← All 186 courses
SEC-101 Security

Security Foundations & Threat Landscape

The ground truth every security role builds on: the CIA triad made practical, attacker motivations and kill-chain thinking, common attack classes, defense-in-depth, and security's place in the SDLC — taught through walkthroughs of real (public) incidents so concepts attach to consequences.

B1Aware
5modules
34skill atoms
9role journeys
Curriculum

What this course covers.

5 modules, 34 named skill atoms. Expand any module to see them.

1Security Mental Models6 skill atoms
CIA triadtrust boundariesattack surfacethreat vs vulnerability vs riskasset & crown-jewel identificationpreventive/detective/corrective control types
2Adversary Thinking7 skill atoms
threat actorskill chainMITRE ATT&CK orientationactor motivation & capability tierstactics vs techniques vs proceduresinitial access vs lateral movementdwell-time awareness
3Common Attack Classes7 skill atoms
phishingcredential abusemisconfiguration realityransomware lifecycle awarenesssocial-engineering pretextssupply-chain compromise basicsinsider-risk indicators
4Defense in Depth7 skill atoms
layered controlsdetection vs prevention economicssingle points of trustsegmentation intuitionleast privilege as a defaultbackups as a security controlresidual risk awareness
5Incident Anatomy7 skill atoms
public case walkthroughslessons-to-controls mappingroot cause vs contributing factorstimeline readingblast-radius estimationbreach disclosure basicsblameless post-incident review
Where it fits

SEC-101 in the role journeys.

This course appears in 9 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

AI Security Engineer

Foundation stage
AI-107SEC-101SEC-501

Security Engineer

Foundation stage
starts hereSEC-101SEC-102

DevSecOps Engineer

Foundation stage
CL-312SEC-101SEC-301

SOC Analyst

Foundation stage
starts hereSEC-101SEC-102

AppSec Engineer

Foundation stage
starts hereSEC-101SEC-303

IAM Engineer

Foundation stage
SEC-201SEC-101SEC-104

GRC / Compliance Analyst

Foundation stage
starts hereSEC-101SEC-102

Cryptography / PQC Engineer

Foundation stage
starts hereSEC-101SEC-103

OT / ICS Security Engineer

Foundation stage
starts hereSEC-101SEC-105

Roles this course serves

The capability ladder

This course is authored to band B1.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-101 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free