Running track · free to participants

Cybersecurity fundamentals

Learn to spot, investigate and contain security problems, using the logs and monitoring that watch CCA’s own systems.

What this track covers

Much of security work is careful reading: learning what normal looks like on a system, then noticing when something does not fit. This track teaches that on data from systems that are actually in use.

Threat modeling
Working out what could go wrong with a system, who might cause it, and what most needs protecting.
Log analysis
Reading the records that systems leave behind to work out what happened, in what order and why.
Security monitoring
How a security information and event management (SIEM) platform gathers logs, raises alerts and helps analysts work through them.
Incident handling
What to do, and in what order, when something has gone wrong, from containing the problem to writing it up afterward.
Security hygiene
Keeping accounts, devices and software in a state that does not invite trouble.

The data you work with

The logs in this track come from CCA’s production systems, so the patterns in them are real.

CCA runs its own security monitoring platform, with views covering:

  • security incidents and the alerts that raised them
  • the security state of laptops, servers and cloud services
  • system logs from servers and workstations
  • logs from routers, switches and firewalls
  • web sessions
  • physical security events

Alongside it is the audit trail from CCA’s own platform, which records sign-ins and failed sign-ins, permission denials, views of personal information and data exports. Records like these are what security analysts spend their days reading.

Working with real data

Production logs can include information about real people. Participants in this track get access that matches their role, every view of personal information is logged, and every participant signs our acceptable use and security policies at enrollment.

Where it leads

The track prepares participants for security analyst and security operations center roles, and for recognized security certifications. Analysts in those roles watch for alerts, investigate what caused them and decide what needs to happen next.

When you are ready to sit a security certification exam, CCA can pay the fee. Staff run interview practice with you, and look over any job offer with you before you accept it.

See the support every participant gets

What donors fund in this track

Hardware and training resources, including vouchers for certification exams.

$500

Pays for one certification exam attempt

$1,500

Replaces one enterprise device in the lending library

$5,000

Sponsors one participant for a full year, covering equipment, access, mentorship and certifications

To restrict a gift to this track, say so when you give. We will confirm it in writing and tell you what the gift paid for.

Questions about this track

Do I need security experience to start?

No. You can enroll without any security background. You will need a sponsor or board approval, and a computer with an internet connection.

Will I be working with real people’s data?

The logs come from systems people really use, so they can include personal information. Access is limited by role, every view of personal information is logged, and you agree to our acceptable use and security policies when you enroll.

Is this a hacking course?

No. The track is about defense: monitoring systems, investigating alerts and responding to incidents.

Pay for a participant’s certification exam

Many security job listings ask for a recognized certification. A gift of $500 pays for one exam attempt.