Project 1 Part A: Planning a Security Assessment
Unit 1 Assignment Directions: Project 1 Part A: Planning a Security Assessment
Task
To start this task for the City of Gotham, you will plan for a security assessment against a target environment. The target environment will be comprised of multiple virtual machines that are arranged on a virtual network with intentional vulnerabilities. Please note you will use Nessus and OpenVAS in Unit 2. Consider this information as you go about planning your project.
Needs Assessment and Best Practices Research
Exercise 1: Organize a comprehensive applied project that embodies current best practices in cybersecurity.
- Identify the areas where IT security has failed, leading to successful intrusions and violations of city assets and user data.
- Research and analyze current best practices in cybersecurity, considering emerging threats, industry standards, and successful case studies.
- Identify relevant frameworks and methodologies, such as the NIST Cybersecurity Framework or CIS Controls, to guide the implementation of a solid Cybersecurity Operation Center (SOC) for the City of Gotham.
- Develop a project scope that encompasses the identified needs and aligns with the best practices in the field.
- Add your work in the Comprehensive Assessment and Proposal template, found in the submission instructions.
Instructions
Hands-on Exercises
Exercise 3: Design a detailed plan for immersive and hands-on cybersecurity learning experiences.
In this third exercise, you will create a detailed plan for immersive and hands-on cybersecurity learning experiences.
- Identify key areas of focus, such as incident detection and response, vulnerability assessment, secure network design, or secure coding practices.
- Develop practical exercises, simulations, or virtual labs that allow the IT security team to apply cybersecurity concepts in a controlled environment.
- Incorporate real-life scenarios and case studies to enhance the relevance and effectiveness of the learning experiences.
- Establish appropriate metrics and evaluation criteria to measure the success and impact of the hands-on learning activities.
Exercise 4: Establish clear, measurable goals and blueprints for executing the applied cybersecurity project effectively.
In this fourth exercise, you will establish clear and measurable goals for the implementation of the Cybersecurity Operation Center, addressing the identified needs and aligning with best practices.
- Define goals such as reducing the number of successful intrusions, enhancing incident response capabilities, improving network security, and ensuring regulatory compliance.
- Review and select 3-7 main competencies that your project is achieving based on the goals you defined. Use the CTCH Cybersecurity Technology Competencies Master List. You should already be familiar with many of these competencies as your projects in previous courses were assessed against them. The SMART goals you develop for your project should be based on these competencies. These competencies are directly reflective of the CAE / KUs (Center for Academic Excellence / Knowledge Units), which is the national center for security administration for cyber-affiliated schools. Any future employer in cybersecurity will be familiar with this center and the knowledge units; therefore, aligning the correct competencies to your project is critical.
- Develop a detailed execution plan, including timelines, milestones, and resource allocation to guide the implementation of the cybersecurity project.
- Create blueprints for the deployment of security technologies, such as firewalls, intrusion detection systems, or security information and event management (SIEM) solutions.
- Define roles and responsibilities for team members involved in the project and establish a communication and reporting framework to ensure effective coordination.
- Add your plan in the Project Charter template, which will be included as an appendix in your Comprehensive Assessment and Proposal.
Conclusion
By addressing the exercises outlined in the previous section, you will organize a comprehensive applied project that embodies current best practices in cybersecurity. You will apply a deep understanding of cybersecurity concepts, ensure adherence to national standards, design immersive, hands-on learning experiences, and establish clear, measurable goals and blueprints for effectively executing the applied cybersecurity project. Through your expertise and guidance, the City of Gotham will be equipped with a solid Cybersecurity Operation Center, effectively protecting its assets and user data, ensuring compliance with government regulations, and restoring trust in its security capabilities.
Tutorial For Project 1 Part A: Planning a Security Assessment

