11
Mentorship Monday - Discussions for career and learning!
(infosec.pub)
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Enjoy!
I am not pursuing Cybersecurity but I have a good understanding of Linux, command line, networking etc. I have made IRC bots which got hacked by IRC people and it was fun learning things.
My question is what do we actually do in Cybersecurity? Is it just nmap, Hydra, Kali?
That's a loaded question ๐ . One that can be answered in a few different ways... From a technical perspective, "infosec" is a relatively vast field comprised of a lot of sub-disciplines, so from a tooling and procedural perspective, it varies from job to job. Some would argue a lot of what we do is just theater, and for many orgs and many "pros", this may very well be true. At the root of it all though, you could say our job is to ensure the Confidentiality, Integrity and Availability (classic CIA triad) of data/systems, keeping in mind the balance/tradeoffs between security needs and business requirements. To do so, we employ a variety of tactics, techniques, tools, methodologies, frameworks, etc... Another way to boil down what security folks do is in the lens of "risk". Most business and IT decisions in general come down to risk-based decision making and security is no different. Security teams should understand the risk introduced by the threat landscape coupled with the respective data, attack surface, business assets, etc... to help inform the business how to reduce security risk to acceptable levels.
Hopefully this answer isn't too vague and non-answer-ey!