Agricultural Extension  ·  Level 5
Digital Literacy
Chapter 5: Apply Cybersecurity Skills
📚 5 Topics
What you will be able to do

By the end of this chapter, you will be able to:

  • correctly classify data protection and privacy following workplace policies and legal requirements
  • accurately identify internet security threats based on workplace rules and regulations
  • detect computer threats and cybercrimes by using information management security guidelines
  • properly apply cybersecurity control measures to keep systems safe and secure

Mastering these skills helps you protect important information and keep digital systems safe, which is essential for any modern workplace.

Digital literacy in professional settings requires a strong foundation in cybersecurity skills to safeguard sensitive information and maintain trust across all sectors. Whether managing patient records in a county referral hospital or handling financial data in a SACCO, understanding how to protect data is crucial. This chapter focuses on key principles of data protection and privacy: confidentiality, integrity, and availability, which collectively ensure that information remains secure, accurate, and accessible when needed.

5.1 Data protection and privacy

Data protection and privacy are fundamental to upholding legal, ethical, and operational standards in Kenyan workplaces. Organizations such as county governments, universities, and retail businesses collect and process vast amounts of personal and organizational data daily. Protecting this data from unauthorized access, alteration, or loss is essential to maintain compliance with laws like the Data Protection Act 2019 and to secure the confidence of clients, employees, and stakeholders.

5.1.1 Confidentiality of data/information

Confidentiality refers to the principle that information is accessible only to those authorized to have access. In the Kenyan context, confidentiality ensures that sensitive data such as patient health records at a county hospital or payroll details at a university remain private and protected from unauthorized disclosure. Upholding confidentiality prevents identity theft, financial fraud, and breaches of trust that can lead to legal penalties and reputational damage.

Meaning of Confidentiality

Confidentiality means restricting access to information to specific individuals or groups who have a legitimate need to know. This involves implementing controls such as passwords, encryption, and secure user authentication to prevent data exposure. For example, at a retail business, customer payment information should only be accessible to authorized finance staff to avoid misuse.

Importance of Confidentiality in the Workplace

  • Protects personal privacy rights of employees and clients by preventing unauthorized data sharing.
  • Maintains competitive advantage by safeguarding proprietary business information from competitors.
  • Ensures compliance with Kenyan data protection regulations, avoiding fines and legal action.
  • Builds trust between the organization and its stakeholders through responsible data handling.
  • Prevents financial losses resulting from data breaches and cyberattacks.

Methods to Maintain Confidentiality

  • Use strong, unique passwords and change them regularly to limit unauthorized access.
  • Apply data encryption for sensitive information, especially during transmission over networks.
  • Restrict physical access to servers and workstations where confidential data is stored.
  • Conduct regular staff training on data privacy policies and the consequences of breaches.
  • Implement role-based access control to ensure employees only access information necessary for their duties.

Challenges to Maintaining Confidentiality and How to Address Them

Challenges
  • Insider threats due to negligent or malicious employees.
  • Phishing attacks that deceive users into revealing credentials.
  • Inadequate security policies or failure to enforce them.
  • Use of unsecured devices or networks for accessing sensitive data.
  • Lack of awareness or training among staff about confidentiality protocols.
How to Address Challenges
  • Establish clear policies with defined penalties for breaches of confidentiality.
  • Conduct frequent cybersecurity awareness campaigns and phishing simulations.
  • Employ multi-factor authentication to strengthen access controls.
  • Regularly audit systems and access logs to detect unusual activities.
  • Ensure all devices accessing sensitive data have updated security software.

5.1.2 Integrity of data/information

Data integrity refers to the accuracy, consistency, and reliability of data throughout its lifecycle. For instance, in a SACCO, the integrity of members’ financial records must be maintained to ensure correct loan balances and interest calculations. Any unauthorized alteration, whether accidental or malicious, can lead to wrong decisions, financial losses, or legal disputes.

Meaning of Data Integrity

Data integrity means that information is complete, accurate, and unaltered from its original state unless changes are authorized and documented. It encompasses protection against accidental corruption, intentional tampering, and unauthorized modification. For example, at a county government office, maintaining the integrity of land records is vital to prevent fraudulent property transactions.

Significance of Data Integrity in the Workplace

  • Ensures decision-making is based on trustworthy and accurate data.
  • Protects organizational reputation by avoiding errors and misinformation.
  • Supports compliance with statutory requirements such as financial reporting standards.
  • Enables smooth operational processes by preventing discrepancies.
  • Reduces risks of fraud and unauthorized manipulation of critical data.

How to Demonstrate Data Integrity in Daily Work

  • Implement version control systems to track changes made to documents.
  • Use checksums and hash functions to verify data has not been altered.
  • Maintain audit trails for all data modifications to ensure accountability.
  • Apply access restrictions to prevent unauthorized editing.
  • Regularly back up data to enable recovery of original information if compromised.

Consequences of Lacking Data Integrity

  • Financial losses due to incorrect billing or accounting errors.
  • Legal penalties arising from inaccurate reporting or breach of compliance.
  • Loss of client trust when errors affect service delivery.
  • Operational disruptions caused by faulty or inconsistent data.
  • Increased vulnerability to cyber fraud and sabotage.

5.1.3 Availability of data/information

Availability ensures that authorized users can access data and information when needed without undue delay. For example, at a university, lecturers and students must have reliable access to the learning management system to support teaching and learning activities. Lack of availability can halt operations, cause missed deadlines, and degrade service quality.

Meaning of Data Availability

Data availability means that information systems and data are accessible and usable upon demand by authorized personnel. It involves minimizing downtime and ensuring systems are resilient against failures, attacks, or disasters. For instance, a county hospital must maintain availability of patient records to provide timely care.

Importance of Data Availability in Professional Settings

  • Supports continuity of critical business functions and services.
  • Enables timely decision-making based on current information.
  • Enhances customer satisfaction by preventing service interruptions.
  • Reduces operational risks related to system outages or data loss.
  • Complies with service level agreements and regulatory requirements.

Strategies to Ensure Data Availability

  • Implement redundant hardware and data storage solutions such as RAID arrays.
  • Use uninterruptible power supplies (UPS) and backup generators to prevent outages.
  • Perform regular data backups and test restoration procedures.
  • Deploy network monitoring tools to detect and resolve issues proactively.
  • Employ disaster recovery and business continuity plans.

Risks to Data Availability and Mitigation Measures

  • Hardware failures causing system crashes; mitigated by redundancy and maintenance.
  • Cyberattacks such as Distributed Denial of Service (DDoS); mitigated by firewalls and traffic filtering.
  • Natural disasters like floods or fires; mitigated by offsite backups and recovery sites.
  • Software bugs or errors; mitigated by regular updates and patch management.
  • Human errors such as accidental deletion; mitigated by user training and access controls.

Practice Questions

  1. Explain five methods that organizations can use to maintain the confidentiality of sensitive data and provide examples relevant to Kenyan workplaces. (10 marks)
  2. Discuss the importance of data integrity in financial institutions and describe four ways to ensure data integrity. (10 marks)
  3. Identify six strategies to ensure the availability of data in a healthcare facility and explain the significance of each. (12 marks)
The rest of this chapter
🔒

Create a free account to open more of this chapter.

Free: practical guides, quick cards, workplace scenarios and more.

Create a free account
🔒5.2 Internet Security Threats

In Kenya’s diverse professional environments, from county hospitals to retail businesses, internet security threats pose significant risks to data confidentiality, system availability, and operational continuity. As organizations increasingly rely on digital p…

🔒5.3 Computer Threats and Crimes

In Kenya’s digital environment, professionals across all sectors face a variety of computer threats and crimes that can compromise personal data, business operations, and national security. County referral hospitals, universities, banks, and retail businesses…

🔒5.4 Cybersecurity Control Measures

Cybersecurity controls are essential safeguards that protect digital assets from threats and crimes. Kenyan organizations across sectors implement physical, technical, and operational controls to secure their systems, data, and users. These controls work toget…

🔒5.5 Laws governing protection of ICT in Kenya

Kenya’s digital transformation has necessitated robust legal frameworks to safeguard information and communication technologies (ICT) from misuse and cyber threats. These laws establish the boundaries for lawful digital conduct, protect data privacy, and enhan…

Chapter Summary

This chapter explored essential cybersecurity skills focusing on safeguarding data through the principles of confidentiality, integrity, and availability. It examined various internet security threats such as malware, social engineering, distributed denial of service, man-in-the-middle, password attacks, IoT vulnerabilities, phishing, and ransomware, highlighting their impact on digital systems. The discussion then extended to computer threats and crimes, emphasizing the risks posed by malicious activities in cyberspace. Effective cybersecurity control measures were outlined, including physical safeguards, technical solutions like passwords and biometrics, and operational protocols that organizations must implement. The chapter concluded with an overview of Kenyan legislation governing ICT protection, specifically the Computer Misuse and Cybercrimes Act No. 5 of 2018 and the Data Protection Act No. 24 of 2019, which provide the legal framework for combating cybercrimes and protecting personal data. Together, these topics equip learners with a comprehensive understanding of how to defend digital information and comply with relevant laws.

Self-Assessment

🔒 PDFDownload this self-assessment, with answers

A. Written Assessment

  1. What does the confidentiality of data mean in the context of a county referral hospital’s patient records? (2 marks)
  2. Explain how data integrity can be compromised in a retail business’s inventory management system. (3 marks)
🔒20 more in this section.

Chapter Examination Questions

🔒 PDFDownload these examination questions, with model answers

SECTION A (40 Marks) - Answer ALL Questions

  1. Explain the principle of confidentiality in data protection and give an example relevant to a county referral hospital. (4 marks)
  2. Describe two ways in which data integrity can be compromised in a retail business setting. (4 marks)
🔒18 more in this section.

Chapter Practical Activities

Practical 1: Implement data protection and privacy settings on a Windows 10 computer

Agricultural Extension · Level 5
Digital Literacy
PRACTICAL ASSESSMENT
TIME: 4 HOURS
⬇ PDFCandidate Instructions (Candidate Tool)

Type: Individual

INSTRUCTIONS TO CANDIDATE:
1.  You are required to perform the following task:
i.  Configure data protection and privacy settings on a Windows 10 computer system to secure sensitive information as per the provided security policy document.
2.  You have been provided with the following resources for the practical task:
Tools & EquipmentMaterials
Windows 10 Pro computer systemAntivirus software (pre-installed)
External USB flash drive 16 GBPrivacy and security settings documentation
Internet connection
⬇ PDFResources Required (Cutting List)
S/NItemQuantity
1Windows 10 Pro computer system1 Pc per Candidate
2External USB flash drive 16 GB1 Pc per Candidate
3Internet connectionShared per Candidate
4Antivirus software (pre-installed)1 License per Candidate
5Privacy and security settings documentation1 Copy per Candidate
⬇ PDFAssessor Guide
Items to be EvaluatedMarks AvailableMarks ObtainedComments
TASK 1: Safety and preparation
Wore prescribed PPE (e.g., anti-static wrist strap if required)
(Award 1 mark if PPE worn correctly, 0 if not)
1
Checked system for existing malware using antivirus software
(Award 1 mark for starting scan, 1 mark for no interruptions)
2
Backed up existing data to external USB flash drive
(Award 1 mark for successful backup initiation, 1 mark for completion)
2
Sub-Total5
TASK 2: Configure privacy settings
Enabled Windows Defender Firewall with recommended settings
(Award 1 mark for enabling firewall, 1 mark for correct profile selection)
2
Set up user account with strong password and enabled account lockout policies
(Award 1 mark for password complexity, 1 mark for account lockout, 1 mark for password expiration settings)
3
Configured privacy settings to limit app access to location, camera, and microphone
(Award 1 mark each for location, camera, microphone privacy settings)
3
Disabled telemetry and data sharing with Microsoft
(Award 1 mark for disabling telemetry, 1 mark for disabling tailored ads)
2
Sub-Total10
TASK 3: Implement data protection techniques
Enabled BitLocker encryption on system drive
(Award 1 mark for starting encryption, 1 mark for choosing correct encryption method, 1 mark for saving recovery key)
3
Configured Windows Update settings for automatic security updates
(Award 1 mark for enabling updates, 1 mark for setting active hours)
2
Set up Windows Defender Antivirus real-time protection and scheduled scans
(Award 1 mark for enabling real-time protection, 1 mark for scheduling scan, 1 mark for updating virus definitions)
3
Sub-Total8
TASK 4: Housekeeping and documentation
Cleared temporary files and browser history to protect privacy
(Award 1 mark for clearing temporary files, 1 mark for clearing browser history)
2
Saved and documented all configuration changes made
(Award 1 mark for saving configuration, 1 mark for clear documentation)
2
Logged out and shut down the system properly
(Award 1 mark for proper logout and shutdown)
1
Sub-Total5
PRODUCT CHECKLIST
System encrypted with BitLocker and recovery key saved
(Award 3 marks if encryption is active and recovery key retrievable)
3
User account password policy correctly configured
(Award 2 marks if password complexity, expiration, and lockout policies are set)
2
Privacy settings correctly restrict app access to location, camera, and microphone
(Award 1 mark each for location, camera, microphone settings correctly applied)
3
Firewall enabled with correct profile and active
(Award 2 marks if firewall is enabled and active on appropriate network profiles)
2
Windows Defender Antivirus real-time protection and scheduled scans active
(Award 2 marks if real-time protection and scheduled scans are enabled and updated)
2
System settings and changes documented clearly and completely
(Award 3 marks for complete and clear documentation of all changes made)
3
Sub-Total15
GRAND TOTAL43
ASSESSMENT OUTCOME:   ☐ Competent    ☐ Not Yet Competent (competent if at least 50%)

Practical 2: Perform data backup and restore to verify data integrity and availability

Agricultural Extension · Level 5
Digital Literacy
PRACTICAL ASSESSMENT
TIME: 4 HOURS
⬇ PDFCandidate Instructions (Candidate Tool)

Type: Individual

INSTRUCTIONS TO CANDIDATE:
1.  You are required to perform the following task:
i.  Perform a full backup of a 500MB data folder to an external 1TB USB hard drive and restore the data verifying file integrity and availability.
2.  You have been provided with the following resources for the practical task:
Tools & EquipmentMaterials
Laptop or Desktop Computer with Windows 10 OSSample Data Folder (100 files, 500MB)
External USB Hard Drive 1TB
USB Flash Drive 16GB
Backup Software (Windows Backup and Restore)
Network Connection
Antivirus Software Installed
Power Backup (UPS)
⬇ PDFResources Required (Cutting List)
S/NItemQuantity
1External USB Hard Drive 1TB1 Pc per Candidate
2Laptop or Desktop Computer with Windows 10 OS1 Pc per Candidate
3Backup Software (e.g. Windows Backup and Restore)1 License per Candidate
4Sample Data Folder (containing 100 files, total size approx. 500MB)1 Set per Candidate
5Network Connection (for cloud backup simulation)1 Connection per Candidate
6Antivirus Software Installed1 License per Candidate
7USB Flash Drive 16GB1 Pc per Candidate
8Power Backup (UPS)1 Pc per Candidate
⬇ PDFAssessor Guide
Items to be EvaluatedMarks AvailableMarks ObtainedComments
TASK 1: Prepare and set up backup environment
Wore prescribed PPE (e.g. anti-static wrist strap if applicable)
(Award 1 or 0 mark)
1
Checked power backup (UPS) is connected and functional
(Award 1 or 0 mark)
1
Verified antivirus software is active and updated
(Award 1 or 0 mark)
1
Connected external USB hard drive properly
(Award 1 or 0 mark)
1
Ensured network connection is active for cloud backup simulation
(Award 1 or 0 mark)
1
Sub-Total5
TASK 2: Perform full backup
Selected correct source folder (500MB sample data folder)
(Award 1 or 0 mark)
1
Configured backup software for full backup to external USB hard drive
(Award 2 or 0 marks)
2
Started backup process and monitored progress
(Award 1 or 0 mark)
1
Confirmed backup completed successfully without errors
(Award 2 or 0 marks)
2
Sub-Total6
TASK 3: Simulate data loss and restore backup
Deleted original data folder to simulate data loss
(Award 1 or 0 mark)
1
Configured restore settings to recover data from external USB hard drive
(Award 2 or 0 marks)
2
Executed restore operation
(Award 1 or 0 mark)
1
Monitored restore progress and confirmed completion
(Award 1 or 0 mark)
1
Sub-Total5
TASK 4: Verify data integrity and availability
Checked that all 100 files are restored
(Award 2 or 0 marks)
2
Opened multiple file types to verify data integrity
(Award 2 or 0 marks)
2
Performed checksum/hash verification on restored files
(Award 2 or 0 marks)
2
Sub-Total6
TASK 5: Perform housekeeping and shutdown
Safely ejected external USB hard drive
(Award 1 or 0 mark)
1
Closed backup software and shut down computer properly
(Award 1 or 0 mark)
1
Cleaned workstation and organized tools and materials
(Award 1 or 0 mark)
1
Sub-Total3
PRODUCT CHECKLIST
Backup completed successfully with all files copied (500MB folder size verified)
(Award 3 or 0 marks)
3
Restored data matches original file count and structure (100 files intact)
(Award 3 or 0 marks)
3
Data integrity verified by opening files and checksum comparison
(Award 4 or 0 marks)
4
Data availability confirmed by successful access from restored location
(Award 3 or 0 marks)
3
Sub-Total13
GRAND TOTAL38
ASSESSMENT OUTCOME:   ☐ Competent    ☐ Not Yet Competent (competent if at least 50%)
🔒

Free: practical guides, quick cards, workplace scenarios and more.

Create a free account
🔒Identify and Mitigate Common Internet Security ThreatsPractical 3
🔒Detect and Remove Malware and Ransomware from a Windows SystemPractical 4
🔒Simulate Social Engineering Attack PreventionPractical 5
🔒Analyze and Respond to Distributed Denial of Service (DDoS) AttacksPractical 6
🔒Detection and Prevention of Man-in-the-Middle Attacks in a Test NetworkPractical 7
🔒Implement strong password policies and demonstrate password managementPractical 8
🔒Secure Internet of Things (IoT) Device Configuration and Firmware UpdatePractical 9
🔒Installation and Demonstration of Physical Security Controls for ICT EquipmentPractical 10
🔒Implement Operational Cybersecurity Controls for a Small Office NetworkPractical 11
🔒Configure and test biometric authentication on a laptop computerPractical 12
🔒Demonstrate compliance with Kenyan ICT laws in a simulated workplace scenarioPractical 13
🔒Configure Firewall and Antivirus Software to Secure a Computer SystemPractical 14
🔒Setup and Verification of Multi-Factor Authentication on a User AccountPractical 15
Flashcards 20 cards Study deck ▾
Question
1

↻ Tap card to reveal answer
🔒

18 more in this section.

Create a free account
Test Yourself 19 questions Start quiz ▾
0%
0 / 2
🔒

17 more in this section.

Create a free account
Am I competent?

At the start of this chapter we promised you would be able to:

  • correctly classify data protection and privacy following workplace policies and legal requirements
  • accurately identify internet security threats based on workplace rules and regulations
  • detect computer threats and cybercrimes by using information management security guidelines
  • properly apply cybersecurity control measures to keep systems safe and secure

Tick each one you can genuinely do.

Prove it — in the simulator

Sample simulation — try how the simulator works. A version built for this chapter's practical is coming.

Prepare Kenyan PilauLocked ▸

Free: practical guides, quick cards, workplace scenarios and more.

Now — are you there yet?

You're competent when you can confidently do 50% or more of what this chapter promised.

Sign in to record how you're doing.