Case Study Gotham City Electrical Distribution Center (GCEDC)
Budget: $10 – $30 USD
Review GCEDC's environment and the documentation provided by GCEDC.
If deemed necessary, requests (and even maybe obtain) additional information and documentation from GCEDC. Fair warning: do not make blind assumptions.
Analyze the business and technical requirements for the Enterprise security infrastructure.
Research manufacturer’s product lines and equipment has to be used in the design.
Perform a high-level risk assessment and present a risk and threat assessment report as part of the main design report or as a separate document.
Based on the risk assessment and research, perform the detailed design of the security infrastructure. This will include recommendations to mitigate any risk in the existing environment and the documentation of security policy improvements for the corporation.
Document the design and propose an implementation plan for the new security infrastructure.
Deliver the design and formally present it to the customer.
Consulting Groups Deliverables
Each consulting group must provide the following documents and deliverables:
Overall Project plan for the risk assessment and design activities
Threat and risk assessment report - This high level report will include the process you used to perform the threat and risk assessment, your findings and report.
Recommended Security Policy – This report will show how GCEDC is compliant with NERC CIP, PCI, and any security standards that the company currently fails at.
A Draft/Skeleton Design Report - This document will be delivered to the customer in order to receive feedback from the customer to ensure the appropriateness of the report, its completeness and its format.
Final Design Report - This is the main deliverable of the case study.
Presentation Slides - These slides will be used as support for the design presentation.
If deemed necessary, requests (and even maybe obtain) additional information and documentation from GCEDC. Fair warning: do not make blind assumptions.
Analyze the business and technical requirements for the Enterprise security infrastructure.
Research manufacturer’s product lines and equipment has to be used in the design.
Perform a high-level risk assessment and present a risk and threat assessment report as part of the main design report or as a separate document.
Based on the risk assessment and research, perform the detailed design of the security infrastructure. This will include recommendations to mitigate any risk in the existing environment and the documentation of security policy improvements for the corporation.
Document the design and propose an implementation plan for the new security infrastructure.
Deliver the design and formally present it to the customer.
Consulting Groups Deliverables
Each consulting group must provide the following documents and deliverables:
Overall Project plan for the risk assessment and design activities
Threat and risk assessment report - This high level report will include the process you used to perform the threat and risk assessment, your findings and report.
Recommended Security Policy – This report will show how GCEDC is compliant with NERC CIP, PCI, and any security standards that the company currently fails at.
A Draft/Skeleton Design Report - This document will be delivered to the customer in order to receive feedback from the customer to ensure the appropriateness of the report, its completeness and its format.
Final Design Report - This is the main deliverable of the case study.
Presentation Slides - These slides will be used as support for the design presentation.