Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cybersecurity Notes

Personal study notes compiled while preparing for and completing four certifications in 2023: CISA, CISM, CRISC, and GCSA. This also contains some content from the Cyber Security Masters I completed in 2019.

The content goes beyond exam prep. Curiosity led to exploring adjacent topics that weren't strictly on the syllabus but felt worth understanding properly. The notes sat in an Obsidian folder for a while before being restructured using an LLM to make them more readable and consistent. They're shared here in case they're useful to others.

These are still actively maintained. Topics get updated when something is forgotten and re-learned, and new areas get added over time. LLMs make it easy to explore and structure new topics, so the scope will likely keep growing.

Please note that these notes focus primarily on Australian cyber security compliance requirements.


How to Use These Notes

The notes are plain Markdown and render well in VS Code, GitHub, or any Markdown viewer.

There's no strict reading order. Jump to whatever is relevant.

Suggested reading order if you do want one: start with the foundations in sequence — 01 Cyber Governance and Management, 02 Cyber Risk Management, 03 Legal, Regulatory, and Compliance, and 04 Privacy and Data Protection — since the later notes build on the governance, risk, and regulatory context they establish. After that, read the operational domains in any order that suits you, with two pairings worth keeping together: read 13 Incident Management and Business Continuity Planning after 12 Security Operations and Monitoring, and read 16 DevOps and DevSecOps after 15 Software Development Security. Note 00 Current Versions and Facts is a reference to check as you go, not a note to read front to back.


Adding New Topics

New notes follow a consistent template to keep things readable and comparable across topics. Use this with an LLM:

--- START OF THE TEMPLATE
# [Topic Name]


## Overview

What this domain is and where it fits in the broader security landscape.

## Why It Matters

What goes wrong when this is done poorly, with real-world consequences.

## Core Concepts

The foundational ideas explained in plain language. Not definitions — understanding.

## Key Frameworks and Standards

| Framework / Standard | What It Covers | When to Use It |
| -------------------- | -------------- | -------------- |

## How It Works in Practice

What this looks like inside a real organisation — roles, processes, tools, and decisions.

## Common Mistakes and Weaknesses

Where organisations typically fail and why, with practical examples where possible.

## Connections to Other Domains

How this topic feeds into and draws from other areas in the note series. Reference the following 21 topics where relevant:

1. Cyber Governance and Management
2. Cyber Risk Management
3. Legal, Regulatory, and Compliance
4. Privacy and Data Protection
5. Vendor Management
6. Asset and Change Management
7. Network and Communication Security
8. Identity and Access Management
9. Cryptography
10. Cyber Testing
11. Threat Intelligence
12. Security Operations and Monitoring
13. Incident Management and Business Continuity Planning
14. Cloud Management
15. Software Development Security
16. DevOps and DevSecOps
17. Cyber Architecture
18. Cyber Culture and Education
19. LLM Security
20. Physical Security
21. OT

## Further Reading

2-3 authoritative sources for going deeper on this topic. Provide working URLs where possible.

--- END OF THE TEMPLATE

Using the note template above, write a note on [TOPIC]. Focus on practical understanding over definitions. Reference the 21 domain list in the Connections section wherever it is genuinely relevant. Provide real URLs for Further Reading. Make sure to meet the following criteria:

- Markdown format throughout
- All diagrams must be text-based (ASCII or plain text)
- Maximum 3 A4 pages when printed (both sides = 6 sides total)
- Write for a practitioner, not a student
- Research and verify frameworks, standards, and technical claims — do not rely on training data alone for anything that can change over time
- Cite frameworks and standards accurately with version numbers or publication dates where relevant
- Do not pad — if a section is short because the topic does not warrant more, keep it short
- Australian English throughout
- Focus on Australian security compliance requirements, such as Essential 8, PSPF, AESCSF, SOCI Act, and The Privacy Act.
- Do not pin framework versions, requirement numbers, or reporting clocks inside topic notes. Reference note 00 (Current Versions and Facts) instead, and add the standard note-00 pointer near the top of the Overview.
- Never reference "uploaded", "provided", or "project" material. Every note and diagram must stand on its own.

  • Review all LLM-generated content for accuracy and currency. Ensure all important areas are covered.
  • Note 00 (Current Versions and Facts) is the single source of truth for volatile facts. Update it, not the topic notes, when a version, date, or requirement number changes.

Disclaimer

These are personal notes. They are not official study materials and have not been reviewed or endorsed by any certification body or vendor. Content may contain errors or omissions. Always cross-reference with official documentation and current standards before relying on anything here professionally.

Compliance, legal, and regulatory rules change over time. Framework versions, requirement numbers, reporting clocks, penalties, and effective dates are all subject to amendment, and any figure here may be out of date by the time you read it. In a professional context, always verify the true position against the original primary source, the current legislation, regulator guidance, or the framework's official publication, before you act on it.

No certification, exam, tool, or product mentioned in these notes is being sold or marketed. References are purely for context.

About

Old notes refined using an LLM.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Used by

Contributors