📚 Series Maritime Cybersecurity Learning Roadmap | PART 1 Lesson 5 of 5 · Course Index →
PART 1 · Lesson 5 Fundamentals Knowledge Map

Security+ and the Cybersecurity Knowledge Map

Network · Identity · Cryptography · Vulnerability Management · Security Operations · Incident Response · Risk — the full terrain of professional cybersecurity, and how this series maps across it.

Captain Paul
Captain Paul
Maritime Cybersecurity · IACS UR E26/E27
September 2026
Maritime Cybersecurity Learning Roadmap
🎯 Lesson Objective

After this lesson you can describe what CompTIA Security+ is and what it validates, explain each of its six domain areas, map the concepts from this series to those domains, understand how the Security+ knowledge framework applies to maritime cybersecurity, and have a clear picture of where the remaining parts of this series take you next.

1. What Is CompTIA Security+?

CompTIA Security+ (currently SY0-701, released November 2023) is a vendor-neutral, globally recognised cybersecurity certification that validates baseline competency across the core domains of the field. It is the most widely deployed entry-to-mid-level cybersecurity certification — required or preferred by the US Department of Defense (DoD 8570/8140), NATO, and a large proportion of enterprise security job descriptions worldwide.

Security+ is not a tool-specific certification. It certifies that a holder understands why security controls exist, how threats and risks are analysed and managed, and what the correct response is to common security scenarios — across networks, systems, applications, and people. This makes its domain structure an excellent map of the professional cybersecurity knowledge landscape.

SY0-701
Current exam version (2023–)
90
Maximum questions (MCQ + PBQ)
90 min
Duration
750 / 900
Passing score (scaled)

Source: CompTIA official exam objectives, SY0-701 (2023). Exam details may change; verify at comptia.org before preparing.

2. The Six Domain Areas

Security+ SY0-701 is organised into six domains with percentage weightings that indicate their relative importance on the exam — and in the field.

12%
1. General Security Concepts

Security controls (preventive, detective, corrective), authentication concepts, cryptographic concepts (symmetric/asymmetric, hashing, PKI), zero trust, physical security. — This is the vocabulary layer. Lessons 1–5 in Part 1 of this series cover most of this domain.

This series: Part 1 (Lessons 1–5) covers most of Domain 1.
22%
2. Threats, Vulnerabilities, and Mitigations

Attack types (phishing, ransomware, MitM, DoS, SQL injection, XSS, zero-day), threat actors and their motivations, vulnerability scanning, threat intelligence, attack surface management. The largest domain — attackers, their tools, and how defenders respond.

This series: Part 2 (Lessons 6–13) — Understanding Cyber Attacks covers this domain.
18%
3. Security Architecture

Cloud security, network infrastructure security (VLANs, DMZ, firewalls, VPN, SD-WAN), secure network design, resilience and recovery, data protection, identity and access management (IAM, RBAC, MFA, PAM). How security is built into system and network design.

This series: Parts 3–5 (Attackers & Defenders, Security Operations, Endpoint Security) cover this domain.
28%
4. Security Operations

The largest domain. Identity and access management operations, asset management, vulnerability management (scanning, prioritisation, patching), monitoring and alerting (SIEM, log analysis), incident response procedures, digital forensics, data loss prevention, endpoint security. The day-to-day work of a security team.

This series: Parts 4–7 (SOC, SIEM, Endpoint, Threat Hunting, Detection Engineering, SOAR) map directly to this domain.
14%
5. Security Program Management and Oversight

Risk management (identification, assessment, treatment), compliance (regulatory, frameworks), data privacy, third-party risk, audits, security awareness training, policies and procedures. The governance and management layer that ensures security is sustained organisationally, not just technically.

This series: Parts 9–12 (Maritime Compliance, IACS UR E26/E27, Cyber Resilience) connect directly to this domain.

3. Cryptography — The Security Enabler

Cryptography underpins almost every security control — TLS, VPNs, digital signatures, password hashing, and certificate-based authentication all depend on it. Security+ tests cryptographic concepts at a conceptual level — you do not need to implement algorithms, but you must understand their purpose and properties.

ConceptWhat It DoesExample
Symmetric encryptionSame key encrypts and decrypts. Fast but requires secure key sharing.AES-256 (bulk data encryption)
Asymmetric encryptionPublic key encrypts; private key decrypts. Solves key distribution problem.RSA-2048, ECC (TLS, SSH, code signing)
HashingOne-way function: produces fixed-length digest. Same input always gives same output; cannot be reversed.SHA-256 (file integrity), bcrypt (password storage)
Digital signatureProves authenticity and integrity. Sender signs with private key; recipient verifies with public key.Code signing, email DKIM, software updates
PKI / CertificatesInfrastructure for issuing and trusting digital certificates that bind public keys to identities.TLS/HTTPS, VPN mutual authentication, code signing CAs

4. How This Series Maps to the Knowledge Landscape

This series goes deeper than Security+ on the operational and maritime sides, but uses the same knowledge domains as its structural skeleton. Here is how the 12 parts of this series connect to professional cybersecurity — and to maritime-specific requirements:

Series PartSecurity+ Domain(s)Maritime Connection
Part 1 — FundamentalsDomain 1 (General Concepts)CIA Triad priorities differ in OT; NIST CSF = IMO MSC-FAL.1 framework
Part 2 — Cyber AttacksDomain 2 (Threats & Vulnerabilities)Phishing, ransomware, and GPS/AIS spoofing mapped to ship operations
Part 3 — Attack & DefenseDomains 2, 3MITRE ATT&CK → maritime-specific TTPs
Parts 4–5 — SOC, EndpointDomain 4 (Security Operations)SIEM for vessel fleets; EDR on OT workstations
Parts 6–7 — Detection, SOARDomain 4 (advanced operations)Detection engineering for OT protocols (Modbus, S7)
Part 8 — AI in SecurityDomain 4 (emerging tech)AI SOC for fleet cyber monitoring at scale
Parts 9–10 — Maritime IT/OTDomains 2, 3, 4ECDIS, AIS, IAS, GMDSS — architecture and threat landscape
Parts 11–12 — IACS, ResilienceDomain 5 (Governance)IACS UR E26/E27, IMO MSC-FAL, SOLAS, ISPS Code

5. Building Your Learning Path

The five lessons of Part 1 have given you the vocabulary and conceptual foundation for everything that follows. Here is a practical way to think about how to use this series alongside formal certification study:

If you are new to cybersecurity

Follow this series in order: Parts 1 → 2 → 3 → 4 → 5. Each part builds directly on the previous one. Supplement with Security+ study materials for the formal certification dimension. The concepts are the same — this series adds operational depth and maritime context.

If you are an IT professional entering maritime

You likely know Parts 1–7 conceptually. Jump to Parts 9–12 for the maritime-specific content, and use Parts 1–8 as reference and reinforcement. Pay particular attention to the IT/OT differences introduced in Part 9.

If you are a maritime professional entering cyber

Complete Parts 1–3 to build the cybersecurity foundation, then move directly to Parts 9–12 where your domain knowledge of ship systems and maritime regulation will give you significant advantage in understanding the technical content.

Captain Paul
✍️ Author Insight — From the Field
Captain Paul · Maritime Cybersecurity Consultant · IACS UR E26/E27

There is a scene that repeats itself across E26 CRSI assessments. A Master or Chief Engineer — a genuine expert with decades of sea service — walks into a cybersecurity assessment meeting and says: "Our vessel isn't connected to the internet, so we're fine." Everyone in the room knows, but no one says: the vessel is already connected through the satellite communications system, through the smartphones in every crew member's pocket, and through every USB drive plugged in at port.

This is not the fault of the Master or Chief Engineer. The maritime industry has a structural certification gap. Seafarers are trained in STCW, GMDSS, ISM, and the ISPS Code — but formal cybersecurity education is almost entirely absent. The knowledge that Security+ teaches — CIA Triad, threat actors, network segmentation, incident response — has simply not been systematically delivered to the maritime sector.

That is one of the reasons this series exists. Security+'s six domains are not "for IT people" — they are the foundational knowledge every person who operates a digital system needs to have. IACS UR E26 demands cyber resilience for computer-based systems aboard vessels — and that resilience is only real when the people who operate those systems understand what threats look like. That is why this lesson closes Part 1 with the full knowledge map first: see the terrain, then Part 2 onward maps each domain directly to real ship operations and the regulatory requirements you will encounter in the field.

✅ What We Learned — Part 1 Complete

Across Part 1's five lessons, you have built the complete foundation:

  • Lesson 1: CIA Triad, Asset/Threat/Vulnerability/Risk, Security Controls, Incident, Cyber Resilience — the core vocabulary.
  • Lesson 2: TCP/IP, IP/Port, TCP/UDP, DNS, HTTP/HTTPS, Firewalls, Segmentation, VPN — the networking layer.
  • Lesson 3: Processes, Users/Permissions, File System, Services, Process Monitoring, Windows/Linux comparison — the host layer.
  • Lesson 4: Kali Linux, Vulnerability Assessment vs Penetration Test, five testing phases, maritime OT constraints, legal/ethical framework.
  • Lesson 5: Security+ knowledge map — six domains, cryptography primer, and how this series maps to the full professional landscape.
▶ Where This Leads Next — Part 2

PART 2 — Understanding Cyber Attacks takes the foundation from Part 1 and applies it to the most important attack types you will encounter as a security professional and maritime cyber practitioner: Phishing, Ransomware, DoS/DDoS, Man-in-the-Middle, SQL Injection, XSS, Zero-Day vulnerabilities, and DNS attacks. Each lesson explains how the attack works, what makes it effective, and — critically — how to detect and defend against it.

Understanding attacks from the attacker's perspective — not just a high-level description but the actual mechanics — is what separates a practitioner who can build effective defences from one who can only follow a compliance checklist. Part 2 is where that understanding begins.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

Top Ranked · All Posts

Popular Posts