Choose your language
Information Security Fundamentals Course
Over 2 million learners across the globe

Information Security Fundamentals Course

Master the core principles, tools, and frameworks that modern organisations rely on to protect their data and systems. This course covers everything from risk management and cryptography to incident response and network security architecture. Whether you're entering the security field or formalising your existing knowledge, you'll finish with the skills employers are actively hiring for.

Dedika for businesses

What you will learn:

You'll build a complete foundation in information security, starting with core concepts like the CIA triad and threat landscape analysis. From there, you'll work through risk assessment methodologies, security governance, and compliance frameworks. You'll gain hands-on understanding of cryptography, identity and access management, and network security architecture. The course also covers application security, security operations, and incident response procedures. Supplementary topics include cloud security, endpoint protection, digital forensics, and emerging threats like AI risks and zero-trust architecture.

How you study practically Information Security Fundamentals Course

How you practise Information Security Fundamentals Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Information Security

  • Lesson 1 • Core Security Concepts and Terminology

    Defines confidentiality, integrity, availability, and key vocabulary. Provides the shared language used throughout the entire course.

  • Lesson 2 • Regulatory and Compliance Foundations

    Covers data protection obligations, privacy principles, and audit requirements. Connects compliance drivers to technical and policy controls.

  • Lesson 3 • Security Principles and Design Goals

    Introduces least privilege, defence in depth, and fail-safe defaults. Links design principles to practical control selection decisions.

  • Lesson 4 • Information Security Roles and Responsibilities

    Maps organisational roles from end users to security officers. Clarifies accountability structures that support a security-aware culture.

  • Lesson 5 • The Threat Landscape Overview

    Surveys categories of adversaries, motives, and attack vectors. Contextualises why organisations face persistent security challenges.

Chapter 2See details

Risk Management and Security Governance

  • Lesson 1 • Security Frameworks and Control Catalogues

    Surveys widely adopted control frameworks and maps controls to risk scenarios. Enables organisations to benchmark and improve their security posture.

  • Lesson 2 • Risk Treatment and Acceptance

    Explains mitigation, transfer, avoidance, and acceptance strategies. Aligns risk decisions with organisational risk appetite and tolerance.

  • Lesson 3 • Security Metrics and Reporting

    Defines KPIs, KRIs, and dashboard design for executive communication. Translates technical findings into business-relevant security insights.

  • Lesson 4 • Risk Assessment Methodologies

    Covers qualitative and quantitative risk analysis, likelihood, and impact scoring. Produces risk registers that guide resource allocation decisions.

  • Lesson 5 • Security Policy and Standards Development

    Guides creation of policies, standards, procedures, and guidelines. Establishes the governance documents that enforce security requirements.

Chapter 3See details

Cryptography Essentials

  • Lesson 1 • Symmetric and Asymmetric Algorithms

    Compares block and stream ciphers with public-key algorithms. Enables informed algorithm selection based on performance and security needs.

  • Lesson 2 • Cryptography Fundamentals

    Explains plaintext, ciphertext, keys, and algorithm types. Grounds later protocol discussions in mathematical and conceptual basics.

  • Lesson 3 • Hashing and Digital Signatures

    Covers integrity verification through hashing and non-repudiation via signatures. Connects these mechanisms to authentication and data integrity goals.

  • Lesson 4 • Cryptographic Protocol Applications

    Applies cryptography to TLS, VPNs, and secure email. Bridges theoretical knowledge to real-world protocol configuration.

  • Lesson 5 • Public Key Infrastructure

    Explains certificate authorities, certificate lifecycle, and trust chains. Prepares students to manage PKI in enterprise environments.

Chapter 4See details

Identity and Access Management

  • Lesson 1 • Identity Lifecycle Management

    Addresses provisioning, modification, and deprovisioning of user accounts. Reduces risk from orphaned accounts and privilege creep.

  • Lesson 2 • Authentication Mechanisms

    Covers passwords, tokens, biometrics, and multi-factor authentication. Establishes how identity verification strength affects overall security posture.

  • Lesson 3 • Authorisation and Access Control Models

    Compares DAC, MAC, RBAC, and ABAC models. Guides selection of the right model for different organisational contexts.

  • Lesson 4 • Privileged Access Management

    Focuses on securing administrative accounts through vaulting and session monitoring. Mitigates the highest-risk access paths in an organisation.

  • Lesson 5 • Federated Identity and Single Sign-On

    Explains federation protocols, SSO architectures, and trust relationships. Enables secure cross-domain authentication in modern environments.

Chapter 5See details

Network Security Architecture

  • Lesson 1 • Network Security Fundamentals

    Reviews TCP/IP, ports, protocols, and traffic flow from a security perspective. Provides the networking baseline required for all subsequent sections.

  • Lesson 2 • Network Segmentation and Microsegmentation

    Explains VLANs, subnetting, and software-defined segmentation. Limits lateral movement by isolating sensitive network zones.

  • Lesson 3 • Secure Remote Access

    Addresses VPN technologies, zero-trust network access, and remote endpoint controls. Secures distributed workforces without sacrificing usability.

  • Lesson 4 • Firewalls and Perimeter Controls

    Covers stateful inspection, next-generation firewalls, and DMZ design. Teaches rule-set construction and perimeter defence strategies.

  • Lesson 5 • Intrusion Detection and Prevention

    Distinguishes IDS from IPS and covers signature vs. anomaly detection. Integrates detection capabilities into a layered defence strategy.

Chapter 6See details

Application Security Fundamentals

  • Lesson 1 • Input Validation and Output Encoding

    Covers allowlist validation, parameterised queries, and context-aware encoding. Prevents the most prevalent injection and XSS vulnerabilities.

  • Lesson 2 • Authentication and Session Management

    Addresses secure session tokens, timeout policies, and credential storage. Protects user sessions from hijacking and replay attacks.

  • Lesson 3 • Secure Software Development Lifecycle

    Integrates security requirements, threat modelling, and code review into SDLC phases. Shifts security left to reduce remediation costs.

  • Lesson 4 • Common Application Vulnerabilities

    Examines injection, broken authentication, and misconfiguration flaws. Grounds remediation decisions in understanding root causes.

  • Lesson 5 • Application Security Testing

    Introduces SAST, DAST, and penetration testing for applications. Validates that implemented controls effectively reduce vulnerability exposure.

Chapter 7See details

Security Operations and Monitoring

  • Lesson 1 • Vulnerability Management Operations

    Covers scanning cadence, CVSS scoring, and remediation prioritisation. Closes the loop between detection and risk reduction in operations.

  • Lesson 2 • Threat Intelligence Integration

    Introduces threat feeds, indicators of compromise, and intelligence-driven detection. Improves detection relevance by incorporating external adversary knowledge.

  • Lesson 3 • Security Event Triage and Escalation

    Defines triage workflows, severity classification, and escalation criteria. Ensures analysts respond to genuine threats without alert fatigue.

  • Lesson 4 • Log Management and Analysis

    Covers log sources, collection pipelines, and retention policies. Provides the data foundation for all detection and investigation activities.

  • Lesson 5 • SIEM Architecture and Use Cases

    Explains SIEM components, correlation rules, and alert prioritisation. Enables analysts to configure detection logic aligned with threat scenarios.

Chapter 8See details

Incident Response and Recovery

  • Lesson 1 • Containment and Eradication

    Addresses short-term and long-term containment strategies and root cause removal. Prevents attacker persistence while minimising operational disruption.

  • Lesson 2 • Post-Incident Review and Lessons Learned

    Structures blameless post-mortems, root cause documentation, and control improvements. Converts incident experience into measurable security programme enhancements.

  • Lesson 3 • Incident Response Planning

    Defines IR plan components, team roles, and communication protocols. Ensures organisations can respond decisively before an incident occurs.

  • Lesson 4 • Detection and Initial Analysis

    Covers alert validation, initial scoping, and incident declaration criteria. Reduces time-to-contain by establishing clear detection-to-response handoffs.

  • Lesson 5 • Recovery and Business Continuity

    Guides system restoration, integrity validation, and return-to-operations decisions. Balances speed of recovery with confidence in system cleanliness.

Certification

Your valid completion certificate

This course is for you:

  • IT support specialist: ready to move into a dedicated security function.

  • Software developer: wants to build security thinking into daily coding work.

  • System administrator: responsible for infrastructure but lacks formal security training.

  • Compliance analyst: needs technical grounding to evaluate security controls effectively.

  • Career changer: transitioning from a non-technical field into cybersecurity roles.

  • Small business owner: managing sensitive data without a dedicated security team.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top training programmes

FAQ

Who is Dedika?

Is the certificate valid in Kenya?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course