D827 Fundamentals of Information Security is recorded under banner number ITAS 2111 and is worth 3 competency units. It covers information security terminology, principles, processes and best practices, along with basic vulnerabilities and the countermeasures that address them. D827 is the version carried in the B.S. Cybersecurity and Information Assurance plan. D430 shares the title under banner ITAS 2110 and covers the same material for other plans, so complete whichever code your Degree Plan lists.
Principles first, because everything later is built on them
D827 is the vocabulary and principle course for a cybersecurity major, and the temptation is to skim it because the ideas look simple. That skim is expensive. Confidentiality, integrity and availability are not three words to memorise; they are three different failure modes that pull against each other, and almost every design decision later in the degree is a choice about which one to favour. Encryption protects confidentiality and can hinder availability when keys are lost. Aggressive backup protects availability and multiplies the places confidential data lives.
The access control material is the second foundation. Identification, authentication, authorisation and accountability are four distinct steps and students routinely collapse them. Claiming to be someone is identification. Proving it is authentication. Being permitted to do a thing is authorisation. Being traceable afterwards is accountability. Aspects in later courses test that separation constantly, and getting it exact here saves rework in every security course that follows.
Risk is the third pillar and the one that turns security from a preference into a decision. Risk combines the likelihood of something happening with what it would cost. That framing is why perfect security is not a goal: controls cost money and friction, and spending more on a control than the risk is worth is itself a bad decision. A submission that ranks risks and accepts some deliberately is showing the reasoning the course exists to build.
Countermeasures then attach to specific vulnerabilities rather than floating free. Learning vulnerabilities and countermeasures as pairs halves the memory burden and produces answers that survive applied questions, which the definitions alone do not.
Outcomes are logged as Competent or Not Competent, because letter grades and an ordinary grade point average do not exist here, leaving 3 competency units as the only size figure attached to a flat-rate six month term. Closing a foundations course early is worth more than its weight, because the courses it feeds are heavier.
Building a section plan from scored aspects
If your version of D827 uses a performance assessment, the aspects usually ask you to apply principles to a described organization rather than to define them. WGU requires a score of 2 in each aspect for a task to pass and judges each aspect alone, so a thorough definitions section will not carry an unaddressed countermeasure aspect.
Convert to a budget. Take a rubric with five scored aspects and a target near 1,500 words. Reserve 120 words to describe the organization and its information assets, and 90 for the close, leaving 1,290 across five aspects, or 258 each. Weight by demand: two aspects that ask you to assess risk and recommend countermeasures need 360 each, since both require a claim, a justification and a residual position. The three remaining aspects, covering principles, vulnerabilities or processes, take 190 each. Two at 360 plus three at 190 is 1,290 exactly.
Inside every countermeasure paragraph, use a fixed order: the vulnerability, the control, what it reduces, and what it leaves. That fourth element is the one that separates a foundations answer that reads as informed from one that reads as recited, and it costs a single sentence each time.
Where an aspect mentions best practice, resist the urge to list practices generically. Pick the two or three that matter for the described organization and say why the others were lower priority. Selection with a reason is worth more than coverage without one.
Shape for a security fundamentals analysis
D827 deliverables usually assess an organization's security position. These proportions fit that document.
| Section | Content | Share |
|---|---|---|
| Organization and assets | What the business does and which information assets matter, ranked by what their loss would cost. | 13 percent |
| Principles applied | Confidentiality, integrity and availability read against those assets, not defined in the abstract. | 16 percent |
| Vulnerabilities | Weaknesses present in this environment, each tied to an asset and an access path. | 19 percent |
| Risk assessment | Likelihood and impact per vulnerability, producing a ranked list rather than a flat one. | 17 percent |
| Countermeasures | Controls selected per risk, with cost, friction and residual exposure stated. | 21 percent |
| Close | What is accepted deliberately, and the first control to implement with its reason. | 14 percent |
Sourcing at the foundations level
Foundations courses tempt students toward general reference sites because the terms are common. Resist that. Security terminology has authoritative definitions in published standards and national agency glossaries, and using them makes your vocabulary exact rather than approximate. It also builds a habit you will need in every later security course, where imprecise terminology quietly changes the meaning of an answer.
Control guidance belongs to published frameworks. Vulnerability descriptions belong to the recognised public catalogues and to agency advisories, which are dated. Where you make a claim about how common an attack is or what a breach costs, that is empirical and needs research or survey data with a year attached, because those figures change annually and an undated one invites doubt.
The most useful sourcing discipline in a foundations course is separating the general from the applied. A framework can tell you that access should follow least privilege. Only your analysis of the scenario can say which account currently has more access than it needs. Writing those as separate sentences, with the citation on the first, shows an evaluator exactly where your own reasoning begins.
Watch the scope of what a source actually supports. A guidance document recommending multi-factor authentication for remote access does not, by itself, support a claim that adding it will reduce this organization's incident count by a given amount. Students frequently stretch a source one step past what it says, and that stretch is visible to anyone who follows the citation. Where you want to claim an effect, either find evidence for the effect or write the sentence as reasoning rather than as a sourced fact.
Follow the citation style named in your task and reference inline rather than in a closing pile. Where you produce a risk table, put the basis for each likelihood and impact rating in the table, because unexplained ratings are the most common weakness in foundational risk work.
Competent work and returned work
Competent submissions apply rather than define, rank risks rather than listing them, and attach residual exposure to every control. They read as though the student could sit in a meeting and explain why one thing is being fixed before another.
Returns follow four shapes. The document is a glossary with the scenario mentioned once. Risk ratings appear with no basis, so the ranking cannot be evaluated. Countermeasures are named without cost or friction, which makes them look free. Or the four access control steps are collapsed, most often by treating authentication and authorisation as one idea.
A quick check that catches most of it: read your countermeasure section and count the sentences that mention something specific from the scenario. If most of your controls could be lifted into any other organization's report unchanged, the applied aspects will score low no matter how correct the content is.
Performance assessment work at WGU can be revised and resubmitted with no grade penalty, so submit as soon as every aspect has a genuine answer. If your section carries an objective assessment too, WGU objective assessments are proctored and our boundary is absolute: preparation only, with terminology drills, risk practice and a candid read on your preassessment result. We will not take your exam, take no part once one begins, and portal sign-in details stay with you at all times.
Foundations course turning into a glossary?
Send the D827 rubric and scenario. We convert definitions into applied analysis with a ranked risk table and word targets per aspect.
Eight mistakes that cost time in D827
- Confusing the two codes. D827 is ITAS 2111 and D430 is ITAS 2110. Same title, different catalog entries. Only the one on your Degree Plan counts.
- Collapsing authentication and authorisation. Four separate steps, tested separately in every later security course.
- Defining instead of applying. The aspects want the principle read against this organization's assets.
- Unranked risks. A flat list gives a decision maker nothing. Rank, and say what the ranking is based on.
- Free-looking controls. Every countermeasure costs money, friction or both. Naming the cost is what makes the recommendation credible.
- Ignoring residual risk. No control eliminates a threat. Say what remains after each one.
- Undated statistics. Breach cost and attack frequency figures move every year. Date them or drop them.
- Skimming because it is foundational. This vocabulary is the base for the whole major. Imprecision here compounds.
Three questions students ask about D827
What is the difference between D827 and D430?
Do I need technical background to start the major here?
How deep does the vulnerability material go?
Where D827 sits in WGU's programs
The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.