case study
CYB 200 Module Two Case Study Activity Guidelines and Rubric
Overview
In this case study assignment, we will con�nue to inves�gate the Fundamental Security Design Principles at work in a real-world scenario. Through the lens of data protec�on, we will
analyze the following principles:
Least Privilege
Layering (Defense in Depth)
Fail-Safe Defaults / Fail Secure
Modularity
Usability
Note: You will be engaging with this scenario again in the Module Three discussion.
Case Study Scenario
You are a cybersecurity analyst working at a prominent regional hospital. On Monday morning, the organiza�on’s technology help desk received a call from Dr. John Beard, a long-�me
resident physician. Dr. Beard called them to report that his company laptop was stolen from his car a�er he stopped to work out at a local gym on his way home from the office.
A representa�ve from the help desk informed you of the the� and also men�oned that Dr. Beard stated that his laptop case contained a USB thumb drive that he purchased to “back up”
important pa�ent files he saved onto his laptop. Dr. Beard also revealed that his daily planner “might have” been in the bag and that the planner had his hospital computer user name and
password wri�en on the back cover. Prior to ending the call, Dr. Beard told the representa�ve that he would call her back if his daily planner turned up.
As your conversa�on with the help desk representa�ve wound down, she commented that Dr. Beard has many different computer “issues” that keep her team busy. She recalled talking to
Dr. Beard about the hospital’s policy against accessing pa�ent files remotely and his annoyance with her inability to help him “get work done” while away from the hospital. And just a week
ago, a junior member of her team completed a service �cket to reconfigure Dr. Beard’s laptop to grant him administra�ve rights. The service request stuck out because it did not have a
“reason” indicated (a company policy requirement) but was s�ll approved by James Davis, the hospital’s senior system administrator and close personal friend of Dr. Beard.
Prompt
A�er reading the scenario above, complete the Fundamental Security Design Principles mapping table in the Case Study Template and answer the short response ques�ons. You’ll no�ce that
the listed Fundamental Security Design Principles differ from those presented in previous ac�vi�es. In the cybersecurity trade, there are many different design principles and frameworks.
Successful prac��oners learn to work with many different (but conceptually similar) principles to achieve their security goals.
Specifically, you must address the cri�cal elements listed below:
9/11/24, 10:40 AM Assignment Information
https://learn.snhu.edu/d2l/le/content/1698647/viewContent/35102834/View 1/3
I. Fundamental Security Design Principles Mapping: Fill in the table in the Module Two Case Study Template by comple�ng the following steps for each control recommenda�on:
A. Specify which Fundamental Security Design Principle best applies by marking all appropriate cells with an X.
B. Indicate which security objec�ve (confiden�ality, availability, or integrity) best reflects your selected control recommenda�on.
C. Explain your choices in one to two sentences, providing a selec�on-specific jus�fica�on to support your decision.
II. Short Response Ques�ons:
A. How might you work with someone like Dr. Beard to cul�vate a security mind-set that is more in line with the organiza�on’s ethical norms? Hint: Consider his a�tude, his past
behaviors, and his opinion about organiza�onal policies.
B. How would you help the hospital be�er secure its pa�ent files? Make sure to incorporate at least one data state (data-at-rest, data-in-use, or data-in-mo�on) and one of the
control recommenda�ons from your completed table in your response.
What to Submit
Submit your completed Fundamental Security Design Principles map and short response answers in the Module Two Case Study Template. Your submission should be 1–2 pages in length
(plus a cover page and references, if used) and wri�en in APA format. Use double spacing, 12-point Times New Roman font, and one-inch margins. Use a filename that includes the course
code, the assignment number, and your name—for example, CYB_100_1- 4_Neo_Anderson.docx.
Module Two Case Study Activity Rubric
Criteria Proficient (100%) Needs Improvement (65%) Not Evident (0%) Value
Mapping: Fundamental
Security Design Principle
Specifies which Fundamental Security
Design Principle applies to at least 8 of the
control recommenda�ons
Specifies which Fundamental Security
Design Principle applies to fewer than 8 of
the control recommenda�ons
Does not address cri�cal element, or
response is irrelevant
20
Mapping: Security Objec�ve Indicates which security objec�ve (CIA)
best applies to 8 or more control
recommenda�ons
Indicates which security objec�ve (CIA)
best applies to fewer than 8 control
recommenda�ons
Does not address cri�cal element, or
response is irrelevant
20
Mapping: Explain Explains choices with relevant
jus�fica�ons for at least 8 of the control
recommenda�ons
Explains choices with relevant
jus�fica�ons for fewer than 8 of the
control recommenda�ons
Does not address cri�cal element, or
response is irrelevant
25
Short Response: Cul�va�ng
Mindset
Explains how you might work with
someone like Dr. Beard to cul�vate a
security mindset that is more in line with
the organiza�on’s ethical norms
Addresses “Proficient” criteria, but there
are gaps in clarity, logic, or detail
Does not address cri�cal element, or
response is irrelevant
10
9/11/24, 10:40 AM Assignment Information
https://learn.snhu.edu/d2l/le/content/1698647/viewContent/35102834/View 2/3
Criteria Proficient (100%) Needs Improvement (65%) Not Evident (0%) Value
Short Response: Be�er
Secure
Explains how you would help the hospital
be�er secure its pa�ent files incorpora�ng
at least one data state (data-at-rest, data-
in-use, or data-in-mo�on) and one of the
control recommenda�ons from your table
Addresses “Proficient” criteria, but there
are gaps in clarity, logic, or detail
Does not address cri�cal element, or
response is irrelevant
20
Ar�cula�on of Response Submission has no major errors related to
cita�ons, grammar, spelling, or
organiza�on
Submission has some errors related to
cita�ons, grammar, spelling, or
organiza�on that nega�vely impact
readability and ar�cula�on of main ideas
Submission has cri�cal errors related to
cita�ons, grammar, spelling, or
organiza�on that prevent understanding of
ideas
5
Total: 100%
9/11/24, 10:40 AM Assignment Information
https://learn.snhu.edu/d2l/le/content/1698647/viewContent/35102834/View 3/3