Describe the major components of cyber security architecture.

Attached
Associated Learning Objectives
2.4.1: Articulate clearly and fairly others’ alternative viewpoints and the basis of reasoning.
Assessment Method: Score on Criteria – 2.4: Consider and analyze information in context to the issue or problem.
Required Performance: Meets Performance Requirements
2.4.2: Identify significant, potential implications, and consequences of alternative points of view.
Assessment Method: Score on Criteria – 2.4: Consider and analyze information in context to the issue or problem.
Required Performance: Meets Performance Requirements
2.4.3: Evaluate assumptions underlying other analytical viewpoints, conclusions, and/or solutions.
Assessment Method: Score on Criteria – 2.4: Consider and analyze information in context to the issue or problem.
Required Performance: Meets Performance Requirements
5.2.1: Describes the major components of cyber security architecture.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.2: Identifies local hardware, software and telecommunications components.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.3: Follows policies, standards, and procedures.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.4: Interprets and uses IT security architectural guidelines.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.5: Describes IT security architectural initiatives and specifications for own area.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.6: Describes technical standards and procedures that affect own area.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.7: Interprets policy and standards documentation.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.8: Identifies IT security architecture issues and considerations for applicability and risk.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.9: Applies appropriate security standards and procedures relevant to an organization’s unique set of requirements.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.10: Uses existing and evolving technology standards to improve the consistency of organization’s IT efforts.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.11: Keeps abreast of emerging IT security architecture technologies and potential security implications.
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.2.12: Knowledge of security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
Assessment Method: Score on Criteria – 5.2: Knowledge of architectural methodologies used in the design and development of information systems and knowledge of standards that either are compliant with or derived from established standards or guidelines.
Required Performance: Meets Performance Requirements
5.3.1: Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.2: Conduct research, analysis and correlation across a wide variety of all source data sets (indications and warnings)
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.3: Determine appropriate course of action in response to identified and analyzed anomalous network activity
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.4: Employ approved Defense-in-Depth principles and practices (i.e., Defense in Multiple Places, Layered defenses, Security robustness, etc.)
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.5: Examine network topologies to understand data flows through the network.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.6: Identify applications and operating systems of a network device based on network traffic.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.7: Identify network mapping and operating system (OS) fingerprinting activities.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.8: Monitor external data sources to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.9: Perform Computer Network Defense trend analysis and reporting.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.10: Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.11: Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.12: Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.13: Recommend computing environment vulnerability corrections.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.14: Reconstruct a malicious attack or activity based off network traffic.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
5.3.15: Knowledge of the application firewall concepts and functions.
Assessment Method: Score on Criteria – 5.3: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Required Performance: Meets Performance Requirements
7.2.1: Demonstrate ability to identify threats/risks and vulnerabilities taking into account the frequency, probability, speed of development, severity and reputational impact to achieve a holistic view of risk across the entity.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.2: Demonstrate ability to classify risks according to relevant criteria including, but not limited to: risks under the entity’s control, risks beyond the entity’s control, risks with prior warnings, and risks with no prior warnings.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.3: Demonstrate ability to identify the organization’s risk exposures from both internal and external sources.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.4: Explain the proper use of penetration testing and vulnerability scanning for vulnerability assessments.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.5: Explain the impact of penetration testing and vulnerability scanning on OT systems and know when to use such techniques.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.6: Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.7: Knowledge of penetration testing principles, tools, and techniques (e.g., metasploit, neosploit).
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.8: Knowledge of system and application security threats and vulnerabilities.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.9: Knowledge of penetration testing principles, tools, and techniques (e.g., metasploit, neosploit).
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.10: Skill in utilizing exploitation tools (e.g., Foundstone, fuzzers, packet sniffers, debug) to identify system/software vulnerabilities (e.g., penetration and testing).
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.11: Skill in utilizing network analysis tools to identify software communications vulnerabilities.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements
7.2.12: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
Assessment Method: Score on Criteria – 7.2: Includes the process of identifying, quantifying, and prioritizing the vulnerabilities in a system. Vulnerability from the perspective of disaster management includes assessing the threats from potential hazards to the population & to infrastructure.
Required Performance: Meets Performance Requirements

Last Completed Projects

topic title academic level Writer delivered