8-1 Assignment: Case Study
IT 552 Module Eight Assignment Rubric
The purpose of this assignment is for students to write a case study based on a common information security scenario. Prompt: You are the senior information security manager for a federal agency. You received a phone call from an employee stating that his laptop was stolen from his workstation. He tells you that the laptop has at least 20 cases with Social Security numbers of individuals he has been assisting. How would you handle this security incident? What is the first thing you should do? How would you retrieve/destroy the data? You may have an internal thief—what would you do to find out who stole the laptop? What security violations have been committed? How would you prevent this from happening again? Write a report summarizing the issue and addressing all questions. Specifically, the following critical elements must be addressed:
Discuss how the situation would be handled and what steps to begin with.
Examine how data would be retrieved and/or destroyed.
Address what steps would be taken to determine the culprit.
Name what security violations have been committed.
Determine what steps could be taken in order to prevent this from happening again. Guidelines for Submission: Your paper must be submitted as a two-page Microsoft Word document with double spacing, 12-point Times New Roman font, and one-inch margins.
Critical Elements Proficient (100%) Needs Improvement (70%) Not Evident (0%) Value
Situation Discusses the situation and what steps to begin with
Minimally discusses the situation and/or what steps to begin with
Does not discuss the situation and/or what steps to begin with
18
Data Recovery and/or Destruction
Examines how the data will be retrieved and/or destroyed
Insufficiently examines how the data will be retrieved and/or destroyed
Does not examine how the data will be retrieved and/or destroyed
18
Determine the Culprit
Addresses what steps would need to be taken to determine the culprit
Addresses what steps would need to be taken to determine the culprit, but lacks in detail
Steps needed to be taken to determine the culprit are not evident
18
Security Violations Names what security violations have been committed
Security violations are minimally addressed
Does not address security violations 18
Prevention Determines steps to be taken for prevention
Minimally describes steps to be taken for prevention
Does not describe steps to be taken for prevention
18
Articulation of Response
Submission has no major errors related to citations, grammar, spelling, syntax, or organization
Submission has major errors related to citations, grammar, spelling, syntax, or organization that negatively impact readability and articulation of main ideas
Submission has critical errors related to citations, grammar, spelling, syntax, or organization that prevent the understanding of ideas
10
Earned Total 100%