nounew
Project 1: Final Vulnerability Assessment Report
Maria Sosa is depending on you, the chief information security officer at your organization, to provide her and other executive-level stockholders with a final vulnerability assessment report. This thorough report should be presented with your findings and recommendations.
Final Vulnerability Assessment Report (seven- to 10-page report using this template: Assignment 7, Steps 11 and 12) This report should include the following components:
· Title Page
· Include:
· for whom you are preparing the document, the title, the date prepared, and your name as the preparer of the document
· Table of Contents
· with all sections
· Overview (introduction and purpose)
· Include mission-critical aspects of current organizational processes:
· personnel
· physical security
· network security
· cybersecurity tools and processes
· Scope of Work (one-page report: Assignment 1, Steps 1 and 2)
· Identify the elements that will be assessed within the organization for this assessment. Discuss items such as the type of network/system, what elements you'll assess (network, applications, web dmz, databases, physical security, personnel security, etc).
· Work Breakdown Structure (spreadsheet: Assignment 2, Step 3)
· Provide a breakdown of the major actions to be performed in the assessment
· Should cover pre-assessment, assessment, and post-assessment activities
· Include key elements that need to be tested and analyzed
· State how each element will be assessed (Examine, Interview or Test)
· See https://www.projectmanagementdocs.com/template/project-planning/work-breakdown-structure/#axzz69vGBl6bh for a good example of a WBS.
· Network Analysis Tools Report (one- to two-page report: Assignment 4, Step 7)
· Description of the tools and methods that were utilized in the assessment.
· Vulnerability Assessment Methodology
· Discuss how you classified risks (3x3 risk matrix, etc.)
· Provide an intro to this section prior to the tables
· Use the Vulnerability/Threat/Risk Matrix table (new table for each identified weakness)
· description of threats and vulnerabilities
· classifications of threats, vulnerabilities, and risk along with priority (all of these should be in a low/moderate/high format)
· description of remediation action along with cost
· Provide additional information after the tables pertaining to the findings as needed.
· Lessons Learned Report (two- to three-page report: Assignment 6, Steps 9 and 10)
· This is Lessons Learned on the Assessment process, not on the system security
· consider the report’s approach including:
· factors
· assessment completion
· next steps
· other issues to address