SHORT RESPONSE

profileMoona26
ModuleFiveShortResponseGuidelinesandRubric-CYB-250-15105-M01CyberDefense2024C-6Oct-Dec.pdf

CYB 250 Module Five Short Response Guidelines and Rubric

Overview

Security analysts play an important role working alongside the computer incident response team (CIRT). The analyst will be the individual who either fixes the issues or allocates resources to

fix the issues iden�fied by the CIRT. Using resources to facilitate the work becomes essen�al to sustain the health of an organiza�on. Applying the Center for Internet Security (CIS) cri�cal

controls to company infrastructure is normal prac�ce for an analyst. The controls are meant to guide the organiza�on toward compliance. They are not meant to be used in isola�on.

Comparing an organiza�on’s technical concerns to the CIS cri�cal controls provides a means of developing solu�ons to remediate issues. Once the issues are iden�fied and remediated, the

next step is to determine how to properly report those issues to different stakeholders.

Prompt

A�er reviewing Breach Analysis Simula�on Scenario Two, address the cri�cal elements below:

I. Repor�ng: Select an audience for repor�ng (sales team, senior management, or other stakeholders).

A. Explain how you report technical concerns to non-technical people in your selected audience. Keep in mind that most managerial roles are non-technical in nature; managers

need informa�on presented to them in a format they can easily understand and use.

II. Subcontrols: Refer to the CIS Controls worksheet used in Breach Analysis Simula�on Scenario Two and recommend two addi�onal subcontrols that could be modified by policy,

implementa�on, automa�on, or repor�ng to enhance security for the organiza�on.

A. Subcontrol One: Describe the modifica�on of the subcontrol and jus�fy your recommenda�on.

B. Subcontrol Two: Describe the modifica�on of the subcontrol and jus�fy your recommenda�on.

III. Two-Factor Authen�ca�on: A proposed solu�on for the breach issue is to use RSA key fobs as a means of two-factor authen�ca�on.

A. Discuss the merits of using RSA encryp�on and the implementa�on of two-factor authen�ca�on.

B. Discuss how different forms of encryp�on may be used in VPN so�ware.

What to Submit

Your submission should be 1 to 2 pages in length. Use double spacing, 12-point Times New Roman font, and one-inch margins. All sources must be cited using APA format. Use a file name

that includes the course code, the assignment �tle, and your name—for example, CYB_123_Assignment_Firstname_Lastname.docx.



11/25/24, 12:36 PM Assignment Information

https://learn.snhu.edu/d2l/le/content/1748997/viewContent/36623164/View 1/2

Module Five Short Response Rubric

Criteria Exemplary (100%) Proficient (85%) Needs Improvement (55%) Not Evident (0%) Value

Repor�ng: Report Technical

Concerns

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Explains how to report

technical concerns to

nontechnical people in the

selected audience

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

30

Subcontrols: Subcontrol One Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Describes the modifica�on of

the subcontrol and jus�fies the

recommenda�on

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

15

Subcontrols: Subcontrol Two Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Describes the modifica�on of

the subcontrol and jus�fies the

recommenda�on

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

15

Two-Factor Authen�ca�on:

RSA Encryp�on

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Discusses the merits of using

RSA encryp�on and the

implementa�on of two-factor

authen�ca�on

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

15

Two-factor Authen�ca�on:

VPN So�ware

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Discusses how different forms

of encryp�on may be used in

VPN so�ware

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

15

Ar�cula�on of Response Submission is free of errors

related to cita�ons, grammar,

spelling, and organiza�on and

is presented in a professional

and easy-to-read format

Submission has no major errors

related to cita�ons, grammar,

spelling, or organiza�on

Submission has some errors

related to cita�ons, grammar,

spelling, or organiza�on that

nega�vely impact readability

and ar�cula�on of main ideas

Submission has cri�cal errors

related to cita�ons, grammar,

spelling, or organiza�on that

prevent understanding of ideas

10

Total: 100%

11/25/24, 12:36 PM Assignment Information

https://learn.snhu.edu/d2l/le/content/1748997/viewContent/36623164/View 2/2