Produce an evidence-based enterprise security assessment.
Defend scope, assumptions, methods, and recommendations.
Reflect on residual risk and future work.
A capstone assessment should be reproducible and bounded. State scope, assets, stakeholders, methods, evidence dates, limitations, and ethical permissions. Combine architecture review, threat modeling, identity and network analysis, application and data review, monitoring, response, continuity, and governance.
Do not claim that no vulnerabilities exist. State what was assessed, what was not, confidence in findings, and what would change the conclusion. Recommendations should be sequenced into immediate containment, near-term remediation, and longer-term capability.
Exercises
Create a capstone scope and evidence plan.
Write one complete finding with proof and retest.
Present a prioritized roadmap to technical and executive audiences.
Self-check
Why state limitations?
What makes a finding complete?
Why sequence a roadmap?
Self-Check Quiz
1. What is the purpose of assessment scope?
AnswerTo define what was examined, under what authority and method, so conclusions are bounded and defensible.
2. What should follow a recommendation?
AnswerAn owner, priority, due date, measurable expected change, verification evidence, and residual-risk statement.
Homework
Submit a complete security assessment for a chosen enterprise system.
Include architecture, threats, controls, evidence, findings, roadmap, and limitations.
Reflect on one trade-off and one unanswered question.
Sample answerA complete report is bounded, evidence-based, and audience-aware. It prioritizes realistic high-impact risks, recommends layered controls with owners and verification, distinguishes facts from assumptions, and states residual risks. A reflection should acknowledge cost, usability, operational burden, or uncertainty rather than presenting security as absolute.