Tutorial 4: Enterprise Security Case Study

Unit 8 ยท Governance, risk, and capstone

Objectives

A case study is an opportunity to connect control layers. Begin with business objectives and assets, then model actors, data flows, trust boundaries, threats, existing controls, gaps, and residual risk. Recommendations should be feasible, owned, prioritized, and verifiable.

business goal -> asset and impact -> threat path
-> control options -> cost and residual risk -> decision

Executives need impact, exposure, options, cost, and decision requests. Engineers need flows, configuration, tests, dependencies, and runbooks. A credible report serves both without hiding uncertainty or pretending that one control solves a systemic risk.

Exercises

  1. Analyze a breached enterprise portal.
  2. Map findings to owners and controls.
  3. Write executive and technical summaries of the same risk.

Self-check

  1. What makes a recommendation defensible?
  2. Why use different audiences?
  3. What is residual risk?

Self-Check Quiz

1. What should come before choosing controls?

AnswerUnderstand business objectives, assets, threats, impact, existing controls, and constraints.

2. What makes a control verifiable?

AnswerIt has a clear owner, measurable expected behavior, evidence source, and test or review method.

Homework

  1. Write a security assessment for a fictional enterprise portal.
  2. Include data flows, threat model, prioritized findings, and roadmap.
  3. Produce both executive and technical summaries.
Sample answerA strong assessment connects a high-impact asset to a realistic attack path, shows why current controls fail, recommends layered changes with owners and dates, and defines retests. The executive summary emphasizes business impact and decisions; the technical section supplies flows, policy, configuration, and evidence.