SISEN Mapping to CyBOK

This page shows how SISEN lecture and practical materials map to CyBOK sections, Knowledge Areas, Topics, and detailed indicative material/subsections.

Lecture Mapping

LectureCyBOK sectionKnowledge AreaCyBOK Topic(s)Mapped subsectionsCoverage
Lecture 1Security and Safety FundamentalsIntroductory ConceptsIntroduction to CyBOK
  • Foundational Concepts
  • Principles
View mapped subsections
  • 1.1 Cyber Security Definition
  • 1.3.1 Means and Objectives of Cyber Security
  • 1.3.2 Failures and Incidents
  • 1.3.3 Risk
  • 1.4.3 Latent Design Conditions
Full
Infrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
View mapped subsections
  • 21.1 Cyber-Physical Systems and Their Security Risks
  • 21.1.1 Characteristics of CPS
  • 21.1.2 Protections Against Natural Events and Accidents
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
Full
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Definitions
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.2 What Is Risk?
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.2 Elements of Risk
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
Partial
Attacks & DefencesAdversarial Behaviours
  • Characterisation of Adversaries
  • Elements of a Malicious Operation
View mapped subsections
  • 7.1 A Characterisation of Adversaries
  • 7.2 The Elements of a Malicious Operation
Partial
Lecture 2Security-Informed SafetyInfrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cross Cutting Security
View mapped subsections
  • 21.1.2 Protections Against Natural Events and Accidents
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
  • 21.1.3.2 High-Profile, Real-World Attacks Against CPSs
  • 21.2 Crosscutting Security
  • 21.2.1 Preventing Attacks
  • 21.2.2 Detecting Attacks
  • 21.2.3 Mitigating Attacks
Full
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.2 Elements of Risk
  • 2.6.3 Risk Assessment and Management Methods
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
Partial
Attacks & DefencesAdversarial Behaviours
  • Characterisation of Adversaries
  • Elements of a Malicious Operation
  • Models
View mapped subsections
  • 7.1 A Characterisation of Adversaries
  • 7.2 The Elements of a Malicious Operation
  • 7.3 Models to Understand Malicious Operations
Partial
Lecture 3Hazard Analysis and AssuranceHuman, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Definitions
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.2 What Is Risk?
  • 2.3 Why Is Risk Assessment and Management Important?
  • 2.4 What Is Cyber Risk Assessment and Management?
  • 2.6 Risk Assessment and Management Principles
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.2 Elements of Risk
  • 2.6.3 Risk Assessment and Management Methods
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
  • 2.6.6 Security Metrics
Full
Infrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cross Cutting Security
View mapped subsections
  • 21.1 Cyber-Physical Systems and Their Security Risks
  • 21.1.2 Protections Against Natural Events and Accidents
  • 21.1.3 Security and Privacy Concerns
  • 21.2 Crosscutting Security
Partial
Human, Organisational & Regulatory AspectsHuman Factors
  • Fitting the Task to the Human
  • Human Error
  • Awareness and Education
  • Stakeholder Engagement
View mapped subsections
  • 4.2.1 Fitting the Task to the Human
  • 4.3 Human Error
  • 4.4.2 Mental Models of Cyber Risks and Defences
  • 4.6 Stakeholder Engagement
Partial
Lecture 4IoT, Cyber-Physical Systems and SecurityInfrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cross Cutting Security
  • Cyber-Physical Systems Domains
View mapped subsections
  • 21.1 Cyber-Physical Systems and Their Security Risks
  • 21.1.1 Characteristics of CPS
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
  • 21.2 Crosscutting Security
  • 21.2.1 Preventing Attacks
  • 21.2.2 Detecting Attacks
  • 21.2.3 Mitigating Attacks
  • 21.3.5 Medical Devices
  • 21.3.6 The Internet of Things
Full
Infrastructure SecurityNetwork Security
  • Security Goals and Attacker Models
  • Networking Applications
  • Network Protocols and Their Security
View mapped subsections
  • 19.1.1 Security Goals in Networked Systems
  • 19.1.2 Attacker Models
  • 19.2.4 Wireless Networks
  • 19.3 Network Protocols and Their Security
  • 19.3.3.2 IPv6 Security
  • 19.3.4.5 Network Segmentation
  • 19.3.4.6 Wireless Security
Partial
Systems SecurityAuthentication, Authorisation & Accountability
  • Authorisation
  • Authentication
  • Accountability
View mapped subsections
  • 14.3.1 Access Control
  • 14.3.2 Enforcing Access Control
  • 14.5 Authentication
  • 14.6 Accountability
Partial
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
Partial
Lecture 5Wireless and Short-Range ThreatsInfrastructure SecurityNetwork Security
  • Security Goals and Attacker Models
  • Networking Applications
  • Network Protocols and Their Security
  • Network Security Tools
View mapped subsections
  • 19.1 Security Goals and Attacker Models
  • 19.1.1 Security Goals in Networked Systems
  • 19.1.2 Attacker Models
  • 19.2.4 Wireless Networks
  • 19.3 Network Protocols and Their Security
  • 19.3.4 Security on the Link Layer
  • 19.3.4.1 Port-Based Network Access Control
  • 19.3.4.6 Wireless Security
  • 19.4.3 Network Security Monitoring
  • 19.4.5 Network Access Control
  • 19.4.7 DoS Countermeasures
Full
Infrastructure SecurityPhysical Layer and Telecommunications Security
  • Jamming and Jamming-Resilient Communications
  • Identification
  • Distance Bounding and Secure Positioning
  • Physical Layer Security of Selected Communications Technologies
View mapped subsections
  • 22.2 Jamming and Jamming-Resilient Communication
  • 22.2.1 Coordinated Spread Spectrum Techniques
  • 22.2.2 Uncoordinated Spread Spectrum Techniques
  • 22.2.3 Signal Annihilation and Overshadowing
  • 22.3 Physical-Layer Identification
  • 22.4 Distance Bounding and Secure Positioning
  • 22.4.1 Distance Bounding Protocols
  • 22.4.3 Physical-Layer Attacks on Secure Distance Measurement
  • 22.6.1 Near-Field Communication
Full
Infrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cyber-Physical Systems Domains
View mapped subsections
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
  • 21.3.5 Medical Devices
  • 21.3.6 The Internet of Things
Partial
Systems SecurityAuthentication, Authorisation & Accountability
  • Authorisation
  • Authentication
View mapped subsections
  • 14.3.1 Access Control
  • 14.5 Authentication
  • 14.5.4 Facets of Authentication
Partial
Infrastructure SecurityApplied Cryptography
  • Algorithms, Schemes and Protocols
  • Key Management
  • Applied Cryptography in Action
View mapped subsections
  • 18.1.5 Message Authentication Code Schemes
  • 18.1.6 Authenticated Encryption Schemes
  • 18.1.8 Diffie-Hellman Key Exchange
  • 18.3 Key Management
  • 18.5.1 Transport Layer Security
Partial
Lecture 6IoT in Safety-Critical ContextsInfrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cross Cutting Security
  • Cyber-Physical Systems Domains
View mapped subsections
  • 21.1 Cyber-Physical Systems and Their Security Risks
  • 21.1.1 Characteristics of CPS
  • 21.1.2 Protections Against Natural Events and Accidents
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
  • 21.1.3.2 High-Profile, Real-World Attacks Against CPSs
  • 21.2 Crosscutting Security
  • 21.3 CPS Domains
  • 21.3.1 Industrial Control Systems
  • 21.3.2 Electric Power Grids
  • 21.3.3 Transportation Systems and Autonomous Vehicles
  • 21.3.4 Robotics and Advanced Manufacturing
  • 21.3.5 Medical Devices
  • 21.3.6 The Internet of Things
Full
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.2 Elements of Risk
  • 2.6.3 Risk Assessment and Management Methods
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
Full
Infrastructure SecurityNetwork Security
  • Security Goals and Attacker Models
  • Networking Applications
  • Network Protocols and Their Security
  • Network Security Tools
View mapped subsections
  • 19.1.1 Security Goals in Networked Systems
  • 19.1.2 Attacker Models
  • 19.2.4 Wireless Networks
  • 19.3.3.2 IPv6 Security
  • 19.3.4.5 Network Segmentation
  • 19.3.4.6 Wireless Security
  • 19.4.3 Network Security Monitoring
  • 19.4.7 DoS Countermeasures
Partial
Infrastructure SecurityPhysical Layer and Telecommunications Security
  • Jamming and Jamming-Resilient Communications
  • Distance Bounding and Secure Positioning
  • Compromising Emanations and Sensor Spoofing
  • Physical Layer Security of Selected Communications Technologies
View mapped subsections
  • 22.2 Jamming and Jamming-Resilient Communication
  • 22.4 Distance Bounding and Secure Positioning
  • 22.5 Compromising Emanations and Sensor Spoofing
  • 22.5.2 Sensor Compromise
  • 22.6 Physical Layer Security of Selected Communication Technologies
Partial
Lecture 7Resilience and MitigationInfrastructure SecurityCyber-Physical Systems Security
  • Cross Cutting Security
View mapped subsections
  • 21.2 Crosscutting Security
  • 21.2.1 Preventing Attacks
  • 21.2.2 Detecting Attacks
  • 21.2.3 Mitigating Attacks
Full
Attacks & DefencesSecurity Operations & Incident Management
  • Fundamental Concepts
  • Monitor: Data Sources
  • Analyse: Analysis Methods
  • Plan: Security Information and Event Management
  • Execute: Mitigation and Countermeasures
  • Knowledge: Intelligence and Analysis
  • Human Factors: Incident Management
View mapped subsections
  • 8.1 Fundamental Concepts
  • 8.2 Monitor: Data Sources
  • 8.2.1 Network Traffic
  • 8.3 Analyse: Analysis Methods
  • 8.3.1 Misuse Detection
  • 8.3.2 Anomaly Detection
  • 8.4 Plan: Security Information and Event Management
  • 8.5 Execute: Mitigation and Countermeasures
  • 8.5.2 Denial-of-Service
  • 8.6.4 Situational Awareness
  • 8.7 Human Factors: Incident Management
  • 8.7.1 Prepare: Incident Management Planning
  • 8.7.2 Handle: Actual Incident Response
  • 8.7.3 Follow-Up: Post-Incident Activities
Full
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Assessment and Management Principles
  • Business Continuity: Incident Response and Recovery Planning
View mapped subsections
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.3 Risk Assessment and Management Methods
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
  • 2.6.6 Security Metrics
  • 2.7 Business Continuity: Incident Response and Recovery Planning
Full
Infrastructure SecurityNetwork Security
  • Network Protocols and Their Security
  • Network Security Tools
View mapped subsections
  • 19.3.4.5 Network Segmentation
  • 19.3.4.6 Wireless Security
  • 19.4.1 Firewalling
  • 19.4.2 Intrusion Detection and Prevention Systems
  • 19.4.3 Network Security Monitoring
  • 19.4.5 Network Access Control
  • 19.4.6 Zero Trust Networking
  • 19.4.7 DoS Countermeasures
Partial
Infrastructure SecurityPhysical Layer and Telecommunications Security
  • Jamming and Jamming-Resilient Communications
View mapped subsections
  • 22.2 Jamming and Jamming-Resilient Communication
Partial
Systems SecurityAuthentication, Authorisation & Accountability
  • Authorisation
  • Authentication
  • Accountability
View mapped subsections
  • 14.3 Authorisation
  • 14.3.1 Access Control
  • 14.3.2 Enforcing Access Control
  • 14.5 Authentication
  • 14.6 Accountability
  • 14.6.1.1 Audit Policies
  • 14.6.1.2 Preserving the Evidence
Partial
Lecture 8Applied Case StudiesInfrastructure SecurityCyber-Physical Systems Security
  • Cyber-Physical Systems
  • Cross Cutting Security
  • Cyber-Physical Systems Domains
View mapped subsections
  • 21.1 Cyber-Physical Systems and Their Security Risks
  • 21.1.2 Protections Against Natural Events and Accidents
  • 21.1.3 Security and Privacy Concerns
  • 21.1.3.1 Attacks Against CPSs
  • 21.2 Crosscutting Security
  • 21.2.1 Preventing Attacks
  • 21.2.2 Detecting Attacks
  • 21.2.3 Mitigating Attacks
  • 21.3.5 Medical Devices
  • 21.3.6 The Internet of Things
Full
Human, Organisational & Regulatory AspectsRisk Management & Governance
  • Risk Assessment and Management Principles
View mapped subsections
  • 2.6.1 Component vs. Systems Perspectives
  • 2.6.2 Elements of Risk
  • 2.6.3 Risk Assessment and Management Methods
  • 2.6.5 Risk Assessment and Management in Cyber-Physical Systems and Operational Technology
Full
Infrastructure SecurityNetwork Security
  • Security Goals and Attacker Models
  • Networking Applications
  • Network Protocols and Their Security
  • Network Security Tools
View mapped subsections
  • 19.1.1 Security Goals in Networked Systems
  • 19.1.2 Attacker Models
  • 19.2.4 Wireless Networks
  • 19.3 Network Protocols and Their Security
  • 19.3.3.2 IPv6 Security
  • 19.3.4.6 Wireless Security
  • 19.4.3 Network Security Monitoring
  • 19.4.7 DoS Countermeasures
Partial
Attacks & DefencesSecurity Operations & Incident Management
  • Fundamental Concepts
  • Monitor: Data Sources
  • Analyse: Analysis Methods
  • Execute: Mitigation and Countermeasures
  • Knowledge: Intelligence and Analysis
  • Human Factors: Incident Management
View mapped subsections
  • 8.1 Fundamental Concepts
  • 8.2 Monitor: Data Sources
  • 8.2.1 Network Traffic
  • 8.3 Analyse: Analysis Methods
  • 8.5 Execute: Mitigation and Countermeasures
  • 8.6.4 Situational Awareness
  • 8.7.2 Handle: Actual Incident Response
  • 8.7.3 Follow-Up: Post-Incident Activities
Partial
Human, Organisational & Regulatory AspectsHuman Factors
  • Fitting the Task to the Human
  • Human Error
  • Awareness and Education
  • Stakeholder Engagement
View mapped subsections
  • 4.2.1 Fitting the Task to the Human
  • 4.3 Human Error
  • 4.4.2 Mental Models of Cyber Risks and Defences
  • 4.6 Stakeholder Engagement
Partial

SISEN Practical Activities Mapping to CyBOK

The practical activities extend the lecture mapping through traffic observation, controlled attack and disruption exercises, evidence analysis, recovery, and security-to-safety hazard reasoning.

Practical activityKnowledge AreaCyBOK Topic(s)SISEN evidence / activity
MQTT topic observation and packet captureSecurity Operations & Incident Management
  • Monitor: Data Sources
  • Analyse: Analysis Methods
Observe MQTT topics, payloads and reporting patterns; capture traffic and inspect normal and affected communication in Wireshark.
Telemetry spoofing and false-data injectionNetwork Security; Cyber-Physical Systems Security
  • Network Protocols and Their Security
  • Cross Cutting Security
Publish correctly formatted but false telemetry and trace the effect on gateways, dashboards and safety-relevant system state.
Extreme and malformed telemetryCyber-Physical Systems Security
  • Cross Cutting Security
Test whether implausible, incomplete or invalid telemetry is accepted, rejected or propagated through the monitoring path.
Replay and stale telemetryNetwork Security; Cyber-Physical Systems Security
  • Network Protocols and Their Security
  • Cross Cutting Security
Replay previously valid messages and assess whether old information can be presented as current or trustworthy.
Availability disruption, single-client disconnection and sensor blackoutNetwork Security; Cyber-Physical Systems Security
  • Network Security Tools
  • Cross Cutting Security
Interrupt selected communication paths or sensor reporting and observe missing, delayed or frozen telemetry and degraded system behaviour.
Detection, baseline comparison and evidence analysisSecurity Operations & Incident Management
  • Monitor: Data Sources
  • Analyse: Analysis Methods
Compare normal and manipulated behaviour using packet captures, logs and dashboard state to identify evidence of the security event.
Attack termination, recovery and residual-risk assessmentSecurity Operations & Incident Management; Risk Management & Governance
  • Execute: Mitigation and Countermeasures
  • Human Factors: Incident Management
  • Risk Assessment and Management Principles
Stop the bounded activity, restore the scenario, verify recovery and assess remaining operational or safety risk.
Security-to-safety hazard analysisRisk Management & Governance
  • Risk Assessment and Management Principles
Connect the technical security event to operational effects, unsafe conditions, mitigations and residual risk using the SISEN hazard-analysis process.
Medical IoT, Smart Building and 6LoWPAN applied scenariosCyber-Physical Systems Security
  • Cyber-Physical Systems Domains
Apply the same security-informed safety reasoning across healthcare, building automation and constrained wireless/IoT environments.
Hidden SSID observation and MAC spoofingNetwork Security
  • Networking Applications
  • Network Protocols and Their Security
Use the separate access-point activities to examine wireless discovery, device identity and trust at the network/link layer.
WEP IV collection and WPA2/EAPOL handshake captureNetwork Security; Applied Cryptography
  • Network Protocols and Their Security
  • Algorithms, Schemes and Protocols
Capture wireless security exchanges and legacy WEP material to examine how link-layer protection and cryptographic mechanisms appear in practice.
Bounded Wi-Fi deauthenticationNetwork Security
  • Network Protocols and Their Security
Demonstrate disruption through forged management traffic and observe the resulting disconnect/reconnect behaviour.