My name is Duane Dunston and I will be maintaining the SIA curriculum. This curriculum will be the foundation of my course's taught at Pfeiffer University, so it will be updated often. This course teaches real world security principles and provides hands-on exercises for you to become actively engaged in the learning process. This course is not watered down and you'll get a lot out of it, if you actively participate and read through the material and the Recommended Readings throughout the course.

LearnSIA is not apart of or affiliated with Carnegie Mellon, we've been granted permission to create a derivative of their SIA courses, which they've discontinued. You will need to contact them if you wish to make further derivatives of this curriculum.

SIA Curriculum Foundations

Today's organizations rely on networked systems powered by fast-changing technology. This reliance makes them more vulnerable to attacks and forces system administrators to seek new approaches to computer and network security. To help them, the CERT developed a downloadable three-course curriculum in survivability and information assurance (SIA). This curriculum offers a problem-solving methodology built on key SIA principles that are independent of specific technologies. These principles form the foundation of CERT's SIA Curriculum. A summary of the curriculum is provided below.

We based the SIA Curriculum on five key foundations. Each is detailed in Foundations of the SIA Curriculum:

  1. Principles of Survivability and Information Assurance: Making decisions through an organized thought process
  2. The Enterprise Network Supports the Mission of the Business: Understanding how technology choices and applications impact the mission of the business
  3. Survivable Functional Units: Reducing the complexity of the enterprise to a manageable size
  4. Inherit an Enterprise Network: Integrating seamlessly new functionality in the network while keeping mission and constraints of the business in focus
  5. Challenge Assumptions: Understanding first the assumptions, challenging them, and then making an informed decision
These foundations inform the courseware in the SIA Curriculum. Understanding them is the key to successfully teaching and implementing it.

SIA Curriculum Overview

The SIA Curriculum Overview explains the key features of the SIA curriculum: its audience, structure, the technology used, and the characteristics students and teachers should possess to be able to get the most out of the curriculum.

The curriculum consists of the following major topic areas, each of which corresponds to one course:

  1. Principles of Survivability and Information Assurance: This course presents in detail the ten principles of survivability and information assurance, on which the entire SIA curriculum is based.
  2. Information Assurance Networking Fundamentals: This course applies the ten principles to the concepts and an implementation of TCP/IP networking.
  3. Sustaining, Improving, and Building Survivable Functional Units (SFUs)

SIA Lab Overview

In addition to the three core courses, the SIA curriculum offers a companion lab that prepares students for the tasks they will undertake in each course. The SIA Lab Overview provides information about the hardware and the software required for the lab in general and for each specific course. Other topics include configuration management, user identity and privileges, and Internet connectivity.

Curriculum Development

The course material is being converted from word documents to Docbook. This allows editing one document that can then be converted for students and instructors. The primary workbook (reading material) is created for students. Marked sections are then created for the instructor comments. With a single command line switch, the instructor workbook can be easily created. Additionally, as I use this course for other projects, I can use Docbook's Marked Sections to create special notes and references for other places where the SIA curriculum will be taught. Accordingly, I edit one document and convert it for many uses.

After the Docbook is completed, an HTML file is generated for students and then for faculty. That HTML file is opened in MS Word or OpenOffice, depending on where I'm creating the material, and converted to OpenDocument format and then to PDF (docbook2pdf seems to have issues converting the images, that I need to look further into). The program docbook2scorm is used to create the SCORM package. However, I've been looking at using MyUdutu to create the SCORM packages because it is more feature-rich and has a nice web interface for creating the course and exams. I'm also interested in their Facebook integration for elearning in social networks. If there is not interest in that, then I can spend time working on other tasks.

The development course code is being hosted on github where all updates will be made and is the official source for the LearnSIA course material. Please understand that the Docbook files may not compile cleanly if you download it from this location since this is where the development of the course is maintained. However, I will always try to keep a clean compliled version out for those that want to see things in progress. I'll also try to have an html conversion of the Docbook file.

Labs are created using Wink or Camstudio. It depends on whether voice or audio is better for the lesson plan.

Downloading the Curriculum

This course curriculum will continue to be developed and updated. However, you can download the latest stable curriculum documents here.


If you are interested in helping this project, please contact me at This project will need proofreaders (text and tutorial material), assistance with document conversion (to SCORM packages and maybe other formats). Also, anyone interested in helping to develop an introductory Windows System administration course.


Rachel Oliver

Rachel is a freelance technical writer and published author who has provided valuable technical writing services to companies in the Washington, D.C. area. Among her many projects, she has conducted technical writing analysis for IT Security Certification & Accreditation Efforts, written Risk Analysis templates, constructed NIST Compliant documentation along with numerous other professional documents. In addition, she has been nationally recognized for her poetry writing abilities. Her poems have been chosen to be showcased by the National Library of Poetry in multiple volumes, and her poem "For Our Veterans" has been read aloud at Memorial Day ceremonies nationwide.