|
Address of critical areas
|
17 points
Ensured the plan policy thoroughly addressed each of the following critical areas:
Identify threats and vulnerabilities.
Assign appropriate security controls to protect the infrastructure of the organization.
Prepare vulnerability scans and effective risk management protocols to ensure protections remain current and effective and detect any issues.
Initiate an incident response plan for responding to problems.
Develop a business continuity and disaster recovery plan to recover from interruptions in business whether manmade or geographical.
|
13 points
Plan policy provides good coverage of the following critical areas:
Identify threats and vulnerabilities.
Assign appropriate security controls to protect the infrastructure of the organization.
Prepare vulnerability scans and effective risk management protocols to ensure protections remain current and effective and detect any issues.
Initiate an incident response plan for responding to problems.
Develop a business continuity and disaster recovery plan to recover from interruptions in business whether manmade or geographical.
|
10 points
Plan policy provides fair coverage of the following critical areas:
Identify threats and vulnerabilities.
Assign appropriate security controls to protect the infrastructure of the organization.
Prepare vulnerability scans and effective risk management protocols to ensure protections remain current and effective and detect any issues.
Initiate an incident response plan for responding to problems.
Develop a business continuity and disaster recovery plan to recover from interruptions in business whether manmade or geographical.
|
6 points
Plan policy provides poor coverage of the following critical areas:
Identify threats and vulnerabilities.
Assign appropriate security controls to protect the infrastructure of the organization.
Prepare vulnerability scans and effective risk management protocols to ensure protections remain current and effective and detect any issues.
Initiate an incident response plan for responding to problems.
Develop a business continuity and disaster recovery plan to recover from interruptions in business whether manmade or geographical.
|
3 points
Plan policy provides inadequate coverage of the following critical areas:
Identify threats and vulnerabilities.
Assign appropriate security controls to protect the infrastructure of the organization.
Prepare vulnerability scans and effective risk management protocols to ensure protections remain current and effective and detect any issues.
Initiate an incident response plan for responding to problems.
Develop a business continuity and disaster recovery plan to recover from interruptions in business whether manmade or geographical.
|
0 points
Not included or no submission.
|
|
Explanation of functionality
|
17 points
Identified and thoroughly explained the functionality of the Framework Tiers.
|
13 points
Each tier was adequately explained and purpose defined for functionality of the Framework Tiers.
|
10 points
Tiers were explained and purpose described without full functionality coverage of the Framework Tiers.
|
6 points
Overview of the tiers was provided and the tiers were explained with some description of the functionality of the Framework Tiers.
|
3 points
Inadequate description of the tiers with poor description of the functionality of the Framework Tiers.
|
0 points
Not included or no submission
|
|
Use of Framework Outline
|
17 points
Excellent use of the Framework Outline to establish criteria for security control selection and inclusion of this analysis in the planning policy document.
|
13 points
Outstanding use of the Framework Outline to establish criteria for security control selection and inclusion of this analysis in the planning policy document. No more than 1 element was missing or inadequately addressed.
|
10 points
Acceptable use of the Framework Outline to establish criteria for security control selection and inclusion of this analysis in the planning policy document. No more than 2 elements were missing or inadequately addressed.
|
6 points
Fair use of the Framework Outline to establish criteria for security control selection and inclusion of this analysis in the planning policy document. More than 2 elements were missing or inadequately addressed.
|
3 points
Poor use of the Framework Outline to establish criteria for security control selection and inclusion of this analysis in the planning policy document.
|
0 points
Not included or no submission
|
|
Creation of correlation
|
17 points
Created a well-defined correlation between the cybersecurity framework and risk management for your enterprise planning policy.
|
13 points
Developed a cause and effect between the cybersecurity framework and risk management for your enterprise planning policy.
|
10 points
Established a good relationship between the cybersecurity framework and risk management for your enterprise planning policy.
|
6 points
Defined a fair relationship between the cybersecurity framework and risk management for your enterprise planning policy.
|
3 points
No defined relationship between the cybersecurity framework and risk management for your enterprise planning policy.
|
0 points
Not included or no submission
|
|
Excerpt on Risk Management
|
17 points
Provided an excellent, efficient and relevant excerpt on risk management that included a clear and concise protocol for mitigating disasters.
|
13 points
Included an outstanding excerpt on risk management that included a well defined protocol for mitigating disasters.
|
10 points
Developed an acceptable excerpt on risk management that included a protocol for mitigating disasters.
|
6 points
Incomplete submission for providing an excerpt on risk management that included a protocol for mitigating disasters. Protocol was incomplete and/or missing minor points.
|
3 points
Insufficient information to establish an excerpt on risk management that included a protocol for mitigating disasters.
|
0 points
Not included or no submission
|
|
Grammar, Spelling, Punctuation
|
15 points
Fully complied with formatting requirements.
Successfully completed all procedures in the assignment.
Exceptional quality of the assignment with clear, concise, and meaningful content.
Appropriate research conducted when necessary and resolution of the task.
Content contained relevant citations to an accuracy of 90%.
Reference citations were in the reference/bibliography list.
|
12 points
Complied with formatting requirements.
Completed all procedures in the assignment. Good quality of the assignment with clear, concise, and meaningful content.
Research conducted when necessary and attempts at resolution included for the task.
Content contained relevant citations to an accuracy of 80%
Reference citations were in the reference/bibliography list.
|
9 points
Partially complied with formatting requirements.
Partially completed the assignment.
Average quality of the assignment with clear, concise, and meaningful content.
Research attempted and resolution is incomplete.
Content contained relevant citations to an accuracy of 70%
Reference citations were in the reference/bibliography list.
|
6 points
Did not meet criteria for formatting requirements.
Assignment is incomplete.
Poor quality of the assignment and inadequate content.
No research attempted and problem not fully resolved.
Content contained relevant citations to an accuracy of 60%
Reference citations were in the reference/bibliography list.
|
3 points
Did not adhere to formatting requirements.
Criteria for assignment not met.
Poor quality of the assignment and incomplete content.
No research attempted and problem not addressed.
Content contained relevant citations to an accuracy of below 60%
Reference citations were in the reference/bibliography list
|
0 points
Not included or no submission
|