Project 3

profileMoona26
ProjectThreeGuidelinesandRubric-CYB-260-12259-M01LegalandHumanFactorsofCyb2025C-1Jan-Mar.pdf

CYB 260 Project Three Guidelines and Rubric

Service Level Agreement Requirement Recommendations

Overview

Once security requirements have been defined, an organization must have a way to ensure that these requirements are satisfied. Security controls are safeguards or countermeasures that

organizations implement to protect all types of assets (data, physical, personnel, and so on) from threats to confidentiality, integrity, or availability. Trade groups such as the Center for

Internet Security (CIS), the International Organization for Standardization (ISO), and the National Institute of Standards and Technology (NIST) provide collections of security controls

intended to address critical areas of cybersecurity concern. However, these guidelines provide different levels of detail, vary in prescriptiveness, and apply to different industries and

organizational structures. Ultimately, each organization must determine how to best implement security controls to meet their expectations for asset protection. As such, the security

practitioner must select, design, implement, and manage the policies, procedures, standards, and guidelines designed to implement these controls.

In the milestone assignment for this project, you examined employee training as a control measure to reduce the incidents and effects of social engineering. As you saw, training is a key

method for incorporating security best practices. However, it is not the only type of control measure that cybersecurity professionals rely on. Incorporate instructor feedback you received on

the milestone as you envision a more comprehensive approach to security controls at an organization.

In this project, you will analyze requirements, select appropriate security controls, and specify methods to implement your selected controls to satisfy the requirements. You will demonstrate

your mastery of the following course competency:

Design security controls and practices for humans in the system

Scenario

Use the Project Three Scenario to complete this assignment. This scenario places you in the role of a security consultant for an organization. The scenario includes additional requirements

related to the proposal you addressed in Projects One and Two.

To complete this project, review the following documents:

Service Level Agreement

CIS Controls, Version 8

To complete this task, you will prepare service level agreement requirement recommendations for the internal stakeholder board identifying an approach to meeting the requirements in the

scenario.



2/18/25, 12:56 PM Assignment Information

https://learn.snhu.edu/d2l/le/content/1831858/viewContent/38649355/View 1/3

Prompt

Prepare a brief that outlines the requirement recommendations for the service level agreement and describes your approach to meeting the requirements of the scenario. You must address

the following critical elements:

I. Select two controls that address the requirements of the scenario.

A. Control One: Justify how your selected control type (i.e., policy, standard, procedure, or guideline) and implementation will meet the requirements.

B. Control Two: Justify how your selected control type (i.e., policy, standard, procedure, or guideline) and implementation will meet the requirements.

II. Describe the necessity for a training program to address a specific social engineering threat.

III. Describe the expected outcomes of a training program that addresses the social engineering threat you identified in the previous critical element.

What to Submit

Your submission should be 1 to 3 pages in length and use double spacing, 12-point Times New Roman font, and one-inch margins. Sources should be cited according to APA style. Use a file

name that includes the course code, the assignment title, and your name—for example, CYB_260_Project_One_Neo_Anderson.docx.

Project Three Rubric

Criteria Exemplary (100%) Proficient (85%) Needs Improvement (55%) Not Evident (0%) Value

Control One Meets “Proficient” criteria and

addresses critical element in an

exceptionally clear, insightful,

sophisticated, or creative

manner

Justifies how the selected

control type and

implementation will meet the

requirements

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address critical

element, or response is

irrelevant

23

Control Two Meets “Proficient” criteria and

addresses critical element in an

exceptionally clear, insightful,

sophisticated, or creative

manner

Justifies how the selected

control type and

implementation will meet the

requirements

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address critical

element, or response is

irrelevant

23

Necessity for a Training

Program

Meets “Proficient” criteria and

addresses critical element in an

exceptionally clear, insightful,

sophisticated, or creative

manner

Describes the necessity for a

training program to address a

specific social engineering

threat

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address critical

element, or response is

irrelevant

23

2/18/25, 12:56 PM Assignment Information

https://learn.snhu.edu/d2l/le/content/1831858/viewContent/38649355/View 2/3

Criteria Exemplary (100%) Proficient (85%) Needs Improvement (55%) Not Evident (0%) Value

Expected Outcomes of a

Training Program

Meets “Proficient” criteria and

addresses critical element in an

exceptionally clear, insightful,

sophisticated, or creative

manner

Describes the expected

outcomes of a training program

that addresses the identified

social engineering threat

Addresses “Proficient” criteria,

but there are gaps in clarity,

logic, or detail

Does not address critical

element, or response is

irrelevant

23

Articulation of Response Submission is free of errors

related to grammar, spelling,

and organization and is

presented in a professional and

easy-to-read format

Submission has no major errors

related to grammar, spelling, or

organization

Submission has some errors

related to grammar, spelling, or

organization that negatively

impact readability and

articulation of main ideas

Submission has critical errors

related to grammar, spelling, or

organization that prevent

understanding of ideas

8

Total: 100%

2/18/25, 12:56 PM Assignment Information

https://learn.snhu.edu/d2l/le/content/1831858/viewContent/38649355/View 3/3