SHORT RESPONSE

profileMoona26
ModuleTwoShortResponseGuidelinesandRubric-CYB-250-15105-M01CyberDefense2024C-6Oct-Dec.pdf

CYB 250 Module Two Short Response Guidelines and Rubric

Overview

In cybersecurity, data protec�on should be the first priority. There are two basic concepts: data at rest and data in transit. Each version of data is protected slightly differently. It may be

sufficient to protect data at rest with some type of encryp�on that is difficult to crack over a long period of �me, while the data in transit only needs to be protected un�l it gets past the

en�ty that is trying to decipher it. In either case, it is important to know what to do when a breach or incident occurs. Having a strong computer incident response team (CIRT) is a valuable

resource for any company. The premise behind incident response is to iden�fy an a�ack, contain and eradicate its effects, and minimize the risk of incident recurrence.

What is the shortest amount of �me it can take to restore the system to a safe state? The shortest amount of �me might not be the most cost-effec�ve. Therefore, the company must

priori�ze its ac�ons and make sure that in trying to fix the cyber incident, it doesn’t cause the company more harm. There are many incidents and ac�ons that the CIRT needs to be ready for,

so having a highly defined and well-prac�ced incident response plan is important for the company’s well-being. Having the proper resources, whether they are personnel or informa�on

technology related, can play a role in how fast the company recovers from the incident. Being prepared for the worst possible cases, having a strong understanding of the influences of the

confiden�ality, integrity, and availability (CIA) triad, and knowing how the company will react to those situa�ons could mean the difference between company survival or deeper

consequences, such as company closure. Having the proper CIRT is about having the right people for the job. This does not mean that all of senior management needs to be on the CIRT. This

does mean that the company must figure out what the proper makeup of the team should be. The team members must be knowledgeable in their roles as they need to be sure that the

decisions they make are in the best interests of the company.

Prompt

A�er reviewing Breach Analysis Simula�on Scenario One, address the cri�cal elements below:

I. Reflec�on on CIA and Data Protec�on

A. Select a tenet of the CIA triad and explain how the principle applies to the scenario. Jus�fy your response with details or examples from the scenario.

B. Explain the issues with Secure Sockets Layer (SSL) that facilitated its depreca�on and how Transport Layer Security (TLS) remedies those issues.

II. Incident Response Plan

A. In small organiza�ons, there typically isn’t a large membership to form the CIRT. Explain how organiza�ons with a small IT department ensure that the CIRT is prepared to handle

all possible situa�ons.

What to Submit

Your submission should be 1 to 2 pages in length. Use double spacing, 12-point Times New Roman font, and one-inch margins. All sources must be cited using APA format. Use a file name

that includes the course code, the assignment �tle, and your name—for example, CYB_123_Assignment_Firstname_Lastname.docx.



11/5/24, 11:04 AM Assignment Information

https://learn.snhu.edu/d2l/le/content/1748997/viewContent/36623161/View 1/2

Module Two Short Response Rubric

Criteria Exemplary (100%) Proficient (85%) Needs Improvement (55%) Not Evident (0%) Value

Reflec�on on CIA and Data

Protec�on: Tenet of CIA

Triad

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Selects a tenet of the CIA triad

and explains how the principle

applies to the scenario,

including details or examples

from the scenario

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

30

Reflec�on on CIA and Data

Protec�on: Issues with SSL

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Explains the issues with SSL

that facilitated its depreca�on

and how TLS remedies those

issues

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

30

Incident Response Plan:

Form the CIRT

Meets “Proficient” criteria and

addresses cri�cal element in an

excep�onally clear, insigh�ul,

sophis�cated, or crea�ve

manner

Explains how organiza�ons

with a small IT department

ensure that the CIRT is

prepared to handle all possible

situa�ons

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address cri�cal

element, or response is

irrelevant

30

Ar�cula�on of Response Submission is free of errors

related to cita�ons, grammar,

spelling, and organiza�on and

is presented in a professional

and easy-to-read format

Submission has no major errors

related to cita�ons, grammar,

spelling, or organiza�on

Submission has some errors

related to cita�ons, grammar,

spelling, or organiza�on that

nega�vely impact readability

and ar�cula�on of main ideas

Submission has cri�cal errors

related to cita�ons, grammar,

spelling, or organiza�on that

prevent understanding of ideas

10

Total: 100%

11/5/24, 11:04 AM Assignment Information

https://learn.snhu.edu/d2l/le/content/1748997/viewContent/36623161/View 2/2