Derek Allan Boman — Cybersecurity Study Tools and Defensive Security Visuals
Cybersecurity Study Tools is a public learning page by Derek Allan Boman focused on defensive security concepts, study diagrams, technical fundamentals, and controlled lab learning.
This page is not an exploit guide. It is not a penetration-testing playbook. It is not intended to provide operational attack instructions. The purpose is defensive understanding: how systems are organized, how risk is evaluated, how identity and access are controlled, how incidents are handled, and how cybersecurity learners can connect abstract terms to practical diagrams.
Cybersecurity becomes easier to learn when it is visible.
A term like “zero trust” can sound vague until it is shown as an access flow. A term like “incident response” becomes clearer when it is shown as a lifecycle. A term like “risk” becomes more useful when it is connected to assets, threats, vulnerabilities, likelihood, impact, and controls.
This page collects visual study tools for learners working through A+, Network+, Security+, defensive security fundamentals, cloud security, identity, risk, monitoring, and incident response.
NIST describes its Cybersecurity Framework as helping organizations better understand and improve cybersecurity-risk management, and its CSF page includes CSF 2.0 resources, profiles, mappings, and quick-start guides. MITRE ATT&CK organizes adversary behavior around matrices, tactics, techniques, defenses, detections, and related resources. OWASP’s Top Ten is a public application-security awareness resource focused on common web-application security risks.
The best cybersecurity study path is layered.
Start with systems:
hardware, operating systems, storage, user accounts, permissions, updates, backups, and troubleshooting.
Then move to networks:
IP addresses, DNS, DHCP, routing, switching, firewalls, ports, protocols, VPNs, wireless, and segmentation.
Then move to security:
authentication, authorization, least privilege, malware, vulnerabilities, risk, monitoring, encryption, incident response, governance, and recovery.
Then move to frameworks:
NIST CSF, MITRE ATT&CK, the Cyber Kill Chain, the Diamond Model, OWASP, CIS Controls, and Zero Trust.
The diagrams on this page are designed to make that path easier to follow.
Defense in depth means security should not depend on one control. A firewall can fail. A password can be stolen. A system can miss a patch. A user can make a mistake. A cloud setting can be misconfigured.
Layered defense gives the organization more than one chance to prevent, detect, contain, and recover.
The defense-in-depth diagram on this page shows multiple layers: user, firewall, IDS and IPS, web application firewall, endpoint protection, and SIEM. The point is not that every organization uses the same exact stack. The point is that security should be layered.
Zero Trust is easiest to understand as a decision process. A user requests access. The system verifies identity. The device is checked. Policy is applied. Access is allowed, denied, limited, or monitored.
The zero trust diagram on this page shows identity, MFA, device health, policy engine, resource access, and continuous verification.
Identity is one of the most important areas in cybersecurity. Many incidents involve accounts, credentials, excessive permissions, shared accounts, weak authentication, or missing audit logs.
Identity and access management asks basic questions:
Who is the user?
How was identity verified?
What is the user allowed to do?
Is the access still needed?
Is the activity being logged?
What happens when access is abused?
Risk management connects technical security to business impact.
A useful risk model includes:
asset
threat
vulnerability
likelihood
impact
control
residual risk
Risk is not just “bad things might happen.” It is a structured way to decide what matters most, what should be fixed first, and what level of risk remains after controls are applied.
Incident response is the process of handling a cybersecurity event without guessing under pressure.
A practical incident response lifecycle includes:
prepare
detect
analyze
contain
eradicate
recover
lessons learned
The goal is to reduce confusion. Good incident response depends on preparation, communication, evidence handling, containment decisions, recovery planning, and review.
Security monitoring turns system activity into evidence. Logs from endpoints, firewalls, identity systems, servers, applications, and cloud tools are collected and reviewed. Alerts are triaged, investigated, escalated, and closed.
A SOC workflow is not just about tools. It is about the path from signal to action.
The Cyber Kill Chain helps learners understand intrusion stages. MITRE ATT&CK helps learners organize adversary behavior by tactics and techniques.
For defensive study, these models are valuable because they help learners ask better questions:
What is the activity trying to accomplish?
What stage of the process does it belong to?
What evidence would show it?
What control could reduce the risk?
What response would contain it?
Data protection begins by knowing what kind of data exists. Public information, internal information, confidential information, and restricted information should not be handled the same way.
A classification model helps decide who can access data, where it can be stored, how it should be transmitted, whether it should be encrypted, and how it should be monitored.
A cybersecurity lab should be controlled, legal, and educational. Virtual machines allow learners to separate study environments from everyday work systems. Kali Linux can be used as part of a cybersecurity learning environment, but it should be treated responsibly and used only in authorized labs.
The point of a lab is to learn safely.
NIST Cybersecurity Framework
https://www.nist.gov/cyberframework
NIST Computer Security Resource Center
https://csrc.nist.gov/
NIST National Vulnerability Database
https://nvd.nist.gov/
MITRE ATT&CK
https://attack.mitre.org/
MITRE ATT&CK Enterprise Matrix
https://attack.mitre.org/matrices/enterprise/
MITRE ATT&CK Tactics
https://attack.mitre.org/tactics/enterprise/
MITRE ATT&CK Techniques
https://attack.mitre.org/techniques/enterprise/
OWASP Top Ten
https://owasp.org/www-project-top-ten/
OWASP Cheat Sheet Series
https://cheatsheetseries.owasp.org/
OWASP Application Security Verification Standard
https://owasp.org/www-project-application-security-verification-standard/
CISA Cybersecurity Best Practices
https://www.cisa.gov/topics/cybersecurity-best-practices
CISA Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
CISA Secure by Design
https://www.cisa.gov/securebydesign
CIS Controls
https://www.cisecurity.org/controls
CWE Top 25
https://cwe.mitre.org/top25/
CompTIA A+
https://www.comptia.org/certifications/a
CompTIA Network+
https://www.comptia.org/certifications/network
CompTIA Security+
https://www.comptia.org/certifications/security
Kali Linux Documentation
https://www.kali.org/docs/
VirtualBox Documentation
https://www.virtualbox.org/wiki/Documentation
Wireshark Documentation
https://www.wireshark.org/docs/
Microsoft Learn Security
https://learn.microsoft.com/en-us/security/
Google Cloud Security Documentation
https://cloud.google.com/security
AWS Security Documentation
https://docs.aws.amazon.com/security/
Cisco Networking Basics
https://www.netacad.com/