📧 hipravat@gmail.com Support

Information Assurance

Course: CS861 — Doctoral Program in Computer Science (Cybersecurity & Information Assurance) Applied Context: Satire Media Inc. — Enterprise Security Strategy Plan


Overview

This course builds doctoral-level expertise in information assurance — covering threat landscape analysis, enterprise security strategy, risk assessment, standards and compliance, security policies, awareness programs, team operations, and audit frameworks. All concepts are applied through the development of a comprehensive Enterprise Security Strategy Plan for a real-world organization.


Defense in Depth — The Cybersecurity Onion

Cybersecurity is often compared to an onion: multiple concentric layers protect the core, and if one layer fails, the next provides defense.

The Four Layers

Outer Layer — Perimeter Security - Firewalls, intrusion detection and prevention systems (IDS/IPS), network access controls - Prevents unauthorized access; monitors traffic at the boundary - Ensures compliance with established security regulations

Intermediate Layer — Network and Application Security - Secure configurations, encryption, vulnerability patching, network behavior monitoring - Mitigates the impact of an intrusion that bypasses perimeter defenses - Includes application-layer controls: input validation, secure coding, WAFs

Deeper Layer — Identity and Access Management (IAM) - Manages user credentials, enforces MFA, regulates access to specific data and systems - Ensures that even if outer defenses are bypassed, attackers face authentication barriers - Role-Based Access Control (RBAC), OAuth, certificate-based authentication

Core Layer — Data Security and Incident Response - Encryption of data at rest and in transit, regular backups, unauthorized access monitoring - Incident Response Plan (IRP) for rapid containment, investigation, and recovery - The core represents the organization's most valuable and targeted asset: sensitive data

Advantages of the Onion Approach

  • Layered Defense: If one layer fails, another catches the threat — no single point of failure
  • Comprehensive Coverage: Addresses physical, network, application, and data security simultaneously
  • Complexity for attackers: Each layer requires different techniques to bypass — dramatically raising the cost and effort of an attack

Risks, Threats, and Vulnerabilities

Core Definitions

Concept Definition Example
Risk Probability × Impact of a harmful event Database SQL injection → data theft + financial loss
Threat Any actor, event, or condition that can exploit a vulnerability Hacker attempting unauthorized access
Vulnerability A weakness or gap in security that a threat can exploit Outdated software with unpatched CVEs

Risk = Threat × Vulnerability × Impact

Key Risks for Enterprise Organizations

  • Data breaches — Compromise of client PII, financial records, or intellectual property
  • Operational disruptions — DDoS, ransomware, or system failures causing downtime
  • Insider threats — Privileged users intentionally or accidentally misusing access
  • Third-party vendor risks — Compromised suppliers providing attack vectors into the enterprise
  • Compliance violations — Regulatory non-compliance leading to fines and reputational damage

Key Threats

Type Examples
External / Intentional Ransomware (BlackCat/ALPHV), APTs, phishing, zero-day exploits
External / Unintentional Natural disasters, infrastructure outages
Internal / Intentional Insider data theft, sabotage
Internal / Unintentional Human error, misconfiguration, accidental data exposure

Common Vulnerabilities

  • Outdated software and unpatched libraries
  • Weak or reused passwords; absence of MFA
  • Misconfigured firewalls or cloud storage buckets
  • Excessive access privileges (violating least privilege)
  • Insufficient network segmentation enabling lateral movement

Case Study: MGM Resorts Ransomware Attack (2023)

Incident Summary

In 2023, MGM Resorts International was attacked by the BlackCat (ALPHV) ransomware group, which encrypted over 100 ESXi hypervisors. The attack caused:

  • Multi-day outages across hotel websites, reservation systems, and ATMs
  • Significant financial losses from service interruptions and gaming revenue
  • Customer dissatisfaction and reputational damage
  • Potential regulatory fines and legal liabilities

Attack Vector

Social engineering — attackers used phishing and MFA bombing (repeated push notifications to exhaust users) to compromise employee credentials, then moved laterally to critical infrastructure.

Security Gaps Identified

  • Insufficient employee training on social engineering and MFA fatigue attacks
  • Weak detection and response capabilities — compromise was not detected quickly
  • Poor network segmentation — lateral movement was not contained
  • Inadequate vendor risk management for third-party dependencies
  • Incomplete recovery strategy against ransomware-grade encryption

Recommended Mitigations

  1. Employee training — Regular phishing simulations and MFA push notification awareness
  2. Zero Trust Architecture (ZTA) — Continuous access verification; never trust, always verify
  3. Network segmentation — Isolate critical systems to limit blast radius of a breach
  4. Granular RBAC — Minimum access required for each role; quarterly access reviews
  5. Improved IRP — Include mock simulations, regular updates from lessons learned, and specific escalation paths
  6. Threat intelligence feeds — Real-time awareness of emerging ransomware tactics

Risk Assessment Framework

Risk Assessment Process

1. Planning and Preparation - Define goals: data protection, downtime reduction, compliance - Identify stakeholders: IT, operations, security, legal - Appoint a Risk Assessment Leader - Catalog assets: hardware, software, data, personnel, intellectual property

2. Risk Identification - Gather input from employees, managers, and department heads - Review existing policies, incident reports, and past audits - Apply threat modeling to identify attack vectors - Include both external threats (hackers, natural disasters) and internal threats (human error, insider misuse)

3. Risk Analysis - Assess likelihood using historical data, expert judgment, and industry benchmarks - Evaluate potential impact: operational, financial, reputational, legal - Classify using a risk matrix:

Likelihood Low Impact Medium Impact High Impact
Likely Medium High Critical
Possible Low Medium High
Unlikely Low Low Medium

4. Risk Evaluation and Prioritization - Focus on High and Critical risks first - Evaluate effectiveness of existing controls - Align priorities with organizational risk tolerance

5. Risk Mitigation and Control Recommendations - Technical controls: firewalls, encryption, SIEM, EDR - Administrative controls: policies, training, access reviews - Physical controls: facility access, device security - Backup and disaster recovery planning

6. Reporting and Monitoring - Document findings and recommendations in a formal report - Assign owners and remediation deadlines - Schedule re-assessment cadence (annual minimum; quarterly for high-risk areas)

Risk Assessment Scope for Satire Media Inc.

Covers all departments: IT infrastructure, cloud services (GCP, AWS), data handling (MongoDB, PostgreSQL, SQL Server), physical security, and legal/regulatory compliance. Specifically targets:

  • External threats: outdated software, misconfigured infrastructure, insecure APIs
  • Internal risks: weak access controls, unencrypted sensitive data, vulnerable source code

Standards and Frameworks

Standards vs. Procedures

Concept Defines Answers
Standard What is required — the benchmark to meet What must be done
Procedure How to achieve the standard — step-by-step instructions How to do it

Recommended Security Standards

Standard Domain Value
ISO/IEC 27001 Information Security Management System (ISMS) Demonstrates data security commitment; reduces breach risk
NIST Cybersecurity Framework Risk management Identifies, protects, detects, responds, recovers
OWASP Secure Coding Practices Application security Minimizes software vulnerabilities at the development stage
ISO/IEC 20000 IT Service Management Improves service quality; aligns IT with business goals
CMMI for Development Process maturity Continuous improvement of project management and quality
ITIL IT service delivery Streamlined service operations; improved resource value
ISO 9001 Quality Management System Reduces errors; ensures consistent, high-quality delivery

Security Policies

Why Security Policies Matter

Policies establish: - Clear expectations and accountability for all users - Consistent behavior across the organization - Legal and regulatory compliance baselines - A foundation for enforcement and disciplinary action

Access Control Policy

Purpose: Control who can access what systems, data, and resources — and under what conditions.

Key Provisions:

  • RBAC (Role-Based Access Control) — Access granted based on least privilege aligned to job responsibilities; quarterly review of all access levels
  • Authentication — Strong passwords with complexity requirements; OAuth validation; MFA mandatory for critical systems
  • Access Request Process — Submitted via designated system; requires supervisor and IT security approval; group-level access only (no individual emergency access without 24-hour review)
  • Access Revocation — Immediately deactivated on role change or termination; accounts inactive >90 days automatically reviewed
  • Monitoring and Auditing — Continuous log monitoring; periodic audits; users provide access-level summaries
  • Third-Party Access — Need-to-know basis only; temporary; requires signed NDA and security team approval; mutual TLS for cross-system connections

Mobile Device Policy

Key Provisions: - Devices must be encrypted and password-protected - Unauthorized applications prohibited on corporate devices - Remote wipe capability required for all enrolled devices - Personal devices accessing corporate systems must comply via MDM (Mobile Device Management)

Email Service Policy

Key Provisions: - Professional use only; sensitive information encrypted before transmission - Email retention schedules defined and enforced - Spam and phishing controls mandatory; suspicious emails reported to security team - STARTTLS enforced for all outbound email transmission

Internet Usage Policy

Key Provisions: - Acceptable use defined; inappropriate content blocked via proxy/filter - All traffic logged for security monitoring and audit purposes - Cybersecurity standards (OWASP, NIST) guide permitted browsing behavior - Violations subject to disciplinary action up to termination

Security Policy Template Structure

Every security policy should include:

  1. Overview — Purpose and context
  2. Scope — Who and what it applies to (employees, contractors, vendors, systems)
  3. Policy Statement — Core requirements (the what)
  4. Threats and Risk Evaluation — What threats this policy addresses
  5. Roles and Responsibilities — IT, security, managers, users
  6. User Guidelines and Procedures — The how (password rules, patch schedules, backup procedures)
  7. Compliance and Enforcement — Monitoring mechanisms; consequences of violation
  8. Review and Update Schedule — How and when the policy is reviewed

Security Awareness Program

Human error is one of the most significant factors in security breaches. A structured awareness program makes employees the first line of defense.

Monthly Security Awareness Workshops

Timing: First Tuesday of every month, starting Q1

Topics (rotating monthly): - Phishing identification and reporting - Password hygiene and management - Social engineering tactics (vishing, pretexting) - Safe remote work and VPN practices - Secure handling of sensitive data

Communications: - Email invitations 2 weeks before; reminder 1 day before - Intranet posts and newsletter inclusion - Promotional posters in common areas 10 days before

Success Metrics: - Participation rate ≥75% of target employees - Improved post-workshop quiz scores over time - Positive feedback in attendee evaluations

Annual Security Awareness Fair

Timing: October (Cybersecurity Awareness Month)

Activities: - Interactive exhibits: password-cracking demonstrations, phishing recognition challenges - Keynote presentations on current threat trends - Hands-on safe device handling demonstrations - Guest cybersecurity experts and panel discussions - Quiz session with prizes to maximize engagement

Success Metrics: - Turnout ≥80% of employees - Positive post-event survey feedback - Increased follow-up participation in security activities

Quarterly Phishing Simulations

Timing: Q2 first week, then quarterly

Process: 1. Design phishing scenarios mirroring real organizational risks 2. Execute simulations using phishing simulation tools 3. Record click-through rates and reporting rates per team 4. Send immediate feedback to all participants post-simulation 5. Provide targeted follow-up training for employees who failed

Success Metrics: - Click-through rate reduction to <5% by year 2 - Increase in phishing report rates over time - Quarterly performance comparisons to measure improvement


Security Team Operations and Monitoring

Critical Daily Monitoring Areas

1. Invalid Login Attempts

KPI Optimal Range Action if Exceeded
Invalid login attempts per user per week ≤5 Investigate for brute-force; enforce MFA
Accounts locked due to failed logins ≤1% of active accounts Review impacted accounts; prompt password reset
Geographic origin of logins Authorized regions only Block unexpected geographies; alert security team

2. Security Incidents Per Month

KPI Optimal Range Action if Exceeded
Security incidents per month <3 Root cause analysis; patch/policy remediation
Incident response time (high-priority) <2 hours Escalate; review IRP effectiveness
Incident response time (critical) <1 hour Immediate escalation; invoke crisis response
Recurring incidents of same type 0–1 per quarter Systemic policy or technical fix required

Security Operations Best Practices

Organizational Change Management for Security Implementation - Communicate why the security plan exists and what benefits it delivers before rollout - Provide tailored training matching varied workforce learning styles - Engage employees as stakeholders — participation reduces resistance by up to 70% - Create a culture of security awareness, not compliance-only compliance

Regular Risk Assessments and Updates - Conduct periodic audits of the security framework - Run penetration testing to validate controls against real attack scenarios - Monitor emerging threat intelligence feeds - Update the security plan based on assessment findings — treat security as continuous, not periodic


Compliance

Internal Compliance

How an organization enforces its own policies, procedures, and standards: - Training employees on current requirements - Conducting regular internal audits - Monitoring for violations and enforcing consequences - Building a culture where compliance is the default, not the exception

External Compliance

How an organization adheres to regulations imposed by government bodies, industry groups, or international standards organizations:

Industry Key Regulations
Healthcare HIPAA (US) — patient data privacy and security
Finance SOX (Sarbanes-Oxley), Dodd-Frank Act, AML regulations
Pharmaceuticals FDA regulations, GxP standards, clinical data integrity
Technology / General GDPR (EU), CCPA (California), ISO 27001
Defense / Government CMMC, FedRAMP, FISMA

Compliance Framework for Satire Media Inc.

  • ISO 27001 — ISMS framework for data security management
  • NIST CSF — Risk management and cybersecurity posture baseline
  • GDPR / CCPA — Data privacy for customer-facing services
  • OWASP — Secure coding and API security standards

Enterprise Security Strategy Plan: Satire Media Inc.

Company Profile

  • Industry: Satellite video and wireless internet services
  • Size: 8,200 employees across multiple time zones
  • Key Services: Digital TV/video platform, payroll/billing systems, API security via Apigee
  • Infrastructure: Hybrid — on-premises Rancher/VMware cluster + GCP + AWS; 5G Open RAN deployment

Business Security Goals

  1. Protect client and internal data — End-to-end encryption in transit and at rest; MFA for critical systems; DLP deployment
  2. Achieve and uphold compliance — Regular audits; automated monitoring; targeted training programs
  3. Ensure business continuity — Disaster recovery and IRP for rapid recovery; minimize downtime
  4. Reduce third-party vendor risk — TPRM process with due diligence, continuous monitoring, and risk assessments for all vendors
  5. Maintain customer trust — Transparent, secure data handling; proactive breach communication protocols

Security Strategy Pillars

Pillar Approach
Defense-in-Depth Physical, network, application, and data security layered controls
Zero Trust Architecture "Never trust, always verify" — continuous identity verification for every access request
Continuous Monitoring SIEM (Logz.io), application monitoring (Dynatrace), security scanning (SNYK, No-Name)
Employee Training Monthly workshops, annual fair, quarterly phishing simulations
Risk Management Annual risk assessments; quarterly reviews of high-risk areas

Audit Strategy

Audit Checklist Areas: - Access control reviews — all user accounts, roles, and permissions - Software vulnerability scanning — libraries, dependencies, OS patches - Network configuration audit — firewall rules, segmentation, open ports - Data encryption verification — transit and at rest - Incident response readiness — IRP test exercises, response time metrics - Vendor risk review — third-party security assessments - Compliance documentation — audit trails, policy acknowledgments

Self-Assessment Cadence: - Monthly: Security awareness metrics, login anomaly review - Quarterly: Access control audit, phishing simulation analysis, risk re-evaluation - Annually: Full risk assessment, IRP tabletop exercise, compliance certification review


Key Takeaways

  1. Risk is always a combination of threat, vulnerability, and impact — addressing one dimension alone is insufficient

  2. Defense-in-depth means no single point of failure — every layer must be designed with the assumption that others will eventually be breached

  3. People are both the greatest vulnerability and the strongest defense — security awareness programs are not optional; they are a core security control

  4. Zero Trust is the modern baseline — perimeter-only security is obsolete; every access request must be verified regardless of origin

  5. Standards provide a framework, policies provide enforcement — ISO 27001, NIST, and OWASP define the what; internal policies and procedures define the how

  6. Compliance is a floor, not a ceiling — meeting regulatory requirements is necessary but not sufficient for strong security posture

  7. Monitoring and metrics make security measurable — KPIs for login anomalies, incident response time, and phishing click rates transform abstract security into actionable data

  8. Incident response must be practiced, not just documented — mock simulations, tabletop exercises, and post-incident reviews are what make an IRP effective

  9. Third-party risk is organizational risk — vendor security posture must be continuously monitored, not assessed once at onboarding

  10. Security is a business enabler — a strong security posture builds customer trust, enables compliance, and supports long-term organizational growth


References

  • Stallings, W., & Brown, L. (2015). Computer Security: Principles and Practice. Pearson.
  • Peltier, T. R. (2016). Information Security Policies, Procedures, and Standards. CRC Press.
  • OWASP Foundation (2021). OWASP Secure Coding Practices Quick Reference Guide.
  • Shrobe, H., Shrier, D., & Pentland, A. (2018). New Solutions for Cybersecurity. MIT Press.
  • Manzoor, J., et al. (2024). Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs. PLoS One, 19(3).
  • Ramluckan, T., van Niekerk, B., et al. (2020). Organizational change management in cybersecurity implementations. Information & Computer Security.
  • Hegazi, T., & Fouda, M. (2023). Risk assessment frameworks for enterprise cybersecurity. Journal of Information Security.
  • Verizon (2023). Data Breach Investigations Report (DBIR).