Course Description
CIS2530 is the introductory cybersecurity course. The Statewide Course Numbering System titles it Introduction to Cybersecurity and defines it as a course that "introduces students to cybersecurity. It provides information related to cyber threats as well as the basic security design and information assurance fundamentals. In addition the course covers information assurance controlling laws and guidelines." There is no statewide prerequisite.
✅ Three Florida public institutions carry it, all at 3 credits, and all three use the identical statewide title — Lake-Sumter State College, Pensacola State College and the University of West Florida. ⚠ That uniformity is worth stating, because it is uncommon in this catalog and it means a student can transfer this course between them without the usual caveats.
⚠ Note the third clause of the statewide definition: "information assurance controlling laws and guidelines." This is not purely a technical course. Cybersecurity is practised inside a legal and regulatory framework — what you are permitted to do is as much of the discipline as what you are able to do — and a course that taught only technique would produce someone dangerous.
The course also functions as a gateway. It sits at the 2000 level, assumes no prerequisite, and is frequently the point at which a student decides whether this field suits them. ⚠ It is worth knowing early that cybersecurity work is mostly methodical rather than dramatic: reading logs, applying patches, writing policy, checking configurations. The students who thrive are usually the ones who find that satisfying rather than the ones drawn by the idea of breaking in.
Learning Outcomes
Required Outcomes
- Explain the CIA triad — confidentiality, integrity, availability — and analyse a scenario in terms of which property is at stake.
- Describe the principal threat categories: malware, phishing and social engineering, denial of service, insider threat, supply chain compromise.
- Describe threat actors and their motivations, from opportunistic criminals to organised crime to state-sponsored actors, and explain why motivation shapes defence.
- Apply basic risk assessment: asset identification, threat, vulnerability, likelihood, impact, and the difference between a risk and a vulnerability.
- Explain authentication, authorisation and accounting, and the role of multi-factor authentication.
- Explain access control models — discretionary, mandatory, role-based — and apply least privilege.
- Describe cryptography at a working level: symmetric and asymmetric encryption, hashing, digital signatures, certificates and what each guarantees.
- Describe network security fundamentals: firewalls, segmentation, VPNs, intrusion detection, and secure protocols.
- Apply defence in depth and explain why a single control is never sufficient.
- Describe security operations: logging, monitoring, incident response phases, and business continuity.
- Explain the governing legal framework — ⚠ including the Computer Fraud and Abuse Act — and the regulatory regimes that apply by sector (HIPAA, FERPA, PCI DSS, GLBA).
- Explain authorisation as an ethical and legal requirement: testing a system without written permission is a crime regardless of intent.
- Describe common security frameworks, principally the NIST Cybersecurity Framework.
Optional Outcomes
- Use security tools in a controlled laboratory — packet capture, vulnerability scanning, password auditing.
- Harden an operating system to a published benchmark.
- Analyse a real breach case and identify the controls that would have prevented or limited it.
- Address cloud security and shared responsibility models.
- Address secure software development at an introductory level.
- Participate in a capture-the-flag exercise or a cyber competition.
- Prepare for the CompTIA Security+ examination.
Major Topics
Required Topics
- Foundations — the CIA triad, non-repudiation, authenticity; security as risk management rather than as prevention.
- Threats and attacks — malware families, phishing and social engineering, web attacks, denial of service, insider and supply chain threats.
- Threat actors — capability, motivation, and what each implies for defence.
- Risk management — assets, threats, vulnerabilities, likelihood and impact; controls and residual risk.
- Identity and access — authentication factors, MFA, access control models, least privilege, separation of duties.
- Cryptography — symmetric and asymmetric, hashing, digital signatures, PKI and certificates; ⚠ what each does and does not protect.
- Network security — segmentation, firewalls, VPN, IDS/IPS, wireless security, secure protocols.
- System and endpoint security — hardening, patching, configuration management, endpoint protection.
- Security operations — logging and monitoring, SIEM concepts, the incident response lifecycle, disaster recovery and continuity.
- Law, regulation and ethics — the Computer Fraud and Abuse Act, sectoral regulation, privacy law, and the absolute requirement of authorisation.
- Frameworks and governance — NIST CSF, policy, standards and procedures, and the role of security awareness.
Optional Topics
- Hands-on laboratory work with security tools.
- Operating system hardening to a CIS benchmark.
- Breach case studies.
- Cloud security and shared responsibility.
- Secure development and the OWASP Top Ten.
- Capture-the-flag and competition preparation.
- Certification preparation.
Resources & Tools
- Principles of Information Security by Whitman and Mattord is the most widely adopted text for this course.
- CompTIA Security+ Study Guide (Sybex) is common where the course is aligned to certification, and is worth having either way — ⚠ Security+ is the credential most entry-level cybersecurity postings ask for, including US government and contractor roles, where it satisfies the DoD 8570/8140 baseline.
- ⚠ Free and authoritative primary material: the NIST Cybersecurity Framework and the NIST SP 800 series; the CIS Controls and CIS Benchmarks; the OWASP Top Ten. These are what practitioners actually work from, and reading a control description in the original is a better exercise than a textbook summary of it.
- Free hands-on practice: TryHackMe and Hack The Box (introductory tiers), Wireshark, and virtual machine labs built locally. ⚠ Practise only on systems you own or are explicitly permitted to use — see the legal note below, which is not a formality.
- Florida-specific: CyberFlorida, the state's cybersecurity centre hosted at the University of South Florida, runs scholarships, competitions and workforce programmes and is a genuine resource for students here.
- ⚠ The NSA/DHS National Centers of Academic Excellence designation is held by several Florida institutions, including UWF — it matters for federal scholarship and hiring pipelines, and is worth checking for your own institution.
Career Pathways
- Information Security Analyst (SOC 15-1212) — the direct destination, and one of the faster-growing occupations in the United States.
- Computer Network Support Specialist (SOC 15-1231) and Network and Computer Systems Administrator (SOC 15-1244) — ⚠ the realistic first jobs, since most security roles expect operational experience first.
- Computer User Support Specialist (SOC 15-1232) — the common entry point.
- Information Security Manager and compliance roles — later, with experience.
- Florida employers: the defence and space sector on the Space Coast and in Central Florida, where clearance-eligible security staff are in sustained demand; US Central Command and US Special Operations Command at MacDill in Tampa, with their contractor ecosystem; healthcare systems under HIPAA obligations; financial services in South Florida; state agencies and the Florida Digital Service; and county school districts and governments, which have been targeted repeatedly by ransomware.
- ⚠ An honest note on entry: cybersecurity is frequently advertised as a field with a talent shortage, and that is true of experienced practitioners rather than of graduates. Entry-level security roles are competitive, and the usual route in is a help-desk or systems administration job first. Certifications, a home lab and competition participation are what distinguish candidates — and all three are available to a student in this course.
Special Information
Offering Notes — offerings and hours, school by school
| Institution | Its title | Credits | Contact hours |
| Lake-Sumter State College | Introduction to Cybersecurity | 3 | not published |
| Pensacola State College | Introduction to Cybersecurity | 3 | not published |
| University of West Florida | Introduction to Cybersecurity | 3 | not published |
Two are Florida College System institutions and one is in the State University System, so statewide numbering guarantees transfer between them. ✅ Identical title, identical credit value, no drift — one of the cleanest numbers in this catalog.
⚠ The mix of sectors is itself useful here: a student can take this at a state college and carry it into the University of West Florida's cybersecurity programme, which is exactly the transfer path Florida's numbering exists to protect. ⚠ It is still a 2000-level course, so confirm how it counts toward an upper-division requirement rather than assuming.
⚠ The 45 contact hours at the top of this guide are derived — the Florida convention for a 3-credit lecture course. No institution publishes an hour figure.
⚠⚠ Authorisation is the law, not an etiquette rule
Of everything in this course, one point has consequences that outlast the grade. Accessing a computer system without authorisation is a federal crime under the Computer Fraud and Abuse Act, and comparable state offences exist in Florida. ⚠ Intent does not provide a defence, and neither does curiosity, nor finding a vulnerability and reporting it.
What that means in practice, and it is worth being precise:
- Practise only on systems you own, or on platforms explicitly built for it — TryHackMe, Hack The Box, a home lab of virtual machines, your institution's designated range.
- Scanning a network you do not administer is not a neutral act, including your university's. ⚠ Doing it on campus infrastructure is the single most common way a cybersecurity student ends their own career before it starts, and institutions treat it as a disciplinary matter as well as a legal one.
- If you find a vulnerability incidentally, report it and stop. Do not explore further to "confirm" it; that exploration is the offence.
- Where an organisation runs a bug bounty or a vulnerability disclosure programme, the scope document is the authorisation — read it and stay inside it.
⚠ Employers in this field run background checks, and clearance-eligible roles run thorough ones. A conviction, or a university disciplinary record for unauthorised access, closes doors permanently. The course teaches this because it needs to be understood before the skills are.
Position in the curriculum and certification
A 2000-level course with no prerequisite, and typically the first cybersecurity course in an A.S. or B.S. pathway. It precedes network security, digital forensics, ethical hacking and secure development courses. ⚠ Where it is aligned to CompTIA Security+, the alignment is worth exploiting — sitting the examination shortly after the course, while the material is fresh, is far easier than returning to it later. The examination is a separate cost; ask about voucher programmes, which many Florida institutions have.
Workload
Budget six to nine hours a week. ⚠ The breadth is the difficulty rather than the depth. This course touches networking, operating systems, cryptography, law and risk management in a single term, and students with no prior IT background find the volume of new vocabulary heavier than any single concept. Build a glossary from week one; the terminology is most of what a certification examination tests.
AI Integration
Cybersecurity is being reshaped by these tools on both sides simultaneously, and this course is the right place to start thinking about it clearly.
Genuinely useful: explaining a concept a second way — public key cryptography is the standard sticking point and models explain it well; generating practice questions, which is exactly how certification study works; explaining log entries, error messages and command output, which is a real time-saver in operations; summarising a long standard or framework document; drafting policy and awareness material; and explaining an unfamiliar tool's purpose.
⚠⚠ Where it fails:
- Security advice that is outdated or wrong. Recommendations change — password rotation policy, TLS versions, hashing algorithms — and a model trained on older text will confidently recommend a practice the field has retired. ⚠ Check any control recommendation against current NIST guidance.
- Invented CVEs, tool flags and configuration syntax. A generated firewall rule or hardening command may not do what it says, and in security a misconfiguration is the vulnerability.
- False confidence about whether something is safe. Asked "is this configuration secure", a model gives an answer; security is contextual, and that answer has no knowledge of your environment, your threat model or your regulatory obligations.
⚠⚠ The two-sided reality this course should be honest about:
Attackers use these tools. Phishing messages no longer have the spelling errors that used to be the tell; they are fluent, contextual and cheap to produce at scale. ⚠ That changes defensive advice materially — "look for bad grammar" is obsolete guidance, and awareness training built on it is training people to miss the current attack.
Defenders use them too, in log analysis, anomaly detection and triage, and that is where the growth in the field is. But an analyst who cannot read a log unaided cannot evaluate what the tool flagged, and alert triage is precisely the judgement a junior analyst is hired for.
Academic integrity: read your syllabus. ⚠ And note the obvious but important point that asking a model to help you attack a system you are not authorised to test is not made lawful by the tool being willing. The authorisation rule above applies to everything, whatever produced it.