Synthesize threat, architecture, identity, data, and response analysis.
Make defensible recommendations under constraints.
Communicate technical risk to different audiences.
A case study is an opportunity to connect control layers. Begin with business objectives and assets, then model actors, data flows, trust boundaries, threats, existing controls, gaps, and residual risk. Recommendations should be feasible, owned, prioritized, and verifiable.
business goal -> asset and impact -> threat path
-> control options -> cost and residual risk -> decision
Executives need impact, exposure, options, cost, and decision requests. Engineers need flows, configuration, tests, dependencies, and runbooks. A credible report serves both without hiding uncertainty or pretending that one control solves a systemic risk.
Exercises
Analyze a breached enterprise portal.
Map findings to owners and controls.
Write executive and technical summaries of the same risk.
Self-check
What makes a recommendation defensible?
Why use different audiences?
What is residual risk?
Self-Check Quiz
1. What should come before choosing controls?
AnswerUnderstand business objectives, assets, threats, impact, existing controls, and constraints.
2. What makes a control verifiable?
AnswerIt has a clear owner, measurable expected behavior, evidence source, and test or review method.
Homework
Write a security assessment for a fictional enterprise portal.
Include data flows, threat model, prioritized findings, and roadmap.
Produce both executive and technical summaries.
Sample answerA strong assessment connects a high-impact asset to a realistic attack path, shows why current controls fail, recommends layered changes with owners and dates, and defines retests. The executive summary emphasizes business impact and decisions; the technical section supplies flows, policy, configuration, and evidence.