Advanced Diploma – Cybersecurity Analyst
This guide supports students in the Advanced Diploma – Cybersecurity Analyst programme at Vector Technology Institute (VTI). Use it for cybersecurity assignments, security labs, risk assessments, incident-response exercises, standards-based work, technical reports, and research projects.
Start with the question or scenario, identify the kind of evidence it needs, use authoritative sources first, and work only in a safe and authorized environment. Keep an evidence trail so that your analysis, recommendation, and references can be checked by another student, instructor, or practitioner.
How to Use This Guide Successfully
- Define the cybersecurity problem or question. State the asset, scenario, risk, control, incident, or research claim and what a useful answer must establish.
- Identify the evidence type. Decide whether the task needs a standard or framework, technical guidance, threat intelligence, government advice, or peer-reviewed research.
- Use authoritative sources first. Check the relevant standard, framework, agency, or official tool documentation before relying on summaries or tutorials.
- Test only in safe, authorized environments. Use an approved lab, simulator, virtual machine, or isolated dataset, and follow institutional rules.
- Document evidence and cite sources. Record assumptions, versions, observations, limitations, and the sources that support each important claim.
Related guides: IT Standards and Frameworks • Research Skills • Peer-Reviewed Scholarly Articles
Start Here: Core Cybersecurity Research
Separate discovery tools from direct scholarly sources. Search tools help you find candidates; they do not make every result peer reviewed. Open and read the individual record, confirm the publication type, and follow the original source before citing it.
Discovery tools
- Google Scholar – Broad discovery across articles, books, theses, and conference papers; evaluate each result.
- BASE – Discovery of scholarly and repository records; verify the original publication and source type.
- CORE – Discovery of open-access research outputs and repository copies.
- OpenAlex – Open scholarly metadata for tracing works, authors, topics, and related literature.
Peer-Reviewed Journals & Scholarly Sources
Use these as academic starting points, then evaluate the individual article for relevance, method, currency, and credibility. A directory or search service helps with discovery; it is not itself a journal.
- IEEE Access – Open peer-reviewed research in computing, engineering, and technology.
- Directory of Open Access Journals (DOAJ) – A directory for finding open-access journals and article records; verify the journal and article.
- SpringerOpen – Open-access journals and books; check the publication type and peer-review information for the item used.
- Peer-Reviewed Scholarly Articles Library Guide – VTI guidance for finding, evaluating, and citing peer-reviewed journal literature.
Standards, Frameworks & Authoritative Guidance
Use the source that matches the assignment. Frameworks organize outcomes and risk; standards describe agreed requirements or protocols; technical guidance explains implementation; threat models support analysis.
- NIST Computer Security Resource Center (CSRC) and NIST Cybersecurity Framework (CSF 2.0): use for risk-management language, controls, governance, and standards-based recommendations.
- International Organization for Standardization (ISO): use when discussing formal management-system standards, control objectives, or certification context; verify the specific standard required by the assignment.
- IETF Standards: use for Internet protocols, technical specifications, and standards-based network explanations.
- ITU Standards: use for telecommunications, network, and information-and-communication technology standards and context.
- OWASP: use for application-security risks, secure-development guidance, and defensive web-security explanations.
- MITRE ATT&CK: use as a common language for describing adversary tactics and techniques in threat analysis, detection, and incident-response exercises.
Threat Intelligence, Tools & Applied Learning
Use applied resources to understand defensive operations and collect evidence in an approved lab. Tools and training materials are useful for practice, but they are not substitutes for peer-reviewed evidence when making academic claims.
- CISA Cybersecurity Resources – Government advisories, alerts, and defensive guidance for current risks.
- SANS Reading Room – Practitioner-oriented papers and training context; assess the source type and use scholarly literature for academic claims.
- Kali Linux Documentation – Documentation for an authorized security-learning environment and defensive lab preparation.
- HackerOne Hacker101 – Introductory security learning for authorized, non-destructive practice.
- Snort and Suricata – Defensive intrusion-detection concepts and documentation for lab analysis.
- Wireshark Documentation – Packet-capture and analysis guidance; capture only traffic you are authorized to examine and protect sensitive data.
Best Starting Point by Topic
- Governance, risk & compliance: begin with NIST CSRC and CSF, then use ISO for management-system and control context and CISA for current government guidance.
- Network security: use IETF and ITU for protocol and standards context, NIST for risk, Wireshark for authorized evidence, and MITRE ATT&CK for defensive technique language.
- Application security: start with OWASP for risks and secure-development guidance, then use NIST or MITRE ATT&CK to frame controls, detection, or threat behaviour.
- Incident response & threat intelligence: use CISA for advisories, MITRE ATT&CK for tactics and techniques, NIST for response and risk context, and SANS for practitioner examples.
- Secure systems and hardening: start with NIST and CISA guidance, use official platform documentation for implementation, and use Kali only in an authorized defensive lab.
- Academic research and literature review: discover through Google Scholar, BASE, CORE, or OpenAlex, then prioritize relevant peer-reviewed work in IEEE Access, SpringerOpen, or journals identified through DOAJ.
Cybersecurity Research Workflow
Question/Scenario -> Standards/Frameworks -> Scholarly Research -> Technical Evidence -> Analysis -> Recommendation -> References
Use the standards or framework to define the terms and expected outcomes, scholarly research to support academic claims, and technical evidence to show what happened in the scenario. Keep recommendations proportional to the evidence and state limitations.
Source Quality: What to Use for What
- Standards and frameworks: use NIST, ISO, IETF, ITU, OWASP, or MITRE ATT&CK for authoritative requirements, terminology, control context, protocols, and threat-analysis structure. These are appropriate for standards-based recommendations, but cite the specific document and version.
- Peer-reviewed research: use journal articles and scholarly books for academic claims, literature reviews, methods, and evidence about research findings. Evaluate the actual publication, not only a search result.
- Government and agency advisories: use CISA and similar official guidance for current risks, alerts, public-sector recommendations, and incident context. Distinguish an advisory from peer-reviewed research.
- Vendor and tool documentation: use official product or tool documentation for supported configuration, commands, versions, limitations, and implementation details.
- Training and lab material: use SANS, Hacker101, Kali documentation, Snort, Suricata, and Wireshark resources for practice and applied understanding. Do not treat a lab or tutorial as sufficient evidence for an academic claim.
Ethical & Legal Use
Use cybersecurity knowledge only on systems, accounts, networks, and data for which you have explicit permission. Follow VTI and institutional policies, keep lab work isolated and non-destructive, protect credentials and personal information, and use responsible-disclosure channels when a legitimate issue is found. Do not turn a classroom exercise into testing of a live third-party system.
Regional Context: Jamaica & Caribbean
Regional sources can help you connect cybersecurity theory to local policy, infrastructure, workforce, and risk questions. They are useful for context and primary records, but should be combined with authoritative standards and suitable scholarly research.
- Government of Jamaica Open Data Portal – Public datasets and government context that may support analysis of services, infrastructure, policy, or digital-development issues.
- UWISpace – University repository material that can provide Caribbean research, theses, and regional perspectives; verify the publication type and review status.
- Digital Library of the Caribbean (dLOC) – Regional and historical collections useful for understanding Caribbean institutions, policy, infrastructure, and social context.
Best Starting Point by Assignment Type
- Literature review: define the question, discover through Google Scholar, BASE, CORE, or OpenAlex, then evaluate and cite the most relevant peer-reviewed studies.
- Standards comparison: identify the scope and version, compare NIST, ISO, IETF, ITU, OWASP, or MITRE ATT&CK documents, and state where their purposes differ.
- Risk assessment: define assets and risks, use NIST CSF or ISO for structure, consult CISA for current context, and state assumptions and evidence.
- Incident-response case study: frame the scenario with CISA, NIST, and MITRE ATT&CK, separate observed facts from inferences, and make recommendations supported by evidence.
- Network-security lab or report: use IETF or ITU for protocol context, Wireshark or an approved IDS lab for evidence, and document the environment, captures, findings, and limitations.
- Capstone or research project: combine a clear question, standards and scholarly literature, authorized technical evidence, a reproducible method, and a properly cited recommendation.
Recommended Companion Guides
- IT Standards and Frameworks
- Research Skills
- Technology Management
- Software Engineering
- Peer-Reviewed Scholarly Articles Library Guide
Use peer-reviewed research for academic claims, standards and government sources for authoritative requirements and guidance, and official technical documentation for implementation details. Ask the VTI Library for help when you need to locate, evaluate, or cite a source.