Teaching information security recommendations in Grades 9-10 (Level 1) unit cover (OAS L1.NI.CY.02)

Teaching Recommend the Right Security Measure in Grades 9-10 (Level 1): Oklahoma Standard L1.NI.CY.02

Teaching Recommend the Right Security Measure in Grades 9-10 (Level 1): Oklahoma Standard L1.NI.CY.02

Teaching information security recommendations in grades 9-10 (level 1) does not have to be complicated. Picture an information security consultant recommending encryption and access controls for a clinic's patient database. That kind of thinking is exactly what Oklahoma's grades 9-10 (level 1) computer science standard L1.NI.CY.02 asks students to practice — and it is very teachable with the right materials. This post walks through what the standard means, the misconceptions students bring to it, and discussion starters you can use tomorrow, whether you teach in a classroom or at your kitchen table.

What Does Standard L1.NI.CY.02 Actually Ask?

Recommend security measures to address various scenarios based on information security principles. — Oklahoma Academic Standards for Computer Science (February 2023)

In plain language: This standard asks Level 1 students (grades 9-10) to look at different real-world scenarios and recommend specific security measures that fit each one, based on three core information security principles: keeping data private, keeping data accurate, and keeping data accessible when needed.

In student-friendly terms, the learning target is: "I can recommend security measures to address various scenarios based on the information security principles of confidentiality, integrity, and availability."

What Students Should Be Able to Do

  • I can explain confidentiality, integrity, and availability and identify which one is most at risk in a given scenario.
  • I can recommend a specific security measure that directly addresses an identified risk.
  • I can justify why a recommendation fits a scenario rather than proposing generic security advice.
  • I can explain the role of policy, audits, and response plans in putting recommendations into practice.

Along the way, students pick up the working vocabulary of the topic: confidentiality, integrity, availability, recommendation, scenario, accesscontrol, backup, audit, compliance, incident, policy, redundancy.

Information Security Recommendations: Misconceptions to Watch For

These are the wrong turns students reliably take with this standard — knowing them ahead of time is half the lesson plan. Each correction strategy below comes straight from the unit's teacher guide (the paragraph and activity references point into the unit itself).

1. "A good security recommendation always suggests the strongest, most extreme measure available."

Return to paragraph 6. A strong recommendation matches the measure to the scenario's actual risk level, rather than applying maximum protection everywhere regardless of fit.

2. "Confidentiality is the only information security principle that matters."

Point back to paragraphs 3-4. Integrity and availability failures can cause just as much real harm as confidentiality breaches, even though they are discussed less often.

3. "A written security policy is unnecessary if a good recommendation has already been made."

Emphasize paragraph 7. A one-time recommendation without a documented policy and regular audits can be forgotten or inconsistently applied over time.

4. "Strong preventive security measures mean an organization will never experience a security incident."

Revisit paragraph 8. No recommendation eliminates every incident; response planning is a necessary part of a complete security recommendation.

Discussion Starters You Can Use Tomorrow

  • Think of an organization you interact with regularly (a school, a store, a streaming service). Which information security principle do you think matters most for their data, and why?
  • Why might a company prioritize availability over confidentiality for one system, but prioritize confidentiality over availability for a different system?
  • Describe a scenario where ignoring the integrity principle, even without any data being stolen, could still cause serious harm.

Bringing It Home

This topic is a natural one for families. One ten-minute activity to try: Together, pick an account or device your family uses that holds information you would want protected (a bank account, a family photo cloud storage, a medical portal). Talk through which of the three principles — keeping it private, keeping it accurate, or keeping it accessible — matters most for that specific account, and discuss one security step your family could take to address it.

Where This Leads

Students who can recommend security measures to address various scenarios based on the information security principles of confidentiality, integrity, and availability are building skills used every day in information security consulting, IT management, risk and compliance analysis, and security awareness training.

See the Unit in Action

Get the Complete L1.NI.CY.02 Unit

I built a complete, no-prep unit for this standard — Recommending Security Measures: Matching Solutions to Real Scenarios — covering 3-4 days of instruction across 42 pages:

  • Teacher guide — day-by-day pacing, misconceptions to watch for, discussion questions, differentiation for support / ELL / extension, and a 4-point rubric
  • Student learning target page — a kid-friendly "I can" statement with success criteria
  • Full content lesson with 3 embedded "Check Your Understanding" checkpoints
  • 12-question assessment (6 multiple choice, 4 true/false, 2 short answer) with a complete answer key, explanations, and exemplar responses
  • Group activity — "Security Consultant: Recommend a Solution" (25-30 minutes)
  • Individual activity — "My Security Recommendation Report" (20 minutes)
  • Crossword and word search built from all 12 vocabulary terms (with answer keys)
  • Family connection letter — a plain-language page for parents, with dinner-table questions and a 10-minute home activity
  • Certificate of achievement — ready to sign and send home
  • Client Scenario Card Set: Security Consultant (separate printable, 2 pages)
  • Reference Sheet: The CIA Triad and Recommendations (separate printable, 1 page)
  • My Security Recommendation Report (separate printable, 2 pages)

Get Recommend the Right Security Measure on Teachers Pay Teachers →

Also aligned to CSTA 3B-NI-04: Explain tradeoffs when selecting and implementing cybersecurity recommendations.

Every Sooner Standards resource is built directly from the official Oklahoma Academic Standards for Computer Science (February 2023) — standard text verified, never paraphrased from memory.

Similar Posts

Leave a Reply