A real-world case study is given to students “Critical Controls that Sony Should Have Implemented”
June 12th, 2020
CSF 4003 Case Study Two
A real-world case study is given to students “Critical Controls that Sony Should Have Implemented”. Each team should read and understand the case study and provide detailed answers in their own words on the following questions.
- Provide a brief summary of the Case?
- Recommend at least five critical controls from the 20 CSCs, then justify and discuss the reason for your choice. For each control, recommend two sub-controls.
- Assess the severity of the cybersecurity breach and discuss how significant the impact (short, and long-term) might be to the company.
- Discuss five security issues the company was facing prior to the breach.
- If you have a low budget for implementing security system, which security tools will you use? Explain pros and cons.
- For each security issue identified in Q4, recommend two suitable security tools. Then, link each tool with proper risk decision (defense, transference, mitigation, acceptance, termination).
- What role should Senior Management play in assessing risks and implementing controls?
- Summarize lessons learned from this incident.
Report Requirements
1. MS Word report with 1000 words.
2. Font: Times New Roman, size 12.
3. APA referencing with in-text references and a “references” page.
4. Max of two students per team.
5. Signed
cover sheet
| Deliverables and Marking | ||
| 10 = Excellent, 8 = Very good, 6 = Satisfactory, 4 = Not very good, 2 = Poor | ||
| A Summary of the case | /5 | |
| Recommend five controls | /10 | |
| Assess the severity of the cybersecurity breach | /10 | |
| Discuss security issues | /10 | |
| Security budget recommended tools | /15 | |
| Suitable security tools and proper risk decision | /10 | |
| Senior Management role in risk and controls | /10 | |
| Lessons learned from incident | /10 | |
| Language/Grammar and Format (APA) | /5 | |
| /85 | ||
| Total Mark |