Tutorial 5: Capstone Security Assessment

Unit 8 ยท Governance, risk, and capstone

Objectives

A capstone assessment should be reproducible and bounded. State scope, assets, stakeholders, methods, evidence dates, limitations, and ethical permissions. Combine architecture review, threat modeling, identity and network analysis, application and data review, monitoring, response, continuity, and governance.

scope + method -> evidence -> finding severity
finding -> recommendation + owner + verification -> residual risk

Do not claim that no vulnerabilities exist. State what was assessed, what was not, confidence in findings, and what would change the conclusion. Recommendations should be sequenced into immediate containment, near-term remediation, and longer-term capability.

Exercises

  1. Create a capstone scope and evidence plan.
  2. Write one complete finding with proof and retest.
  3. Present a prioritized roadmap to technical and executive audiences.

Self-check

  1. Why state limitations?
  2. What makes a finding complete?
  3. Why sequence a roadmap?

Self-Check Quiz

1. What is the purpose of assessment scope?

AnswerTo define what was examined, under what authority and method, so conclusions are bounded and defensible.

2. What should follow a recommendation?

AnswerAn owner, priority, due date, measurable expected change, verification evidence, and residual-risk statement.

Homework

  1. Submit a complete security assessment for a chosen enterprise system.
  2. Include architecture, threats, controls, evidence, findings, roadmap, and limitations.
  3. Reflect on one trade-off and one unanswered question.
Sample answerA complete report is bounded, evidence-based, and audience-aware. It prioritizes realistic high-impact risks, recommends layered controls with owners and verification, distinguishes facts from assumptions, and states residual risks. A reflection should acknowledge cost, usability, operational burden, or uncertainty rather than presenting security as absolute.