REQUIREMENTSYour submission must be your original work. No more than a combined total of 30% of the submission and no more than a 10% match to any one individual source can be directly quoted or closely paraphrased from sources, even if cited correctly. The similarity report that is provided when you submit your task can be used as a guide. You must use the rubric to direct the creation of your submission because it provides detailed criteria that will be used to evaluate your work. Each requirement below may be evaluated by more than one rubric aspect. The rubric aspect titles may contain hyperlinks to relevant portions of the course. sks may not be submitted as cloud links, such as links to Google Docs, Google Slides, OneDrive, etc., unless specified in the task requirements. All other submissions must be file types that are uploaded and submitted as attachments (e.g., .docx, .pdf, .ppt).A. Describe the consensus-based policies developed for the solution to your cybersecurity problem, including standards and practices that were adopted to facilitate implementation of the solution and a description of the cybersecurity problem being addressed.1. Summarize how the solution supports decision-making capabilities and the needs of the environment where the solution was implemented.B. Describe how your solution meets the following cybersecurity assurance criteria: promotes automation in cybersecurity improves and modernizes security implements industry-standard security tools and infrastructure or environmentC. Explain how your solution addresses the following data collection and implementation elements: collects digital evidence, including data for analysis or forensics implements confidentiality, integrity, and availabilityD. Explain how your solution investigates and mitigates cybersecurity incidents and crimes within the environment where the solution was implemented.E. Describe the cybersecurity plans, standards, or procedures that were developed for the solution.1. Explain how the solution is aligned with cybersecurity initiatives or regulatory compliance in the environment where the solution was implemented.2. Summarize the applications, source code, executable files, tools, installation guides, or user guides developed in conjunction with the solution.F. Discuss the post-implementation environment, including new systems implemented, new processes developed, or network diagrams created demonstrating the new infrastructure.1. Describe the efficiency of the solution.2. Analyze the new data (e.g., new reports, logs, processes in place) collected, including how the solution will impact business processes.3. Describe the summative evaluation plan, including a plan of action and milestones.a. Describe any control deficiency analysis resulting from your testing plan. Or if a controlled deficiency analysis was not required, explain why.4. Discuss post-implementation risks, including their likelihood, organizational impact, and mitigation.5. Explain how the security solution meets each of the project stakeholder needs, including a description of the stakeholder needs.a. Analyze how the changes resulting from the new solution affect stakeholders. G. Describe the post-implementation maintenance plan for the solution.H. Describe the cybersecurity domain from the attached “List of Cybersecurity Domains” that your solution addresses.I. Provide one original artifact (e.g., security policy, procedure, network diagram) of the completed project.J. Acknowledge sources, using in-text citations and references, for content that is quoted, paraphrased, or summarized.K. Demonstrate professional communication in the content and presentation of your submission.TMM3: Technology-Supported Security Solution
List of Cybersecurity Domains
Domain: Cyber Risk Management and Oversight
– organization chart
– cybersecurity-related policies and procedures
– strategic plans
– cybersecurity job descriptions
– cybersecurity personnel qualifications
– risk assessments
– data loss prevention analysis
– IT audit schedule
– IT audit reports and correspondence
– audit exception tracking
– risk management reports
– cybersecurity training policies and procedures
– cybersecurity training and awareness materials
Domain: Cybersecurity Controls
– list of physical access controls (e.g., key cards, biometric controls, video cameras)
– baseline security configuration standards
– vulnerability or patch management policies and procedures
– patch management reports
– penetration test results and reports
– vulnerability assessments
– continuous monitoring strategy
Domain: External Dependency Management
– list of third parties and subcontractors
– contracts governing all third-party relationships
– inventory of all third-party connections
– network topology/diagram
– independent reports on the service provider’s security controls
– remote access logs
– third-party employee access reviews
– vendor management policies and procedures
Domain: Threat Intelligence and Collaboration
– list of threat intelligence resources (e.g., industry groups, consortiums, threat and
vulnerability reporting services)
– management reports on cyber intelligence
Domain: Cyber Resilience
– cybersecurity event log and reports on cyber incidents
– business impact analysis
– business or corporate continuity plan
– results of resilience testing
– resilience testing reports
– cyber incident response plans
– crisis management plans
TMM3: Technology-Supported Security Solution
– data loss prevention analysis
– continuous monitoring strategy
