MIS761 Cyber Security Strategies Trimester 2 2025

联系我们: 手动添加方式: 微信>添加朋友>企业微信联系人>13262280223 或者 QQ: 1483266981

MIS761 Cyber Security Strategies
Trimester 2 2025

Final Assessment Task – End of Unit Assessment

Case Study
HarbourLight Facilities is a small-to-medium building services company (~220 staff) that maintains heating, ventilation, and air conditioning (HVAC), lighting and access-control systems for office parks and light industrial sites across NSW. Most customers are long-term contracts; technicians work on rotating shifts and drive company vans with rugged tablets for job dispatch, notes and photo uploads. The firm runs a modest cloud stack: a customer portal for work requests, a scheduling database that allocates jobs and stores contact details, and a lightweight data warehouse used for monthly service dashboards. Collaboration happens in Microsoft 365; a simple service desk and an e-mail phishing-report add-in are deployed.
The culture is commercial and practical: deliver on time, keep sites running, and don’t overcomplicate tooling. Budgets are quarterly; management talks about “being dependable” and “not bogging down field teams.” Process maturity is uneven—some documents are up to date, others live in shared drives. Security has two people in IT Ops who also wear general sysadmin hats. Awareness modules are short and mostly self-paced; participation varies by crew and shift.
Two recent events are front of mind. First, a junior scheduler exported a customer-contact CSV for a mailing and placed it in a shared cloud folder with a “anyone with the link” permission. The link was later forwarded to a subcontractor distribution list. IT Ops discovered external access in the folder log and disabled the link; no ransomware or obvious misuse is known, but external parties could have viewed names, work e-mails and phone numbers for facilities contacts at several client sites. The exec team is debating how to notify and how formal any notifications must be.
Second, the customer portal intermittently slows during local radio ads and after supplier webinars. Sometimes logs show many near-identical requests; other times the portal is fine but a handful of monitoring nodes in the cloud spike CPU without matching traffic. Ops wants clearer guidance on what’s likely going on and how to approach it.
There are also some ongoing business threads that may or may not matter: a fleet-tablet refresh later this year; a possible partnership with a property-management association; a marketing pilot with a neighborhood business forum; and a proposal to send seasonal tips to former job-quote contacts. Meanwhile, the company is tidying its internal security documents after a restructure—there’s a high-level security charter, several policies under revision, and a patchwork of standards.
Assume Australian law applies. Any numbers, tables, or specific draft wordings you need will appear inside the questions.
Question 1 [21 Marks]
a.Following the customer-contact CSV incident described above (shared via “anyone with the link” and accessed externally), would simply posting a short notice on a rarely visited web page for 30 days with no direct contact to affected contacts satisfy Australia’s Notifiable Data Breaches (NDB) scheme Explain why / why not, and state what must be changed.
[9 Marks]

b.Match the following four items (A–D) to Charter / Policy / Standard (or Procedure) and give a one-sentence justification for each.
[7 Marks]

Item Internal document layer — Charter / Policy / Standard (or Procedure) Justification
A. One-page executive statement setting security intent and risk posture for the company
B. Binding statement: the company will meet NDB obligations; names accountable roles
C. Step-by-step checklist for preparing and lodging notifications, with required fields
D. Version control, owner and annual review cadence for the breach-handling documents

c.HarbourLight’s marketing team wants to send promo e-mails to business cards collected at a local trades expo (attendees dropped cards in a bowl for a prize draw run by the expo organiser). The team plans to e-mail those contacts about HarbourLight services. Is this compliant with APP 7 (Direct Marketing) Why / why not
[5 Marks]

Question 2 [32 Marks]
a.Read the draft risk-appetite statement below. Using the “Characteristics of a Well-Defined Risk Appetite” checklist, decide whether it is well-defined (justify with at least three characteristics) and propose two concrete modification that would improve it.
“Cyber risks must be kept as low as possible at all times. All systems should be always up, and security work should never impact delivery timelines. We will achieve this within existing budgets.”
[11 Marks]

b.HarbourLight is evaluating the financial impact of different security risks and the cost-effectiveness of various safeguards. Use the following data to perform a Cost-Benefit Analysis (CBA) for three different assets.
Fill in all 18 blank cells of SLE, ALE, and CBA in the table. There is no need to show the calculation process.
[12 Marks]

Use the following formulas for the calculations
SLE = AV × EF
ALE = SLE × ARO
CBA = ALE (pre-control) – ALE (post-control) – ACS
Assets and Threat Data:
Asset Asset Value (AV) Exposure Factor (EF) Single Loss Expectancy (SLE) Annualized Rate of Occurrence (ARO) Annualized Loss Expectancy (ALE) (Pre-control)
A1 Job-Scheduling Database $200,000 50% 0.4
A2 Customer Portal $300,000 30% 0.5
A3 Fleet Tablets $150,000 40% 0.3

Candidate safeguards:
Safeguard Asset Annualized Cost of Safeguard (ACS) EF (Post-control) ARO (Post-control) ALE (Post-control) CBA
S1: Role-based access + tighter sharing A1 $15,000 45% 0.2
S2: Per-record masking in exports A1 $20,000 25% 0.3
S1: Basic WAF rules A2 $25,000 20% 0.45
S2: CDN caching + autoscale tweaks A2 $30,000 15% 0.4
S1: MDM with device encryption A3 $10,000 30% 0.15
S2: App whitelisting A3 $8,000 25% 0.2

c.For each asset (A1, A2, A3), choose one treatment: Reduce / Transfer / Accept / Avoid. State your choice and justify it using your CBA results. If you choose Reduce, you must also select S1 or S2 for that asset and justify why that safeguard.
[9 Marks]

Question 3 [26 Marks]
a.The IT team proposes the following sign-in method for the customer portal: users enter a password, then answer a security question, then enter a 4-digit PIN. For each of the three checks, identify the factor type (knowledge / possession / inherence), decide whether this setup is truly multi-factor, and suggest a change to make it stronger—explain briefly.
[7 Marks]

b.HarbourLight’s reporting workflow uses two companion files, Key A and Key B. Before sending monthly maintenance PDFs to a council, the reports team runs a tool that adds a tamper-evident stamp to each PDF using Key A. The council runs a separate tool that checks the stamp on received PDFs using Key B.
(i) Is this arrangement using symmetric or asymmetric cryptography
(ii) In this story, which file is the one meant to be shared widely, and which file must be kept secret Name each file and its intended handling.
[6 Marks]

c.Below are four activities in HarbourLight’s account lifecycle (1–4), listed out of order. For each activity, choose which concept it represents: Identification / Identity verification / Authentication / Authorization. Give a one-sentence explanation for each choice.
[8 Marks]

Activities Represents Explanation
A scheduler checks the ABN and official business name of a new subcontractor with a government lookup before creating a vendor record.
A field technician enters a username and one-time code to get into the job-dispatch app.
Finance grants a vendor-portal role that lets a subcontractor submit invoices but not view other vendors’ invoices.
A subcontractor provides the company name and contact e-mail on the self-service portal’s first screen.

d.During a local radio ad, the customer portal receives a surge of near-identical requests from many sources and becomes sluggish. Separately, a few cloud monitoring nodes show prolonged high CPU with normal inbound traffic patterns. Which threat covered in topic “Cyber Threats” best fits the surge of near-identical requests Then, for that threat, state the attacker’s goal and describe one mitigation approach.
[5 Marks]

Question 4. [21 Marks]
a.HarbourLight’s awareness programme faces: crews who share tablets across shifts, some managers who think simulations “cause ticket noise,” contractors who rotate frequently, and field teams who feel modules are too desktop-centric. Pick any three issues and, for each, (i) name one relevant Week 3 lecture concept and (ii) give a 2–3 sentence application to HarbourLight.
[9 Marks]

b.HarbourLight already uses an Outlook “Report Phish” button that sends artefacts to the security team’s intake queue. A university researcher proposes adding a second, separate button for an experiment. From an incident-response viewpoint, is introducing another reporting channel appropriate Why / why not
[6 Marks]

c.Field staff sometimes screenshot suspicious SMS on their tablets and share them in an open group chat that includes subcontractors, instead of using the official reporting function. Identify the main CIA attribute(s) at risk, identify the threat and the vulnerability in this scenario, and propose one corrective control.
[6 Marks]

发表评论

了解 KJESSAY历史案例 的更多信息

立即订阅以继续阅读并访问完整档案。

继续阅读