Group Purchasing
Group Purchasing
AI SKILLS

SEC301: Introduction to Cyber Security

SEC301Cyber Defense, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Rich Greene
Rich Greene
SEC673: Advanced Information Security Automation with Python
Course authored by:
Rich Greene
Rich Greene
  • GIAC Information Security Fundamentals (GISF)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Beginner Level

    Course content applicable to people with limited or no cyber security experience

  • 14 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

SEC301 introduces cybersecurity fundamentals for non-technical professionals, empowering them to understand risks, terminology, and best practices to support security in any role.

Course Overview

This course is designed for cyber-adjacent professionals, managers, HR, legal, auditors, and other non-technical roles who need a strong foundation in cybersecurity fundamentals. Through engaging instruction and relatable examples, this course builds confidence in key areas like threats, risks, defenses, and cyber hygiene. Whether you're supporting a security team, shaping policy, or guiding business decisions, SEC301 helps you understand the language of cybersecurity and your role in protecting the organization. No technical experience required just curiosity and a desire to be cyber smart.

This course also prepares you to earn the GISF certification (GIAC Information Security Fundamentals), a globally respected credential that validates your understanding of essential cybersecurity concepts.

Cyber Starts Here: Building Confidence, Not Confusion

Cybersecurity isn’t just a technical discipline anymore—it’s the language of modern business. Every department, from IT and finance to HR, legal, and operations, depends on secure systems and trustworthy data. Every project carries risk, and every decision, from approving a vendor to opening an email, has security implications. Yet most professionals are never given the chance to learn cybersecurity in a way that feels clear, relevant, and approachable.

SEC301: Introduction to Cybersecurity changes that. It’s designed for anyone who needs to understand cybersecurity fundamentals without drowning in jargon or acronyms. This course provides a common foundation that connects people, process, and technology. You’ll learn how threats exploit vulnerabilities, how human behavior can make or break defenses, and how security controls from encryption to access management create resilience when applied thoughtfully.

Rather than memorizing definitions, you’ll build fluency in the core ideas that drive cybersecurity decisions across every industry: how data moves, where trust begins, and how risk is managed. Whether you’re supporting a security team, auditing compliance, advising leadership, or simply trying to make sense of today’s headlines, SEC301 gives you the context to see the bigger picture and the confidence to contribute meaningfully to it.

Across five focused days, you’ll explore the modern cybersecurity landscape through stories, visuals, and hands-on activities that make abstract ideas tangible:

  • Day 1: Why Cyber Matters — explore how threat, vulnerability, and impact intersect to create risk, and why security failures have real business, legal, and human consequences.
  • Day 2: Building Digital Trust — learn how cryptography, authentication, and modern identity frameworks establish confidentiality and integrity across systems.
  • Day 3: Data in Motion — trace how information moves through networks, understand ports, protocols, and DNS, and discover how Zero Trust principles protect data wherever it flows.
  • Day 4: How Attacks Work — demystify malware, phishing, and adversary tactics using MITRE ATT&CK examples and behavioral clues analysts rely on to detect and disrupt intrusions.
  • Day 5: Defending What Matters — connect the dots across web security, SOC operations, cloud, IoT, and AI, and see how people, tools, and frameworks combine to sustain digital trust.

No technical background is required just curiosity and a willingness to learn. Each topic blends plain-language instruction with realistic scenarios and guided labs that turn theory into experience. You’ll practice analyzing risk, mapping attacks to defenses, and explaining security concepts in terms that business leaders understand.

By the end of the week, you won’t just recognize cybersecurity vocabulary you’ll understand the reasoning behind it. You’ll be able to connect technical controls to organizational outcomes, translate security concepts into decisions, and support a culture of shared responsibility for digital trust.

Because in today’s world, cybersecurity isn’t just an IT issue it’s a leadership skill.

Author Statement

You don’t have to be technical to be part of the solution.

SEC301 was built for the curious, the overwhelmed, and everyone who has ever thought, “I should probably understand this better.” We designed this course to strip away fear and jargon and replace them with insight, clarity, and confidence.

Every concept from hashing to phishing is taught through stories, visuals, and hands-on moments that make sense to real people doing real work. You’ll see how security fits into the systems, policies, and choices that drive every business.

This course isn’t about memorizing acronyms; it’s about learning to think like a defender. You’ll walk away able to explain security risks in plain English, connect controls to business priorities, and contribute meaningfully to every security conversation.

Seeing that lightbulb moment when someone realizes “I actually get this now” is why this course exists. Cybersecurity doesn’t belong to the experts anymore; it belongs to all of us.

— Rich Greene

What You’ll Learn

  • Explain cybersecurity fundamentals using clear, business-ready language.
  • Identify common threat types and the vulnerabilities they exploit.
  • Understand how cryptography, authentication, and access control establish digital trust.
  • Describe how networks, data flows, and Zero Trust principles reduce risk.
  • Recognize how malware, phishing, and social engineering attacks operate—and how to disrupt them.
  • Connect frameworks such as NIST CSF, CIS Controls, and MITRE ATT&CK/D3FEND to practical defense strategies.
  • See how cloud, IoT, and AI reshape both opportunities and risk.
  • Collaborate confidently with technical teams on security policies and incident response.

Business Takeaways

  • Speak the language of cybersecurity—bridging the gap between technical and business teams.
  • Identify and communicate risk clearly in terms of impact, accountability, and resilience.
  • Support compliance and governance efforts with an informed understanding of frameworks and controls.
  • Strengthen organizational security culture by promoting awareness and shared responsibility.
  • Contribute to strategy and decision-making with confidence rooted in understanding, not fear.
  • Empower others—becoming the person in the room who can translate cybersecurity into action.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC301: Introduction to Cyber Security.

Section 1Cybersecurity Foundations

Begin with the essentials that make cybersecurity practical. Learn how threats become risk, why availability can be life-critical, and how trust grows from clear process and communication. Each lab brings concepts to life so you can explain, choose, and apply controls with confidence.

Labs

  • The Risk Equation in Action
  • The Missing Patch
  • To Report or Not?
  • Frameworks in the Wild
  • Evidence Trail

Overview

Every strong security program begins with understanding why security matters and how risk actually forms. Day 1 anchors the course with plain-language fundamentals the human, legal, and technical building blocks that make cybersecurity both possible and practical. Students move from abstract ideas (“hackers and firewalls”) to clear reasoning: how threats exploit vulnerabilities, why availability can be as life-critical as confidentiality, and how frameworks turn scattered controls into repeatable habits of trust.

By the end of this section, learners can explain the CIA Triad, apply the Risk = Threat × Vulnerability × Impact model to real situations, and recognize that cyber resilience depends as much on communication and accountability as on technology. The day closes by connecting these ideas to global compliance frameworks GDPR, HIPAA, SOX and showing that security is really about people, process, and proof.

Cybersecurity is not a collection of tools it’s a way of thinking. Section 1 transforms beginners into informed practitioners who can describe why controls exist, how risk evolves, and what accountability looks like when things go wrong. From the first lab forward, learners begin building the confidence to explain, choose, and apply controls that protect both people and mission because trust, once earned, is the true currency of security.

Full Lab Details

  • Lab 1.1 - The Risk Equation in Action
    • Students explore what cybersecurity really means beyond firewalls and hackers—learning that it’s ultimately about protecting trust. Through real-world hospital scenarios, they apply the Threat × Vulnerability × Impact = Risk formula to reason through how small, everyday actions—like patching or clicking an email—shape organizational risk. The lab builds foundational understanding of the CIA Triad (Confidentiality, Integrity, Availability) and teaches students to see security as balance, not fear.
  • Lab 1.2 – The Missing Patch
    • In this hospital-based scenario, students examine how delayed updates and “just one more day” decisions create systemic risk. They learn to connect technical vulnerabilities to operational and safety impacts, and to frame risks in business language that leadership understands. The lab highlights that cybersecurity and safety are partners—not opposites—and that effective communication and accountability drive resilience.
  • Lab 1.3 – To Report or Not?
    • Students step into the role of a compliance lead managing a cross-border incident involving a lost device and potential data exposure. They learn to distinguish between incidents, suspected breaches, and confirmed breaches, and to apply international laws like GDPR, PDPA, and PIPEDA. The exercise emphasizes judgment under time pressure—deciding who to notify, when, and why—and shows how timely, documented decisions convert legal risk into credibility.
  • Lab 1.4 – Frameworks in the Wild
    • Acting as a GRC advisor for a global airline, students untangle the alphabet soup of GDPR, NIST CSF, ISO 27001, and CIS Controls to design a unified security governance model. They discover that frameworks aren’t red tape—they’re a shared language of accountability that connects strategy, compliance, and daily operations. By the end, students can map frameworks to risk areas and explain how alignment across teams builds organizational trust and consistency.
  • Lab 1.5 – Evidence Trail
    • Students follow an investigation inside a medical organization to understand how to preserve evidence integrity and maintain a defensible chain of custody. They practice documenting each handoff, applying Legal Holds, and explaining why proper process matters as much as technical skill. The lab reinforces that credibility in cybersecurity comes from proof, not just prevention—and that documentation transforms response into resilience.

Section 2Building Digital Trust: Cryptography, Identity, and Access

Build the foundations of digital trust with the core ideas behind encryption, identity, and access. Learn how math protects data, how certificates prove who’s who, and how authentication and authorization shape accountability. Each lab turns complex concepts into clear steps you can use with confidence.

Labs

  • Secrets, Salts, and the Trust Equation
  • Keys to the Kingdom: Proving Identity
  • Lock, Stock, and Certificate
  • Who Are You? The AAA of Digital Identity
  • The Passwordless Pivot

Overview

Section 2 moves from why security matters to how digital trust is built and verified. Students explore how cryptography underpins nearly every act of trust in the modern enterprise—from a secure login to a cloud transaction or a digital signature. The day follows the chain of digital trust step by step: first encrypting data for confidentiality and integrity, then proving identity through certificates, and finally enforcing accountability through authentication, authorization, and logging.

Learners discover that cryptography isn’t magic—it’s math that earns trust—and that identity systems don’t just control access; they define responsibility. By the end of the day, students can explain in plain language how encryption, certificates, and identity management combine to make “Zero Trust” possible.

By the end of Section 2, students can trace how every secure interaction—from encryption to login to audit log—relies on cryptographic proof and disciplined identity management. They learn that the real challenge isn’t technology, but earning and maintaining trust: protecting keys, verifying identity, enforcing least privilege, and proving integrity at every step. Day 2 transforms abstract math into the language of credibility—showing that in cybersecurity, trust is not a feeling; it’s a function.

Full Lab Details

  • Lab 2.1 – Secrets, Salts, and the Trust Equation
    • Students experience how math creates digital trust by verifying integrity and protecting confidentiality. They compute file hashes, observe how even small changes alter a digital fingerprint, and apply symmetric and asymmetric encryption to protect data. The lab distinguishes hashing (proof of integrity) from encryption (control of visibility)—showing that cybersecurity begins with measurable, mathematical trust, not assumption.
  • Lab 2.2 – Keys to the Kingdom: Proving Identity
    • Students generate RSA and ECC key pairs, create digital signatures, and verify authenticity using public-key cryptography. They see how private keys sign and public keys verify, proving both integrity and authenticity. Through hands-on tampering tests, learners understand why digital signatures underpin everything from software updates to legal documents—and that trust must be proven, not presumed.
  • Lab 2.3 – Lock, Stock, and Certificate
    • Students build a small HTTPS website with a self-signed TLS certificate and test how browsers and tools respond. They learn that TLS ensures encryption, not legitimacy, and that HTTPS warnings are signs of protection, not failure. By inspecting certificates and comparing them to real CA-issued versions, learners separate confidentiality (the lock) from authentication (the identity)—understanding why TLS ≠ trust.
  • Lab 2.4 – Who Are You? The AAA of Digital Identity
    • Students investigate an insider-style data incident and apply the AAA model to pinpoint where trust broke down. Through analysis and discussion, they learn how authentication proves identity, authorization limits actions, and accounting provides visibility and evidence. The lab reinforces that trust is a system, not a setting—and that least privilege, logging, and accountability are inseparable pillars of identity security.
  • Lab 2.5 – The Passwordless Pivot
    • Students explore how passkeys replace passwords using public/private key pairs for phishing-resistant authentication. They analyze real-world rollout challenges—device recovery, privacy, and legacy systems—and design a hybrid deployment strategy. Beyond technology, they discover that passwordless adoption is about trust and culture: making users feel secure and confident in the systems that protect them

Section 3Understanding Networks and Data in Motion

Explore how data travels and what it reveals along the way. You’ll break down layers, packets, routing, and DNS, then see how firewalls and segmentation shape trust. Each lab turns network theory into clear understanding so you can follow data in motion and make smarter defense decisions grounded in visibility.

Labs

  • Ports and Protocols
  • HopbyHop
  • DNS Detective
  • Encrypted, Not Invisible
  • Zero Trust, Zero Assumptions

Overview

Section 3 shifts the learner’s focus from individual systems to the pathways that connect them. Every modern attack, investigation, and defense activity relies on understanding how data moves across networks—and how visibility, segmentation, and trust change along the way.

Students start by demystifying network fundamentals: layers, packets, ports, and protocols. They trace what really happens when you load a web page or send an email, seeing how every hop leaves behind clues defenders can use. From there, they explore addressing and routing, DNS resolution, and the difference between metadata and content. The day then expands into how traffic is filtered, logged, and segmented through firewalls, proxies, and DMZs—and how design decisions at these layers shape both performance and security.

The capstone concept, Zero Trust networking, ties it all together: the idea that in modern environments, trust is not a perimeter but a process—one continually verified for every user, device, and packet in motion. By day’s end, students can visualize the full journey of data, explain how it’s protected (or exposed) at each stage, and apply the language of networks to real-world defense decisions.

Data in motion is where visibility, trust, and vulnerability converge. Section 3 transforms abstract network diagrams into a living system of connections, dependencies, and controls. Students walk away able to see the network as defenders do—understanding how information flows, how attacks exploit those flows, and how layered defenses keep operations resilient.

Full Lab Details

  • Lab 3.1 – Ports and Protocols
    • Students learn how to “read” network behavior by exploring how ports, protocols, and services define communication. Through hands-on tests with DNS, HTTP, and HTTPS, they discover how ports signal purpose and intent — and how unusual or non-standard activity can reveal misconfiguration or attack. The lab builds intuition for interpreting metadata as meaningful evidence, teaching that knowing what normal looks like is the first step in detection.
  • Lab 3.2 – HopbyHop
    • Students use traceroute to follow packets hop by hop across internal and external networks. They analyze what each router reveals, where visibility stops, and how encryption alters what defenders can observe. The lab reinforces that every network path represents both a dependency and a trust relationship—teaching learners to recognize where control ends, why encryption is non-negotiable, and how network visibility shapes real-world defense.
  • Lab 3.3 – DNS Detective
    • In this investigative lab, students dig into DNS to uncover how domains resolve, compare results across multiple resolvers, and trace the root-to-authoritative chain of trust. They examine record types (A, MX, TXT, NS, DNSKEY) and see how attackers exploit them. By the end, students understand that DNS isn’t just a naming service — it’s an early-warning system for integrity and visibility, central to Zero Trust and digital accountability.
  • Lab 3.4 – Encrypted, Not Invisible
    • Students confront the paradox of encryption: it protects users and hides threats. Working through a simulated TLS 1.3 incident, they learn how to balance privacy and inspection, distinguishing between encryption and trust. The exercise emphasizes that modern defenders rely on metadata, governance, and context—not decryption alone—to detect hidden risks. The key takeaway: encryption protects information, but visibility protects people.
  • Lab 3.5 – Zero Trust, Zero Assumptions
    • Learners step into the role of an advisor helping an enterprise evolve from perimeter-based security to Zero Trust architecture. They apply identity verification, least privilege, microsegmentation, and continuous monitoring to stop a ransomware-style incident. This lab transforms “Zero Trust” from buzzword to blueprint—showing that trust isn’t removed; it’s earned, verified, and renewed through context.

Section 4Modern Attack Tactics: From Phishing to AI-Powered Threats

Step into the attacker’s mindset to understand how threats evolve. Section 4 explores phishing, credential abuse, wireless compromise, malware behavior, and AI-driven campaigns. Labs help you trace attacker choices, map tactics to ATT&CK and D3FEND, and build defenses that break the chain of compromise.

Labs

  • The Many Doors In
  • Rogue Signal
  • Name That Malware
  • The AI Arms Race: Who’s Winning?
  • ATT&CK & D3FEND

Overview

Day 4 moves from defense to offense—not to make students hackers, but to help them think like one. By understanding how attackers choose their targets, exploit trust, and chain together small weaknesses into major compromises, learners develop the mindset needed to anticipate, detect, and disrupt modern attacks.

The day begins with the human side of exploitation—phishing, social engineering, and credential abuse—before expanding into the technical realities of wireless compromise, malware behavior, and living-off-the-land attacks. Students learn how adversaries bypass firewalls, manipulate trust, and weaponize legitimate tools like PowerShell or cloud services.

From there, the course explores how AI is reshaping both sides of the battlefield: automating phishing, voice cloning, malware generation, and disinformation campaigns. Learners conclude the day by mapping attacker behavior using MITRE ATT&CK and D3FEND, translating complex intrusions into a structured model that connects offensive tactics to defensive countermeasures.

By the end of Section 4, students can recognize not just what an attacker did, but why—and use that understanding to design defenses that stay one step ahead.

Full Lab Details

  • Lab 4.1 – The Many Doors In
    • Students trace a realistic multi-vector intrusion where phishing, smishing, vishing, USB drops, and credential reuse combine into a cascading breach. They learn how attackers chain social engineering with technical exploits and how small human decisions either close or open attack paths. The lab reinforces that defense succeeds when awareness, architecture, and culture intersect—turning every employee into a part of the security perimeter.
  • Lab 4.2 – Rogue Signal
    • Students investigate a rogue Wi-Fi “Evil Twin” scenario to understand how attackers impersonate trusted networks and intercept data. They explore man-in-the-middle tactics, credential theft, and the limitations of encryption when authenticity is faked. Through response and reflection, learners connect these lessons to Zero Trust principles, emphasizing continuous verification, VPN auto-connect, and human vigilance as the real wireless defense.
  • Lab 4.3 – Name That Malware
    • Through a series of short, realistic case studies, students identify and analyze common malware types—worms, Trojans, RATs, keyloggers, ransomware, and fileless attacks. Each scenario reveals behavioral patterns and propagation methods, helping learners distinguish between code types by intent and action, not file name. The lab builds analytic reasoning, showing how visibility and layered defenses turn detection into understanding.
  • Lab 4.4 – The AI Arms Race: Who’s Winning?
    • Students step into the role of a security governance team evaluating an AI-driven SOC pilot. They interpret operational data, financial outcomes, and staff sentiment to balance automation with human oversight. The exercise highlights that speed without trust creates fragility, and the strongest defense model keeps humans in the loop — pairing automation with explainability, transparency, and cultural alignment.
  • Lab 4.5 – ATT&CK & D3FEND
    • Learners use the MITRE ATT&CK and D3FEND frameworks to connect offensive tactics to defensive actions. They map phishing and PowerShell abuse to specific ATT&CK techniques, then identify corresponding D3FEND controls like content filtering and executable allowlisting. By the end, students can translate raw alerts into structured intelligence—turning investigation findings into clear, actionable reporting that bridges technical analysis and business communication.

Section 5Cybersecurity Technologies and Web Security

Section 5 ties the course together with the tools, teams, and web risks that shape real security. You’ll break down common web flaws, see how SOC technologies work in practice, and explore cloud, IoT, and AI-driven defense. Each lab shows how people and systems combine to protect data, safety, and trust.

Labs

  • The Web We Built: Layers of Trust
  • Inside the Glass Box
  • The Cloud Breach That Wasn’t
  • The Factory Floor Goes Dark
  • Human + Machine

Overview

Day 5 brings the course full circle—from individual awareness to organizational resilience. Students move from understanding how attacks happen to mastering how modern defenses work together. They’ll see how technologies like SIEM, EDR, IDS/IPS, IAM, and SOAR form the nervous system of a security program—collecting, correlating, and responding to threats across networks, endpoints, and cloud environments.

The day opens with the web itself, where most attacks still begin. Students dissect web application vulnerabilities like XSS, SQL injection, and clickjacking, learning how insecure input, weak validation, and missing controls turn trusted sites into attack platforms. They explore HTTPS, security headers, and OWASP Top 10 risks—and see how even secure connections don’t guarantee secure applications.

From there, the focus shifts to the tools and teams that power cybersecurity in practice. Learners step inside the SOC to experience how alerts become action, how automation supports humans (not replaces them), and how roles from GRC to Red and Purple Teams combine for continuous improvement. They then move beyond the SOC—into the cloud, IoT, and OT—to understand shared responsibility, configuration risk, and how digital and physical systems are increasingly connected.

Finally, students look ahead to the future of defense, exploring how AI is reshaping security operations, decision-making, and ethics. They learn to separate hype from value, balancing automation with oversight, and discovering why the most resilient organizations are human-led but machine-accelerated.

By the end of this section, learners can explain, evaluate, and communicate how all these technologies, teams, and trends fit into a single goal: protecting data, people, and trust—wherever they live.

Full Lab Details

  • Lab 5.1 – The Web We Built: Layers of Trust
  • Students analyze a real-world web security incident to see how misplaced trust, weak validation, and missing controls combine into compromise. They explore how vulnerabilities like XSS, SQL Injection, and insecure headers arise from everyday development shortcuts and organizational pressure. The lab emphasizes that secure web design is a shared responsibility—spanning users, developers, administrators, and leadership—and that encryption alone doesn’t equal safety.
  • Lab 5.2 – Inside the Glass Box
  • Learners step into a live Security Operations Center (SOC) scenario to experience detection, automation, and collaboration in action. They follow alerts through SIEM, EDR, and SOAR, practicing triage, escalation, and communication under pressure. The lab shows that effective defense depends not on tools, but on coordination, clarity, and trust between teams—turning chaos into confidence during incidents.
  • Lab 5.3 – The Cloud Breach That Wasn’t
    • Through six short case studies, students uncover how shared responsibility defines cloud security success or failure. They analyze SaaS, PaaS, and IaaS contracts to pinpoint where customer misconfigurations—not provider flaws—caused data exposure. The lab reinforces that cloud security is a partnership, not a handoff, and that resilience depends on clear ownership, visibility, and continuous governance.
  • Lab 5.4 – The Factory Floor Goes Dark
    • Students investigate how a well-intentioned IT security update shut down an entire factory floor, exploring the clash between data protection and physical safety in converged IT/OT networks. They identify failures in segmentation, change control, and collaboration, learning that real resilience requires balance between confidentiality, integrity, and availability. The lab highlights the principle of shared fate — where cybersecurity and operational safety depend on coordination, not control.
  • Lab 5.5 – Human + Machine
    • Learners design the SOC of the future, comparing automation-driven and human-centered defense models. They build strategies that blend AI efficiency with human judgment, emphasizing training, ethics, and adaptability. By the end, students can articulate how future-ready security programs will learn faster than attackers by combining machine precision with human wisdom — creating a culture of trust, resilience, and continuous improvement.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

Students must have a properly configured system to fully take part in this course. If you do not carefully read and follow these instructions, you will not be able to do the hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • The SEC301 labs use an online virtualized cloud environment. Students access the environment via a web browser to interact with cloud-based Windows 10 and Linux computers.
  • Therefore, any computer with a web browser and internet access allows student to perform the labs.
  • A larger screen is very helpful, as is a physical keyboard and mouse. Doing the labs on a tablet is very difficult.
  • In-Person attendees must have wireless networking (802.11 standard). There is no wired Internet access in the physical classroom. The classroom will have electrical outlets at the student's tables.
  • Online and LiveOnline students require an Internet connection. We will use Zoom and Slack in online classes. If it is possible to use a second monitor, that can be helpful but this is not a requirement.
  • OnDemand students use the SANS OnDemand player. They get access to that player when their class access begins.
  • In some cases, personal or work VPNs can interfere with both online access and accessing the labs. The ability to turn off VPNs is a requirement.

If there are questions about the computer specifications, please contact customer service.

SEC301 training is recommended for a diverse range of individuals, including:

The SEC301 Introduction to Information Security course is designed to address the needs of:

  • People who are new to information security and in need of an introduction to the fundamentals of security
  • Those who feel bombarded with complex technical security terms they don't understand but want to understand
  • Professionals who need to be conversant in basic security concepts, principles, and terms, but who don't need "deep in the weeds" detail
  • Those who have decided to make a career change to take advantage of the job opportunities in information security and need formal training/certification
  • Managers who worry their company may be the next mega-breach headline story on the 6 o'clock news

The GIAC Information Security Fundamentals (GISF) certification validates a practitioner's knowledge of security's foundation, computer functions and networking, introductory cryptography, and cybersecurity technologies. GISF certification holders will be able to demonstrate key concepts of information security including understanding the threats and risks to information and information resources and identifying best practices to protect them.

  • Cyber security terminology
  • The basics of computer networks
  • Security policies
  • Incident response
  • Passwords
  • Introduction to cryptographic principles

More Certification Details

  • Electronic Courseware for each day of training that includes the slides presented and notes to explain them plus an electronic lab workbook explaining the hands-on labs
  • Five full days' worth of high-quality instruction and explanation.
  • MP3 audio files of the complete course lecture.

  • SEC301 does not have prerequisites.
  • SEC301 assumes only the most basic knowledge of computers.
  • SEC301 makes no assumptions regarding prior security knowledge.

The SEC301 course is a part of the “New to Cybersecurity” Learning Path, which covers a wide spectrum of security topics, including a mix of technical and managerial issues and real-life examples.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Cybersecurity is the practice of protecting computer systems, networks, and data from digital attacks, unauthorized access, damage, or theft. It involves a combination of technologies, processes, and measures designed to defend against threats like hacking, malware, and phishing. Cybersecurity is crucial because today, nearly every aspect of personal, business, and government activity relies on the internet. A successful cyberattack can lead to significant financial losses, data breaches, identity theft, and even damage to an organization’s reputation. With increasing threats from cybercriminals, nation-state actors, and internal risks, safeguarding sensitive information and maintaining the integrity of systems is essential for the smooth functioning of societies, businesses, and governments. As technology evolves, so do the tactics used by cyber attackers, making continuous vigilance and adaptation in cybersecurity practices vital for maintaining digital safety.

SEC301: Introduction to Cyber Security will provide a solid foundation in essential security principles, making it ideal for those starting in cybersecurity. The course covers key topics such as authentication, encryption, network security, and malware defense. You'll learn how to secure systems, understand cyber threats, and gain practical skills in handling real-world security challenges. Completing this course will improve your ability to communicate confidently about cybersecurity concepts, boost your problem-solving skills, and enhance your understanding of technologies like firewalls, cryptography, and access controls. It’s an excellent way to prepare for entry-level roles in cybersecurity, helping you build the skills and knowledge needed to advance in the field, secure certifications, and stand out to potential employers.

Relevant Job Roles

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Systems Developer (DCWF 632)

DoD 8140: Cyber IT

Oversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.

Explore learning path

Systems Authorization (OPM 611)

NICE: Oversight and Governance

Responsible for operating an information system at an acceptable level of risk to organizational operations, organizational assets, individuals, other organizations, and the nation.

Explore learning path

Communications Security (COMSEC) Management (OPM 723)

NICE: Oversight and Governance

Responsible for managing the Communications Security (COMSEC) resources of an organization.

Explore learning path

Cyber Defense Infrastructure Support Specialist (DCWF 521)

DoD 8140: Cybersecurity

Deploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.

Explore learning path

Product Support Manager (DCWF 803)

DoD 8140: Cyber Enablers

Manages support resources and readiness for system components, ensuring operational capability through lifecycle logistics and maintenance.

Explore learning path

Security Architect (DCWF 652)

DoD 8140: Cybersecurity

Designs secure enterprise systems considering environmental constraints and translates them into enforceable security processes and protocols.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam September 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €2,820 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Gulf Region 2026

    Dubai, AE & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Defense Initiative 2026

    Washington, DC, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online: Jan 2027 (EDT)

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam February 2027

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €2,820 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Chicago 2027

    Chicago, IL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $3,000 USD*Prices exclude applicable local taxes
    Registration Options
Showing 10 of 10

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources