Write My Paper Button

WhatsApp Widget

Write My Paper Button

WhatsApp Widget

Assignment Instructions Project 3 – Identifying and Analyzing Threats, Vulnerabilities, and Exploit  Purpose In Projects 1 and 2, you established the organizational and risk management context for the Sabine Coastal Health Network (SCH

Assignment Instructions

Project 3 – Identifying and Analyzing Threats, Vulnerabilities, and Exploit 

Purpose

In Projects 1 and 2, you established the organizational and risk management context for the Sabine Coastal Health Network (SCHN) and identified the assets and business activities that require protection.

Project 3 continues that work.

Your role is to identify and analyze the threats, vulnerabilities, and potential exploits that could affect the important assets and business activities you identified in Project 2 

The goal is not to create the longest possible list of cybersecurity problems. Your goal is to determine which threats and vulnerabilities are meaningful within SCHN’s specific operating environment and explain how they could affect the organization.

 

Your analysis must remain grounded in:

The SCHN scenario

Your decisions from Projects 1 and 2

The Project 3 scenario update

The assigned textbook chapters

SCHN’s operational, financial, technical, and organizational realities

 

You continue to serve as a cybersecurity analyst advising SCHN leadership. AI may assist you as a junior analyst, but you are responsible for evaluating its recommendations and making all final decisions.

 

Required Sources

Primary Sources: Assigned Textbook Chapters

The textbook is the primary source for this project.

Your analysis should demonstrate that you understand and can apply concepts from the following chapters of Managing Risk in Information Systems, 3rd Edition:

Chapter 2 – Managing Risk: Threats, Vulnerabilities, and Exploits

Use Chapter 2 to help distinguish and relate:

Threats

Threat sources

Vulnerabilities

Exploits

Risk

Organizational exposure

Chapter 6 – Performing a Risk Assessment

Use Chapter 6 for the broader risk-assessment context, including:

Identifying relevant risk information

Understanding organizational exposure

Connecting threats and vulnerabilities to assets and activities

Recognizing uncertainty and information gaps

 

You are not performing the complete risk assessment in this project. You will formally evaluate likelihood, impact, and overall risk in Project 4.

 

Chapter 8 – Identifying and Analyzing Threats, Vulnerabilities, and Exploits

Chapter 8 is the primary chapter for the analytical work in Project 3.

Use it to help:

Identify realistic threats

Identify vulnerabilities

Analyze potential exploits

Connect threats and vulnerabilities

Determine how weaknesses could affect organizational assets and activities

Support your prioritization of the exposures requiring further assessment

 

Source Priority

When developing your analysis:

1. Assigned textbook chapters are the primary source.

2. The SCHN scenario provides the organizational facts and conditions you must analyze.

3. NIST publications may be used as secondary supporting sources.

4. Other credible sources may provide limited additional support when necessary.

5. AI output is not a source and does not replace assigned readings.

Your work should not rely primarily on NIST publications, websites, or AI-generated explanations instead of the assigned textbook.

 

Optional NIST Secondary Sources

The following NIST Special Publications may be used to supplement the textbook.

They are secondary sources only and are not substitutes for the assigned chapters.

NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments

This is the most useful NIST secondary source for Project 3.

Students may use it for additional support related to:

Threat sources

Threat events

Vulnerabilities

Predisposing conditions

Risk-assessment information

Uncertainty within risk analysis

The threat, threat-event, and vulnerability guidance may be particularly useful when evaluating whether an exposure identified for SCHN is reasonable.

 

Do not move ahead into detailed likelihood, impact, or risk calculations. Those concepts will be addressed more directly in Project 4.

 

NIST SP 800-37 Rev. 2 – Risk Management Framework for Information Systems and Organizations

This publication may be used for additional context regarding the NIST Risk Management Framework (RMF).

For Project 3, it may help students understand how identifying threats and vulnerabilities contributes to the larger risk management process.

 

Do not attempt to complete the entire RMF or turn this project into a control-selection exercise.

NIST SP 800-61 Rev. 3 – Incident Response Recommendations and Considerations for Cybersecurity Risk Management

This publication may be useful when analyzing the Microsoft 365 security incident introduced in this project.

It may provide secondary support for understanding:

Cybersecurity incidents

Incident-related information

Organizational consequences

The relationship between incidents and cybersecurity risk management

Information that may be needed before conclusions can be reached

The purpose of using this publication is to support your analysis of the incident. You are not developing a complete incident response plan in Project 3.

 

Relationship to Projects 1 and 2

Project 3 must build directly on your previous work.

Project 1 established:

SCHN’s organizational environment

Important business functions

Technology environment

Stakeholders

Third-party dependencies

Organizational constraints

Risk management context

Project 2 identified and prioritized:

Important assets

Important business activities

Information and technology resources

Dependencies among assets and activities

Consequences if important assets or activities were compromised or unavailable

 

Project 3 asks:

What could realistically threaten those assets and activities, what weaknesses could make those threats successful, and how could those weaknesses potentially be exploited?

Use your previous work rather than starting over.

However, cybersecurity risk is not static. You may revise a conclusion from Projects 1 or 2 if the new information in this project changes a previous assumption.

If you revise a previous decision, briefly explain what changed and why.

 

Project 3 Scenario Update

Suspicious Microsoft 365 Account Activity

SCHN recently experienced a security incident involving an employee in the centralized billing office.

The employee received an email that appeared to be a Microsoft 365 security notification. The message directed the employee to a website that closely resembled the Microsoft sign-in page. The employee entered a username and password, then became suspicious and contacted the help desk.

The IT department reset the employee’s password approximately 30 minutes later.

A preliminary review identified the following:

A successful login to the employee’s Microsoft 365 account occurred from an unfamiliar Internet address shortly after the employee entered the credentials.

A new email forwarding rule had been created in the employee’s mailbox.

The employee routinely communicates by email with insurance companies, patients, healthcare partners, and other SCHN employees.

The employee has access to billing, claims, insurance, and patient-related information required to perform the job.

SCHN has not determined whether sensitive information was accessed or removed.

No evidence currently indicates that the electronic health record was accessed through the compromised account.

IT personnel are continuing to investigate.

Executive leadership wants to know whether this incident is isolated or evidence of broader exposure within SCHN.

 

Important

Do not assume that a major data breach occurred.

Do not assume that SCHN is secure simply because a breach has not been confirmed.

Treat the available information as incomplete evidence that must be analyzed.

 

Assignment

Prepare a Threat, Vulnerability, and Exploit Analysis for SCHN.

Your analysis must connect realistic threats to specific organizational assets, business activities, vulnerabilities, and potential exploitation methods.

You are expected to exercise professional judgment.

Do not simply generate a generic list of cybersecurity threats.

 

Required Sections

 

1. Project 2 Continuity and Changes

Briefly explain how this analysis builds on your Project 2 work.

Identify the 3–5 assets or business activities from Project 2 that will receive the greatest attention in this project.

For each, briefly explain why it remains important.

If the new scenario information causes you to change a priority or assumption from Project 2, identify the change and explain why.

You are not required to change your previous conclusions simply because new information was provided. Revise them only when you believe the evidence justifies doing so.

 

2. Threat Identification

Identify at least six meaningful threat scenarios that could affect the assets or business activities selected for analysis.

Your six scenarios must collectively include:

At least one threat related to the Microsoft 365 incident

At least one third-party or vendor-related threat

At least one internal or human-related threat

At least one physical or environmental threat, such as hurricane, flooding, fire, power failure, severe weather, or another condition relevant to SCHN

One threat scenario may satisfy more than one category when appropriate.

For each threat, explain:

The threat source or event

The asset or business activity affected

Why the threat is relevant to SCHN

The possible effect on confidentiality, integrity, and/or availability

Avoid generic statements such as:

“Hackers could attack the network.”

Instead, describe a realistic relationship between the threat and SCHN’s environment.

 

3. Vulnerability Analysis

For each threat scenario, identify one or more vulnerabilities or weaknesses that could allow the threat to cause harm.

Vulnerabilities may involve:

Technology

People

Processes

Configuration

Access management

Physical security

Third parties

Legacy systems

Medical devices

Remote access

Monitoring

Backup practices

Training

Documentation

Business processes

Infrastructure or facilities

Clearly distinguish a vulnerability from a threat.

For example:

Threat: Credential phishing

Potential vulnerability: Weak employee awareness or inadequate authentication

Potential exploit: Stolen credentials used to gain unauthorized account access

Whenever possible, support vulnerabilities using information from the SCHN scenario.

If you identify a reasonable vulnerability that is not specifically stated in the scenario, label it as an:

Assumption or information gap requiring verification

Do not present assumptions as established facts.

 

4. Threat–Vulnerability–Exploit Analysis Table

Create a table covering your six or more threat scenarios.

   Asset or Business Activity

Threat

Relevant Vulnerability

Potential Exploit or
Attack Path

C/I/A Affected

Potential
Organizational Consequence

Scenario Evidence or
Assumption

   Your entries should demonstrate the following relationship:

Asset/Activity → Threat → Vulnerability → Potential Exploit → Organizational Consequence

The table should summarize your analysis rather than replace your explanation.

 

5. Deeper Analysis of Three Priority Exposure Paths

Select the three threat-vulnerability combinations that you believe deserve the greatest management attention.

For each, address the following.

What is at risk?

Identify the important asset, information, system, or business activity involved.

What is the threat?

Explain the threat source or event.

What makes SCHN vulnerable?

Identify the weakness, condition, or exposure that could allow the threat to succeed.

How could the vulnerability be exploited?

Explain the plausible method or pathway through which the vulnerability could be used.

Describe the exploit conceptually. Do not provide attack code, commands, penetration-testing instructions, or detailed procedures for compromising systems.

What could happen to SCHN?

Explain realistic consequences, considering factors such as:

Patient safety

Patient care

Confidentiality

Information integrity

System availability

Regulatory responsibilities

Financial operations

Revenue

Employee productivity

Third-party relationships

Organizational reputation

Explain why the exposure matters to SCHN, rather than simply labeling it “high risk.”

 

6. Analysis of the Microsoft 365 Incident

Provide a focused analysis of the new security incident.

Address:

1.    What threat or threats are represented by the incident?

2.    What vulnerabilities may have contributed to the incident?

3.    What appears to have been successfully exploited?

4.    What additional assets or business activities could potentially be affected?

5.    What additional information should SCHN collect before determining the severity and scope of the incident?

6.    Does the incident change any assumption or priority from Projects 1 or 2? Why or why not?

 

Your analysis should clearly distinguish among:

Known

Facts directly supported by the scenario.

Reasonably Inferred

Conclusions that are supported by available evidence but are not confirmed.

Unknown

Information that SCHN would need to obtain before reaching a conclusion.

 

7. Priority Information Gaps

Identify at least three important information gaps that limit your ability to analyze SCHN’s threats and vulnerabilities.

For each:

State what information is missing.

Explain why it matters.

Explain how obtaining the information would improve the analysis.

Information gaps could involve:

Technical configurations

User permissions

Authentication requirements

Vendor practices

System inventories

Logging

Backup arrangements

Medical devices

Remote access

Physical safeguards

Security awareness practices

Do not invent missing information simply to complete your analysis.

Recognizing uncertainty is part of professional risk analysis.

 

8. Preparation for Project 4

Conclude by identifying the three threat-vulnerability combinations that should move forward into formal risk assessment in Project 4.

Briefly explain why each deserves further assessment.

At this stage, do not:

Assign formal likelihood ratings

Assign formal impact ratings

Calculate overall risk scores

Develop a complete risk matrix

Those activities belong in Project 4: Defining and Performing a Risk Assessment.

 

Applying the Assigned Readings

Simply mentioning a textbook chapter or defining terminology is not sufficient.

Your analysis should demonstrate that you can apply course concepts to SCHN.

For example, instead of writing:

“A vulnerability is a weakness that can be exploited.”

Apply the concept:

“SCHN’s inconsistent use of MFA may create a vulnerability because stolen employee credentials could provide unauthorized access to cloud services.”

The second example demonstrates application rather than definition.

The textbook should provide the primary conceptual foundation for your analysis. NIST guidance may strengthen or support your reasoning but should not replace the textbook.

 

AI Use Requirement

Continue to treat AI as a junior analyst, not the decision-maker.

AI may help you:

Identify possible threats

Generate questions about vulnerabilities

Identify relationships you may have overlooked

Challenge assumptions

Suggest alternative interpretations

Review your reasoning

Identify weaknesses in your analysis

Organize information

 

AI can easily produce long lists of generic cybersecurity threats. Your responsibility is to determine whether an AI recommendation is actually relevant to SCHN and supported by the available evidence.

Complete the same AI Prompt and Evaluation Log requirements used in Projects 1 and 2.

At least one documented interaction must show that you challenged, corrected, substantially revised, or rejected part of an AI response. AI-generated content is not a primary or secondary academic source.

What Not to Do

Do not:

Start over with a different organization.

Ignore decisions made in Projects 1 and 2.

Submit a generic list of cybersecurity threats.

Assume every possible vulnerability exists at SCHN.

Treat threats, vulnerabilities, and exploits as interchangeable.

Invent technical details without identifying them as assumptions.

Assume the Microsoft 365 incident resulted in a confirmed major data breach.

Provide detailed attack or penetration-testing procedures.

Calculate a complete risk score or risk matrix.

Develop a complete mitigation or control implementation plan.

Rely primarily on AI, NIST, or general Internet sources instead of the assigned textbook.

Accept AI-generated recommendations without evaluating their relevance to SCHN.

 

Submission Requirements

Submit one professional document containing the required Project 3 analysis.

Suggested Length

5 pages of project content

The following do not count toward the five-page maximum:

Title page

References

Threat–Vulnerability–Exploit Analysis Table

AI Prompt and Evaluation Log appendix

Formatting

Use clear headings corresponding to the required sections.

Use professional business writing.

Support your analysis primarily with the assigned textbook chapters.

Cite NIST or other secondary sources when used.

Use APA-style citations and references where appropriate.

Include the AI Prompt and Evaluation Log as an appendix.

Review your work for consistency with Projects 1 and 2 before submitting.

Primary Question to Keep in Mind

Given what SCHN values and depends upon, what realistic threats could take advantage of its weaknesses, how could that occur, and why should management care?

Your job is not to identify every possible cybersecurity problem.

Your job is to provide SCHN leadership with a focused, evidence-based, and defensible analysis of the exposures that matter most to this organization.