Reference no: EM134017721 , Length: Word Count:2000
Cybersecurity Governance
Assessment: Comprehensive Cybersecurity Governance Program Report
SILOs:
Analyse organisational cybersecurity requirements within technical, legal, and business contexts (SILO 1)
Evaluate cybersecurity governance frameworks and their application in organisational settings (SILO 2)
Communicate cybersecurity concepts and governance implications effectively (SILO 3)
Design and justify a comprehensive Cybersecurity Governance Framework with reference to Good Corporate Governance principles (SILO 4)
Graduate capabilities:
Critical thinking and problem solving
Professional communication
Digital and technical literacy
GEN AI approach:
AI for collaboration: AI use is accepted for specific tasks such as drafting text, and refining and evaluating work. You are expected to critically evaluate and modify any AI-generated content included.
Overview:
Assignment 4
Cybersecurity Governance (CSG) Framework Development (2,000-word equivalent ±15%)
You have recently been appointed as the Head of the Cyber Governance, Risk, and Compliance (GRC) team in an Australian organization that falls under the definition of critical infrastructure as per the Security of Critical Infrastructure Act 2018 (SOCI Act). The organization's current cybersecurity governance maturity level is at the Initial stage, according to the Capability Maturity Model (CMM). The Board of Directors has tasked you to develop a comprehensive Cybersecurity Governance Framework to strengthen the organization's cybersecurity posture and bring it to a higher level of maturity.
Organizational Assumptions and Scope:
As part of this assignment, you are required to select a real-world Australian organization listed under the critical infrastructure sectors covered by the SOCI Act. You may conduct a Google search or refer to news articles, reports, or blogs to identify the organization. The real-world organization is selected for the purpose of understanding its operating environment, goals, and mission.
To determine the structure of the company for this assignment, follow the steps below using your student ID. Relevant examples are given at the end of this assignment specification.
Step 1: Determine Total Number of Branches (X):
To determine the total number of branches (including the headquarters), calculate:
X = (Your Student ID mod 6) + 4
The result X represents the total number of branches for your organization.
One of these branches will be the headquarter (mandatory assumption: to be operational in Australia).
The remaining X - 1 branches are either national (within Australia) or international (Europe/USA), determined in Step 2. Now proceed to determine branch locations.
Step 2: Determine Location of Branches
If your Student ID ends with an odd number, the company has:
2 international branches: one in Europe and one in the USA
The rest are national branches (within Australia)
If your Student ID ends with an even number, the company has:
1 international branch: located in Europe
The rest are national branches (within Australia)
Note: Even if the real-world organization is not operational in Europe or the USA, for this assignment you must assume that it is operational in those regions considering Step 1 and 2 above. Moreover, you only need to consider regulatory and technical requirements for Australia, Europe, and the USA, even if the real organization operates in other regions.
Assignment Task
Your task is to write a report to develop a comprehensive Cybersecurity Governance Framework for the selected organization, taking into account the organization's structure (such as its size), internal and external operating environments, regulatory and technical requirements based on its nature and operating location, and the organization's goals and strategy. The framework must address the following areas but is not limited to:
Establish Strategic Alignment with Business Objectives
Describe how cybersecurity initiatives will align with the organization's strategic goals and business operations, considering factors related to Business Buyer Behaviour and broader business requirements where relevant.
Define Governance Structure, Roles, and Accountability
Propose a clear governance structure that outlines key roles, responsibilities, and accountability mechanisms.
Identify Assets and Conduct a Comprehensive Risk Assessment
Identify critical organizational assets and outline a method for assessing potential cybersecurity risks, threats, and vulnerabilities. Consider appropriate approaches to Value At Risk and risk evaluation.
Develop and Formalize Cybersecurity Policies and Standards
Design high-level policies and standards that will guide the organization's cybersecurity activities.
Create a Detailed Implementation Plan with Controls, Metrics, and KPIs
Develop a step-by-step implementation plan that includes necessary controls, performance metrics, and key performance indicators (KPIs). Effective Project Management And Planning principles may assist in implementation scheduling and governance execution.
Implement Continuous Monitoring and Risk Management Processes
Propose methods for continuous security monitoring and ongoing risk management.
Review, Audit, and Improve the Framework Continuously
Outline procedures for periodic review, auditing, and continuous improvement of the cybersecurity governance framework.
Requirements
You must refer to appropriate standards, frameworks, and regulations where relevant, and apply them to your selected organization's assumed operating regions (Australia, Europe, and the USA). [Links to relevant frameworks and standards are provided throughout the LMS.]
Based on the organization's structure and nature, the Cybersecurity Governance Framework should differ accordingly. Therefore, you need to consider these factors in every aspect of the governance framework.
Marks will be heavily deducted if the organization's structure and nature are not taken into account in points 1 to 7 above.
All sources must be cited using APA 7th Edition (both in-text citation and reference list) referencing styles.
Word count/length: 2000 words
(The reference list is not included in the word count but in-text citations are)