Information Assurance
Course: CS861 — Doctoral Program in Computer Science (Cybersecurity & Information Assurance) Applied Context: Satire Media Inc. — Enterprise Security Strategy Plan
Overview
This course builds doctoral-level expertise in information assurance — covering threat landscape analysis, enterprise security strategy, risk assessment, standards and compliance, security policies, awareness programs, team operations, and audit frameworks. All concepts are applied through the development of a comprehensive Enterprise Security Strategy Plan for a real-world organization.
Defense in Depth — The Cybersecurity Onion
Cybersecurity is often compared to an onion: multiple concentric layers protect the core, and if one layer fails, the next provides defense.
The Four Layers
Outer Layer — Perimeter Security - Firewalls, intrusion detection and prevention systems (IDS/IPS), network access controls - Prevents unauthorized access; monitors traffic at the boundary - Ensures compliance with established security regulations
Intermediate Layer — Network and Application Security - Secure configurations, encryption, vulnerability patching, network behavior monitoring - Mitigates the impact of an intrusion that bypasses perimeter defenses - Includes application-layer controls: input validation, secure coding, WAFs
Deeper Layer — Identity and Access Management (IAM) - Manages user credentials, enforces MFA, regulates access to specific data and systems - Ensures that even if outer defenses are bypassed, attackers face authentication barriers - Role-Based Access Control (RBAC), OAuth, certificate-based authentication
Core Layer — Data Security and Incident Response - Encryption of data at rest and in transit, regular backups, unauthorized access monitoring - Incident Response Plan (IRP) for rapid containment, investigation, and recovery - The core represents the organization's most valuable and targeted asset: sensitive data
Advantages of the Onion Approach
- Layered Defense: If one layer fails, another catches the threat — no single point of failure
- Comprehensive Coverage: Addresses physical, network, application, and data security simultaneously
- Complexity for attackers: Each layer requires different techniques to bypass — dramatically raising the cost and effort of an attack
Risks, Threats, and Vulnerabilities
Core Definitions
| Concept | Definition | Example |
|---|---|---|
| Risk | Probability × Impact of a harmful event | Database SQL injection → data theft + financial loss |
| Threat | Any actor, event, or condition that can exploit a vulnerability | Hacker attempting unauthorized access |
| Vulnerability | A weakness or gap in security that a threat can exploit | Outdated software with unpatched CVEs |
Risk = Threat × Vulnerability × Impact
Key Risks for Enterprise Organizations
- Data breaches — Compromise of client PII, financial records, or intellectual property
- Operational disruptions — DDoS, ransomware, or system failures causing downtime
- Insider threats — Privileged users intentionally or accidentally misusing access
- Third-party vendor risks — Compromised suppliers providing attack vectors into the enterprise
- Compliance violations — Regulatory non-compliance leading to fines and reputational damage
Key Threats
| Type | Examples |
|---|---|
| External / Intentional | Ransomware (BlackCat/ALPHV), APTs, phishing, zero-day exploits |
| External / Unintentional | Natural disasters, infrastructure outages |
| Internal / Intentional | Insider data theft, sabotage |
| Internal / Unintentional | Human error, misconfiguration, accidental data exposure |
Common Vulnerabilities
- Outdated software and unpatched libraries
- Weak or reused passwords; absence of MFA
- Misconfigured firewalls or cloud storage buckets
- Excessive access privileges (violating least privilege)
- Insufficient network segmentation enabling lateral movement
Case Study: MGM Resorts Ransomware Attack (2023)
Incident Summary
In 2023, MGM Resorts International was attacked by the BlackCat (ALPHV) ransomware group, which encrypted over 100 ESXi hypervisors. The attack caused:
- Multi-day outages across hotel websites, reservation systems, and ATMs
- Significant financial losses from service interruptions and gaming revenue
- Customer dissatisfaction and reputational damage
- Potential regulatory fines and legal liabilities
Attack Vector
Social engineering — attackers used phishing and MFA bombing (repeated push notifications to exhaust users) to compromise employee credentials, then moved laterally to critical infrastructure.
Security Gaps Identified
- Insufficient employee training on social engineering and MFA fatigue attacks
- Weak detection and response capabilities — compromise was not detected quickly
- Poor network segmentation — lateral movement was not contained
- Inadequate vendor risk management for third-party dependencies
- Incomplete recovery strategy against ransomware-grade encryption
Recommended Mitigations
- Employee training — Regular phishing simulations and MFA push notification awareness
- Zero Trust Architecture (ZTA) — Continuous access verification; never trust, always verify
- Network segmentation — Isolate critical systems to limit blast radius of a breach
- Granular RBAC — Minimum access required for each role; quarterly access reviews
- Improved IRP — Include mock simulations, regular updates from lessons learned, and specific escalation paths
- Threat intelligence feeds — Real-time awareness of emerging ransomware tactics
Risk Assessment Framework
Risk Assessment Process
1. Planning and Preparation - Define goals: data protection, downtime reduction, compliance - Identify stakeholders: IT, operations, security, legal - Appoint a Risk Assessment Leader - Catalog assets: hardware, software, data, personnel, intellectual property
2. Risk Identification - Gather input from employees, managers, and department heads - Review existing policies, incident reports, and past audits - Apply threat modeling to identify attack vectors - Include both external threats (hackers, natural disasters) and internal threats (human error, insider misuse)
3. Risk Analysis - Assess likelihood using historical data, expert judgment, and industry benchmarks - Evaluate potential impact: operational, financial, reputational, legal - Classify using a risk matrix:
| Likelihood | Low Impact | Medium Impact | High Impact |
|---|---|---|---|
| Likely | Medium | High | Critical |
| Possible | Low | Medium | High |
| Unlikely | Low | Low | Medium |
4. Risk Evaluation and Prioritization - Focus on High and Critical risks first - Evaluate effectiveness of existing controls - Align priorities with organizational risk tolerance
5. Risk Mitigation and Control Recommendations - Technical controls: firewalls, encryption, SIEM, EDR - Administrative controls: policies, training, access reviews - Physical controls: facility access, device security - Backup and disaster recovery planning
6. Reporting and Monitoring - Document findings and recommendations in a formal report - Assign owners and remediation deadlines - Schedule re-assessment cadence (annual minimum; quarterly for high-risk areas)
Risk Assessment Scope for Satire Media Inc.
Covers all departments: IT infrastructure, cloud services (GCP, AWS), data handling (MongoDB, PostgreSQL, SQL Server), physical security, and legal/regulatory compliance. Specifically targets:
- External threats: outdated software, misconfigured infrastructure, insecure APIs
- Internal risks: weak access controls, unencrypted sensitive data, vulnerable source code
Standards and Frameworks
Standards vs. Procedures
| Concept | Defines | Answers |
|---|---|---|
| Standard | What is required — the benchmark to meet | What must be done |
| Procedure | How to achieve the standard — step-by-step instructions | How to do it |
Recommended Security Standards
| Standard | Domain | Value |
|---|---|---|
| ISO/IEC 27001 | Information Security Management System (ISMS) | Demonstrates data security commitment; reduces breach risk |
| NIST Cybersecurity Framework | Risk management | Identifies, protects, detects, responds, recovers |
| OWASP Secure Coding Practices | Application security | Minimizes software vulnerabilities at the development stage |
| ISO/IEC 20000 | IT Service Management | Improves service quality; aligns IT with business goals |
| CMMI for Development | Process maturity | Continuous improvement of project management and quality |
| ITIL | IT service delivery | Streamlined service operations; improved resource value |
| ISO 9001 | Quality Management System | Reduces errors; ensures consistent, high-quality delivery |
Security Policies
Why Security Policies Matter
Policies establish: - Clear expectations and accountability for all users - Consistent behavior across the organization - Legal and regulatory compliance baselines - A foundation for enforcement and disciplinary action
Access Control Policy
Purpose: Control who can access what systems, data, and resources — and under what conditions.
Key Provisions:
- RBAC (Role-Based Access Control) — Access granted based on least privilege aligned to job responsibilities; quarterly review of all access levels
- Authentication — Strong passwords with complexity requirements; OAuth validation; MFA mandatory for critical systems
- Access Request Process — Submitted via designated system; requires supervisor and IT security approval; group-level access only (no individual emergency access without 24-hour review)
- Access Revocation — Immediately deactivated on role change or termination; accounts inactive >90 days automatically reviewed
- Monitoring and Auditing — Continuous log monitoring; periodic audits; users provide access-level summaries
- Third-Party Access — Need-to-know basis only; temporary; requires signed NDA and security team approval; mutual TLS for cross-system connections
Mobile Device Policy
Key Provisions: - Devices must be encrypted and password-protected - Unauthorized applications prohibited on corporate devices - Remote wipe capability required for all enrolled devices - Personal devices accessing corporate systems must comply via MDM (Mobile Device Management)
Email Service Policy
Key Provisions: - Professional use only; sensitive information encrypted before transmission - Email retention schedules defined and enforced - Spam and phishing controls mandatory; suspicious emails reported to security team - STARTTLS enforced for all outbound email transmission
Internet Usage Policy
Key Provisions: - Acceptable use defined; inappropriate content blocked via proxy/filter - All traffic logged for security monitoring and audit purposes - Cybersecurity standards (OWASP, NIST) guide permitted browsing behavior - Violations subject to disciplinary action up to termination
Security Policy Template Structure
Every security policy should include:
- Overview — Purpose and context
- Scope — Who and what it applies to (employees, contractors, vendors, systems)
- Policy Statement — Core requirements (the what)
- Threats and Risk Evaluation — What threats this policy addresses
- Roles and Responsibilities — IT, security, managers, users
- User Guidelines and Procedures — The how (password rules, patch schedules, backup procedures)
- Compliance and Enforcement — Monitoring mechanisms; consequences of violation
- Review and Update Schedule — How and when the policy is reviewed
Security Awareness Program
Human error is one of the most significant factors in security breaches. A structured awareness program makes employees the first line of defense.
Monthly Security Awareness Workshops
Timing: First Tuesday of every month, starting Q1
Topics (rotating monthly): - Phishing identification and reporting - Password hygiene and management - Social engineering tactics (vishing, pretexting) - Safe remote work and VPN practices - Secure handling of sensitive data
Communications: - Email invitations 2 weeks before; reminder 1 day before - Intranet posts and newsletter inclusion - Promotional posters in common areas 10 days before
Success Metrics: - Participation rate ≥75% of target employees - Improved post-workshop quiz scores over time - Positive feedback in attendee evaluations
Annual Security Awareness Fair
Timing: October (Cybersecurity Awareness Month)
Activities: - Interactive exhibits: password-cracking demonstrations, phishing recognition challenges - Keynote presentations on current threat trends - Hands-on safe device handling demonstrations - Guest cybersecurity experts and panel discussions - Quiz session with prizes to maximize engagement
Success Metrics: - Turnout ≥80% of employees - Positive post-event survey feedback - Increased follow-up participation in security activities
Quarterly Phishing Simulations
Timing: Q2 first week, then quarterly
Process: 1. Design phishing scenarios mirroring real organizational risks 2. Execute simulations using phishing simulation tools 3. Record click-through rates and reporting rates per team 4. Send immediate feedback to all participants post-simulation 5. Provide targeted follow-up training for employees who failed
Success Metrics: - Click-through rate reduction to <5% by year 2 - Increase in phishing report rates over time - Quarterly performance comparisons to measure improvement
Security Team Operations and Monitoring
Critical Daily Monitoring Areas
1. Invalid Login Attempts
| KPI | Optimal Range | Action if Exceeded |
|---|---|---|
| Invalid login attempts per user per week | ≤5 | Investigate for brute-force; enforce MFA |
| Accounts locked due to failed logins | ≤1% of active accounts | Review impacted accounts; prompt password reset |
| Geographic origin of logins | Authorized regions only | Block unexpected geographies; alert security team |
2. Security Incidents Per Month
| KPI | Optimal Range | Action if Exceeded |
|---|---|---|
| Security incidents per month | <3 | Root cause analysis; patch/policy remediation |
| Incident response time (high-priority) | <2 hours | Escalate; review IRP effectiveness |
| Incident response time (critical) | <1 hour | Immediate escalation; invoke crisis response |
| Recurring incidents of same type | 0–1 per quarter | Systemic policy or technical fix required |
Security Operations Best Practices
Organizational Change Management for Security Implementation - Communicate why the security plan exists and what benefits it delivers before rollout - Provide tailored training matching varied workforce learning styles - Engage employees as stakeholders — participation reduces resistance by up to 70% - Create a culture of security awareness, not compliance-only compliance
Regular Risk Assessments and Updates - Conduct periodic audits of the security framework - Run penetration testing to validate controls against real attack scenarios - Monitor emerging threat intelligence feeds - Update the security plan based on assessment findings — treat security as continuous, not periodic
Compliance
Internal Compliance
How an organization enforces its own policies, procedures, and standards: - Training employees on current requirements - Conducting regular internal audits - Monitoring for violations and enforcing consequences - Building a culture where compliance is the default, not the exception
External Compliance
How an organization adheres to regulations imposed by government bodies, industry groups, or international standards organizations:
| Industry | Key Regulations |
|---|---|
| Healthcare | HIPAA (US) — patient data privacy and security |
| Finance | SOX (Sarbanes-Oxley), Dodd-Frank Act, AML regulations |
| Pharmaceuticals | FDA regulations, GxP standards, clinical data integrity |
| Technology / General | GDPR (EU), CCPA (California), ISO 27001 |
| Defense / Government | CMMC, FedRAMP, FISMA |
Compliance Framework for Satire Media Inc.
- ISO 27001 — ISMS framework for data security management
- NIST CSF — Risk management and cybersecurity posture baseline
- GDPR / CCPA — Data privacy for customer-facing services
- OWASP — Secure coding and API security standards
Enterprise Security Strategy Plan: Satire Media Inc.
Company Profile
- Industry: Satellite video and wireless internet services
- Size: 8,200 employees across multiple time zones
- Key Services: Digital TV/video platform, payroll/billing systems, API security via Apigee
- Infrastructure: Hybrid — on-premises Rancher/VMware cluster + GCP + AWS; 5G Open RAN deployment
Business Security Goals
- Protect client and internal data — End-to-end encryption in transit and at rest; MFA for critical systems; DLP deployment
- Achieve and uphold compliance — Regular audits; automated monitoring; targeted training programs
- Ensure business continuity — Disaster recovery and IRP for rapid recovery; minimize downtime
- Reduce third-party vendor risk — TPRM process with due diligence, continuous monitoring, and risk assessments for all vendors
- Maintain customer trust — Transparent, secure data handling; proactive breach communication protocols
Security Strategy Pillars
| Pillar | Approach |
|---|---|
| Defense-in-Depth | Physical, network, application, and data security layered controls |
| Zero Trust Architecture | "Never trust, always verify" — continuous identity verification for every access request |
| Continuous Monitoring | SIEM (Logz.io), application monitoring (Dynatrace), security scanning (SNYK, No-Name) |
| Employee Training | Monthly workshops, annual fair, quarterly phishing simulations |
| Risk Management | Annual risk assessments; quarterly reviews of high-risk areas |
Audit Strategy
Audit Checklist Areas: - Access control reviews — all user accounts, roles, and permissions - Software vulnerability scanning — libraries, dependencies, OS patches - Network configuration audit — firewall rules, segmentation, open ports - Data encryption verification — transit and at rest - Incident response readiness — IRP test exercises, response time metrics - Vendor risk review — third-party security assessments - Compliance documentation — audit trails, policy acknowledgments
Self-Assessment Cadence: - Monthly: Security awareness metrics, login anomaly review - Quarterly: Access control audit, phishing simulation analysis, risk re-evaluation - Annually: Full risk assessment, IRP tabletop exercise, compliance certification review
Key Takeaways
-
Risk is always a combination of threat, vulnerability, and impact — addressing one dimension alone is insufficient
-
Defense-in-depth means no single point of failure — every layer must be designed with the assumption that others will eventually be breached
-
People are both the greatest vulnerability and the strongest defense — security awareness programs are not optional; they are a core security control
-
Zero Trust is the modern baseline — perimeter-only security is obsolete; every access request must be verified regardless of origin
-
Standards provide a framework, policies provide enforcement — ISO 27001, NIST, and OWASP define the what; internal policies and procedures define the how
-
Compliance is a floor, not a ceiling — meeting regulatory requirements is necessary but not sufficient for strong security posture
-
Monitoring and metrics make security measurable — KPIs for login anomalies, incident response time, and phishing click rates transform abstract security into actionable data
-
Incident response must be practiced, not just documented — mock simulations, tabletop exercises, and post-incident reviews are what make an IRP effective
-
Third-party risk is organizational risk — vendor security posture must be continuously monitored, not assessed once at onboarding
-
Security is a business enabler — a strong security posture builds customer trust, enables compliance, and supports long-term organizational growth
References
- Stallings, W., & Brown, L. (2015). Computer Security: Principles and Practice. Pearson.
- Peltier, T. R. (2016). Information Security Policies, Procedures, and Standards. CRC Press.
- OWASP Foundation (2021). OWASP Secure Coding Practices Quick Reference Guide.
- Shrobe, H., Shrier, D., & Pentland, A. (2018). New Solutions for Cybersecurity. MIT Press.
- Manzoor, J., et al. (2024). Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs. PLoS One, 19(3).
- Ramluckan, T., van Niekerk, B., et al. (2020). Organizational change management in cybersecurity implementations. Information & Computer Security.
- Hegazi, T., & Fouda, M. (2023). Risk assessment frameworks for enterprise cybersecurity. Journal of Information Security.
- Verizon (2023). Data Breach Investigations Report (DBIR).