Zum Inhalt springen

English:Cybersecurity Basics

Aus MOOCsWiki Staging

Cybersecurity Basics



Introduction

Cybersecurity is about protecting devices, accounts, networks, and information from unauthorized access, damage, theft, or disruption. You practice cybersecurity whenever you choose a safer password, check whether a message is genuine, update a device, protect personal information, or tell a trusted adult about something suspicious.

This aiMOOC is designed for Grades 7–8. You do not need advanced computer skills. The goal is to help you notice risks, make safer choices, explain why those choices matter, and respond calmly when something goes wrong.

Datei:Confidentiality Integrity Availability triangle.png


What You Will Learn

By the end of this course, you should be able to explain the basic goals of cybersecurity, recognize common threats such as phishing and malware, create stronger account protection, use multi-factor authentication, judge links and messages more carefully, protect personal information, and describe sensible first steps after a possible security incident.

A useful cybersecurity mindset is: pause, check, protect, and report. You do not have to solve every problem alone. If an account, device, or message seems unsafe, stop interacting with it and ask a trusted adult, teacher, parent, guardian, or school IT contact for help.


Why Cybersecurity Matters

Schoolwork, messages, photos, games, social media, cloud files, and online accounts all depend on digital systems. These systems can be useful and convenient, but they can also be misused. Cybersecurity reduces the chance that someone can steal information, take over an account, damage files, or interrupt access to a service.

Cybersecurity is not only a technical subject. People make many security decisions: whether to trust a message, whether to reuse a password, whether to install an update, or whether to share a photo publicly. That is why digital literacy and good judgment are important parts of staying safer online.


The CIA Triad in Simple Terms

Information security is often explained with three goals called the CIA triad. Here, CIA does not mean an intelligence agency.

  1. Confidentiality: Information should be seen only by people who are allowed to see it.
  2. Integrity: Information should stay correct and should not be changed without permission.
  3. Availability: Information and systems should be usable when authorized people need them.

Imagine your class stores a group project online. Confidentiality means strangers should not read private notes. Integrity means no one should secretly replace correct answers with false ones. Availability means your group can still open the file when it is time to present.


Common Cyber Threats

A cyber threat is something that could cause harm to a device, account, network, or information. You can lower risk by learning how common threats work and by refusing to act quickly just because a message creates pressure.


Phishing and Social Engineering

Phishing is a type of deception in which someone pretends to be trustworthy so that you reveal information, open a harmful attachment, send money, or click a dangerous link. Phishing can arrive through email, text messages, social media, games, or other messaging systems.

Common warning signs include unexpected urgency, threats, prizes that seem too good to be true, requests for passwords or verification codes, strange sender addresses, and links that do not match the organization named in the message. One warning sign alone does not prove that a message is fake, so use several clues and verify important requests through a separate trusted channel.

Social engineering is the wider idea of manipulating people instead of directly attacking technology. An attacker might pretend to be a friend, teacher, support worker, game moderator, delivery service, or company. The safest response is to avoid sharing secrets and to verify identity before taking an important action.


Malware

Malware means malicious software. It includes programs designed to spy, steal, damage, disrupt, or give an attacker unwanted control. Malware can spread through harmful downloads, fake apps, infected attachments, compromised websites, or unpatched software.

Datei:Viruswarning.png

Do not install software just because a pop-up tells you to. Use trusted app stores or approved school sources, keep security tools and software updated, and ask an adult or teacher if you are unsure. If a device begins behaving strangely after a download, stop using the suspicious file and report the problem.


Scams and Account Takeover

Online scams try to persuade you to give away money, information, access, or valuable digital items. In an account takeover, someone gains control of another person's account. Password reuse makes this risk worse because a password stolen from one service may be tried on other services.

Never share a password or one-time login code with someone who asks for it in a message. A real friend whose account has been stolen can also send suspicious messages, so verify unusual requests in another way.


Protecting Your Accounts

Your account security is stronger when several protections work together. A strong password helps, but it should not be your only defense.


Passwords and Passphrases

Use a long, unique password or passphrase for each important account. A passphrase can be made from several unrelated words that are easier for you to remember but difficult for someone else to guess. Avoid personal details such as your name, birthday, pet name, school name, or favorite team if other people could discover them.

Password reuse is risky. If one website is breached, attackers may try the same username and password on other websites. A reputable password manager can create and store different passwords for different accounts when your family or school allows its use.


Multi-Factor Authentication

Multi-factor authentication, often called MFA, asks for more than one form of proof before allowing access. For example, an account might require a password and a code from an authenticator app, or a password and a security key.

Datei:CryptoCard two factor.jpg

MFA helps because a stolen password alone may not be enough to enter the account. Some forms of MFA are stronger than others, but using MFA is usually much safer than relying on only a password.

Never approve an unexpected login request. If you receive repeated MFA prompts that you did not start, deny them and report the situation.


Protecting Devices and Files

A secure account can still be put at risk by an unsafe device. Good device habits reduce the number of weaknesses that attackers can use.


Software Updates

Software can contain security flaws. Developers release updates that can fix known problems. Install updates promptly and turn on automatic updates when appropriate and permitted.

Updates are especially important for operating systems, web browsers, apps, and security tools. Restart a device when required so an update can finish installing.


Downloads and App Permissions

Before downloading an app or file, check the source. Avoid cracked software, unknown download sites, and attachments you were not expecting. Apps should receive only the permissions they reasonably need. A calculator app, for example, usually should not need access to your contacts, microphone, and exact location.

If an app asks for a surprising permission, do not automatically accept it. Read the request, consider why the app needs that access, and ask a trusted adult if you are uncertain.


Backups

A backup is an extra copy of important data stored separately from the main copy. Backups can help after accidental deletion, device failure, loss, theft, or some types of malware.

For schoolwork, use the backup method approved by your school. For personal files, families may use cloud backup, an external drive, or both. A backup is useful only if it is recent and can actually be restored.


Safer Web Browsing

You do not need to understand every technical detail of the web to browse more safely. You do need to slow down and check where a link is taking you.


URLs and HTTPS

A URL is the address of a web resource. Attackers sometimes create addresses that look similar to trusted websites by adding extra words, changing letters, or using misleading subdomains. Before entering a password, check the important part of the domain name carefully.

HTTPS encrypts the connection between your browser and the website. A padlock or HTTPS indicator can show that the connection is encrypted, but it does not prove that the website itself is honest. A phishing site can also use HTTPS. You still need to check the domain and the purpose of the site.


Public Wi-Fi

Public Wi-Fi can be convenient, but a network name can be copied or faked. Do not assume a network is official just because its name looks familiar. Ask staff for the correct network name when possible, avoid sending highly sensitive information on networks you do not trust, and keep your device's sharing settings restricted.


Personal Information and Social Media

Personal information can include your full name, location, school, schedule, phone number, email address, photos, account names, and details that help identify you. Some information is harmless in one context but risky when combined with other details.

Datei:Safety, security key to social media use (4999991).jpg

Before posting, think about who can see the content now and who might see it later. Check privacy settings, avoid posting live location when it is unnecessary, and be careful with images that reveal addresses, school badges, travel plans, tickets, or private documents.

Cybersecurity also includes protecting other people. Do not log into someone else's account, share another person's private information, or try to bypass school security controls. Ask permission before testing any system, even if your goal is to learn.


What to Do When Something Goes Wrong

Good cybersecurity includes knowing how to respond. If you click a suspicious link, lose a device, notice an unfamiliar login, or think an account has been stolen, acting quickly can reduce harm.

  1. Incident response: Stop interacting with the suspicious message, page, file, or app.
  2. Reporting: Tell a trusted adult, teacher, parent, guardian, or school IT contact what happened.
  3. Account security: From a trusted device, change a compromised password and protect other accounts that reused it.
  4. Multi-factor authentication: Review MFA settings and remove unfamiliar devices or sessions if the service allows it.
  5. Malware: Do not keep opening suspicious files; follow the school's or family's device-support process.
  6. Evidence: Keep useful information such as the sender name, time, and screenshot if it is safe to do so and an adult asks you to preserve it.

Do not feel pressured to investigate an attacker yourself. Your job is to protect yourself and report the problem to someone who can help.


Mini Scenario Lab

Imagine you receive a message that says: "Your school account will be deleted in ten minutes. Sign in now using this link." The message uses the school logo, but the sender address is unfamiliar and the link points to a strange domain.

A safer response is to avoid the link, open the school's official website or app separately, check for a real notice, and tell a teacher or school IT contact. The key skill is not memorizing one clue. It is combining clues, refusing pressure, and verifying through a trusted path.

Now imagine that a friend sends you a message asking for a login code because they are "locked out." Even if the message comes from a familiar account, do not send the code. Contact your friend another way. Their account may have been taken over.


Interactive Tasks


Quiz: Test Your Knowledge

What is a main goal of cybersecurity? (Protecting devices accounts networks and data) (!Making every website completely anonymous) (!Preventing people from using the internet) (!Sharing passwords only with close friends)




Which action is safest when an unexpected message asks you to sign in immediately? (Open the official service separately and verify the request) (!Click the message link before time runs out) (!Reply with your password to prove your identity) (!Forward the message to many classmates)




Why is using a unique password for each account helpful? (A stolen password from one service is less useful elsewhere) (!It makes software updates unnecessary) (!It guarantees that phishing cannot happen) (!It lets you safely share passwords with friends)




What does multi-factor authentication add to account security? (More than one form of proof for login) (!A public copy of your password) (!A faster way to skip identity checks) (!A rule that every account must use the same password)




Why should software updates be installed promptly? (They can fix known security flaws) (!They remove the need for backups) (!They make every download safe) (!They stop all online scams)




What is malware? (Software designed to cause harm or unwanted access) (!A secure method for storing passwords) (!A type of trusted school network) (!A harmless browser bookmark)




What does HTTPS mainly tell you? (The connection to the website is encrypted) (!The website owner is always honest) (!The website can never contain malware) (!The domain name cannot be misleading)




Which information should you be especially careful about sharing publicly? (Your live location and private contact details) (!The title of a public library book) (!A general fact about a school subject) (!The name of a widely known planet)




What is a sensible first step after noticing an unfamiliar login to your account? (Tell a trusted adult and secure the account) (!Ignore it because alerts are never important) (!Send your password to the person who logged in) (!Delete all of your schoolwork immediately)




Which action shows ethical cybersecurity behavior? (Test systems only when you have permission) (!Guess a classmate's password for practice) (!Bypass school filters to prove a weakness) (!Share private screenshots without consent)





Memory Game

Phishing A deceptive message or site that tries to steal information or trigger unsafe actions
Malware Harmful software designed to damage spy disrupt or gain unwanted access
Passphrase A long memorable secret often built from several words
MFA Login protection that requires more than one form of proof
Backup A separate copy of data that can help restore lost files
Encryption A method that transforms information so unauthorized readers cannot easily understand it





Drag and Drop

Match the correct terms. Topic
Verify through another channel Suspicious message from a known contact
Use a unique passphrase Account password protection
Install trusted updates Fixing known software weaknesses
Turn on MFA Adding another login barrier
Keep a separate backup Preparing for lost or damaged files




...


Crossword Puzzle

Phishing What deception method often uses fake messages to steal information?
Malware What is the general word for harmful software?
Passphrase What long memorable secret can be made from several words?
Encryption What process makes data unreadable without the proper key?
Firewall What security tool filters network traffic using rules?
Backup What extra copy can help restore lost data?





LearningApps


Cloze Text

Complete the text.

Cybersecurity helps protect devices, accounts, networks, and

from harm or unauthorized access. A deceptive message that tries to steal information is called

. Harmful software is known as

. A long memorable login secret can be a

. Adding another form of login proof is called

. Installing software updates can fix known security

. A separate copy of important files is a

. HTTPS mainly protects the connection through

. If something suspicious happens, you should stop, verify, and

it to a trusted adult or responsible support person.




Open-Ended Tasks


Easy

  1. Cyber Safety Checklist: Create a one-page checklist with eight safe habits you can use for school and personal accounts.
  2. Phishing Poster: Design a poster that shows at least five clues that can make a message suspicious and one safe way to verify it.
  3. Passphrase Practice: Invent three fictional passphrases using unrelated words, explain why length and uniqueness matter, and do not use any real password.
  4. Cybersecurity Comic: Draw a short comic in which a student receives a suspicious message, pauses, checks the request, and reports it safely.


Standard

  1. Device Update Audit: With permission, check one personal or school device for pending updates and write a short explanation of why updates matter without recording private device information.
  2. Backup Experiment: Create a harmless sample file, make a backup using an approved method, delete the working copy, restore it, and document what you learned.
  3. School IT Interview: Interview a teacher or school IT staff member about safe reporting procedures and common student mistakes without asking for passwords, security secrets, or confidential system details.
  4. Cyber Safety Video: Produce a sixty to ninety second video that teaches classmates how to respond to a suspicious login message.


Advanced

  1. Threat Model: Choose a fictional student account and map its valuable information, possible threats, likely weaknesses, and realistic defenses.
  2. URL Detective: Build a set of six fictional web addresses, explain which details could mislead a user, and write a safe verification method for each example.
  3. Incident Response Plan: Create a step-by-step response plan for a lost school device or stolen account, including reporting, account protection, and evidence preservation.
  4. Cyber Ethics Debate: Prepare and lead a class discussion about why permission matters in cybersecurity testing, using examples that distinguish responsible research from unauthorized access.



Learning Assessment

  1. Phishing Analysis: Compare two fictional messages, identify the strongest evidence of risk in each one, and justify the safest response rather than relying on a single warning sign.
  2. Account Defense Design: Design a protection plan for a student's email account using a unique passphrase, MFA, recovery options, and safe reporting, then explain how the layers work together.
  3. CIA Triad Application: Apply confidentiality, integrity, and availability to a shared class document and explain one realistic failure and one protection for each goal.
  4. Update Decision: Explain what you would do if an important update appears just before a class presentation and justify how you would balance security, timing, and data protection.
  5. Incident Transfer Task: Given a scenario in which a gaming account is taken over, explain which lessons from school account security also apply and which details might differ.
  6. Ethical Cybersecurity Reasoning: Judge a scenario in which a student wants to test a school website without permission and propose a safe, legal, and educational alternative.




Evidence of Learning

  1. Cybersecurity Knowledge: You can explain core ideas including phishing, malware, passphrases, MFA, updates, backups, HTTPS, personal information, and the CIA triad.
  2. Cybersecurity Skills: You can inspect suspicious messages, verify requests through trusted channels, choose safer account protections, and describe a sensible incident response.
  3. Cybersecurity Products: You can produce useful artifacts such as a checklist, poster, video, threat model, backup record, or incident response plan.
  4. Cybersecurity Transfer: You can apply the same safety principles to new apps, school systems, games, social media, shared documents, and unfamiliar digital situations.




OERs on the Topic

The English Wikipedia article on Computer security provides background information and links to related security concepts.

For further study, you can also use CISA Secure Our World for practical online-safety guidance and NIST guidance on passwords and account protection.



Linked Learning Areas

Cybersecurity connects technical knowledge with communication, ethics, problem-solving, and responsible digital citizenship. The most important idea is not to memorize every possible attack. Instead, learn patterns that help you pause, verify, protect information, use layered defenses, keep systems updated, and report problems to the right people.


aiMOOC Projects