social networks or
in person to obtain information
or access.
Removable devices and untrusted networks
, such as infected USB drives
and unencrypted public Wi-Fi networks,
enable intrusions and
man-in-the-middle attacks and supply chain compromise
by compromising
legitimate library or update providers
to distribute malicious code on a
large scale.
Knowing the threats is the first step.
The next step is to learn how to
protect ourselves through good practices
and ethical principles. Regulations are
the set of formal provisions,
laws, regulations, technical standards and
internal policies that govern the
exercise of an activity.
Its nature is mandatory and
failure to comply generally entails
legal, administrative
or disciplinary consequences.
Common examples include
labor laws, data protection regulations
, ISO standards, and the
specific provisions of each
professional association.
Good practices are procedures,
methods, or behaviors that, without
necessarily having mandatory force
[music],
have proven to be efficient and safe
in achieving quality results.
Unlike regulations, their
adoption is usually voluntary. Among its
benefits are the reduction of
errors and the optimization of resources.
Adopting good practices [in music]
means going beyond
minimum compliance and orienting work towards
operational excellence.
Professional ethics [in music]
is the set of principles and values
that guide the behavior of the
professional towards his colleagues, his
users, his institution and society.
Unlike regulations, it is not
imposed by the coercive force of
law, but is internalized as
a personal and collective conviction. Its
fundamental principles usually include
honesty,
responsibility, confidentiality,
impartiality, respect for
human dignity, and commitment to the
common good. What relationship and integration
exists between these three elements?
Although each operates on a
different plane, the three elements are
complementary.
The regulations establish the
minimum framework for compliance. Good
practices raise that standard towards
quality and efficiency.
Professional ethics provides the human and
moral sense that legitimizes all
actions.
Let's recall the case of the
doctor's office. [music] Had
these three elements been applied:
security policies, strong passwords,
updated systems and trained personnel, the
incident could have been prevented.
Threats and attack vectors
evolve at the same pace as
technology. Therefore,
information protection should not be understood as
a state, but as a
continuous process.
What happened in the doctor's office
is not an isolated incident or a
minor technological failure. It is a reflection of what
happens when an organization
digitizes all its information without
simultaneously building a
cybersecurity culture to support and
protect it. Within
minutes, some simple, strange messages
on the [music] screen translated into
inaccessible medical records,
missed appointments, stopped billing, and an
inability to provide timely medical care
. Here the
three fundamental pillars of
information security become visible.
Confidentiality [music] is
threatened, integrity is called into question, and
availability [music] is broken
just when it is most needed. Most
incidents do not begin with a
sophisticated attack, but with
everyday carelessness, an email opened without
checking, a weak password
shared among several employees, an
unupdated [music] device, or a
backup that was never made.
Studying the fundamentals of
cybersecurity, its guiding principles,
its most frequent threats, and its
regulatory and ethical frameworks is not simply a
technical option reserved for
specialists. It is a
professional and human responsibility that involves
any person who, in their daily life,
has contact with sensitive information
belonging to other human beings.
We hope [music] that this content has
been useful.
In the following video we will address
infrastructure security,
risk management and
basic practices [music] for detecting and
responding to incidents. See you soon.
More transcripts
Explore other videos transcribed with YouTLDR.

Video Pembelajaran
andy ganing · Indonesian

Kisah Pengantar Tidur | Selimut Wol Penenang Pikiran
Pendongeng Tidur · English

The MOST in-depth Feature comparison: DJI Pocket 4 Pro vs Insta360 Luna Ultra
TechTok · English

EL SUDARIO DE TURÍN 🟤 | El Misterio de la Sábana Santa: ¿hemos desvelado finalmente sus secretos?
Pol Bertran · Spanish

General Listening “A University Degree” - ESL CYBER LISTENING LAB
Only One Coin · English

Penyusunan Proposal dan Laporan Program Pengaabdian Berbasis Kemitraan
LPPM UNISNU JEPARA · English

Mars Gizi Poltekkes Kemenkes Makassar
Jurusan Gizi Poltekkes Makassar · Indonesian

فيلم رعب | الدحيح
New Media Academy Life · English

Barisan dan Deret Aritmatika
Zenius Content · Indonesian

Ele cria seu próprio reino com bruxas - "COMPLETO"
Kazuma Manhwa · Portuguese (Portugal, Brazil)

El Régimen Ecoómico en la Constitución Política del Perú
CERSEU CONTABILIDAD - UNMSM · English

Sesi 1 | Memahami Esai Secara Luas
Rita Primayuni · English
Get the TLDR of any YouTube video
Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.