You are the Lead Cybersecurity Architect for the newly formed
department of Cybersecurity and Compliance (CSAC) within a university.
In 2020, University discovered a serious cyber-attack. There was a
Supply Chain Attack as advised by a trusted intel, in a coding library
which is used in creation of LMS (Learning Management system)portal.
The Senior Management Executive Committee has recently earmarked funding
to implement an enterprise-wide cybersecurity program that aligns to the
NIST (National Institute of Standards and Technology) Cybersecurity Framework.
As the lead Cybersecurity Architect, you have been asked to develop a cybersecurity
program for the university and present your strategy for detection, containing and
removal of the malware as well as your implementation and execution roadmap to the
Executive Committee (EC). It should also be noted that its Registration time of the year,
therefore LMS portal is in active use and cannot be shut down, as students are entering
sensitive information as their address, mobile number and bank account.
You are part of a cybersecurity team comprised of a risk analyst, three cybersecurity
analysts and a coop student. The university has multiple lines of business and academic
programs. University has multiple campuses including international offices. University
has domestic students as well as international students.
Note:
Note that your target audience is the Executive Management of the Enterprise