Skip to main content

IST 456: Security & Risk Management with Enigma Glass Labs


Governance, Risk & Privacy Case Study

IST 456 focused on the relationship between security operations, governance, risk management, policy, privacy, and business decision-making. The course combined investigation-oriented Enigma Glass labs with broader security management concepts involving compliance, contingency planning, governance, and organizational risk.

Course IST 456
Project Type Security Risk Management & Investigation Labs
Focus Governance · Risk · Privacy · SIEM Investigation · Security Management
Platform Enigma Glass
Evidence Areas Ransomware · Compromised Credentials · Data Exfiltration · Policy
Publishing Level Portfolio-Safe / Redacted

Project Summary
#

Category
Summary
Problem
Analyze cybersecurity incidents, organizational risk, ransomware activity, compromised credentials, data exfiltration concerns, policy issues, and governance decisions through both technical investigation and risk-management perspectives.
My Role
Performed investigation-oriented lab work, reviewed evidence, assessed security impact, analyzed organizational risk, documented findings, and developed governance-aware recommendations.
Tools & Frameworks
Enigma Glass, security management concepts, ISO 27000-series ideas, contingency planning, risk assessment, governance principles, compliance awareness, and incident analysis workflows.
Public Version
This public version excludes raw lab evidence, screenshots, complete reports, academic submissions, private credentials, and detailed scenario artifacts. The focus is on methodology, decision-making, and professional relevance.
Why It Matters
Demonstrates how technical findings connect to business risk, governance decisions, compliance concerns, security operations, and executive communication. This is especially relevant for ServiceNow SecOps, cybersecurity analyst, vulnerability management, and governance-oriented roles.

Overview
#

IST 456 explored security risk management through both technical and organizational lenses.

The course combined investigation-style lab work with broader topics involving:

  • governance
  • risk management
  • privacy
  • compliance
  • policy
  • contingency planning
  • security leadership
  • business impact analysis
  • security operations
  • incident response decision-making

A significant portion of the course used Enigma Glass scenarios to investigate security events involving ransomware, credential compromise, suspicious activity, and data-exfiltration concerns.

The value of the course was not simply identifying indicators. The value was understanding how technical findings influence business decisions, organizational risk, and security governance.


Why This Project Matters
#

Many cybersecurity portfolios focus entirely on technical analysis.

IST 456 is valuable because it demonstrates something different:

Technical findings are only useful if organizations can make decisions from them.

A ransomware event is not only a malware problem.

A credential compromise is not only an authentication problem.

A data-exfiltration event is not only a network problem.

Each of those situations creates:

  • operational risk
  • financial risk
  • governance concerns
  • privacy implications
  • compliance exposure
  • communication challenges
  • recovery planning requirements

This project shows how cybersecurity work extends beyond investigation into management, policy, governance, and organizational decision-making.


Portfolio-Safe Publishing Approach
#

Security note: This page summarizes investigation methodology, governance concepts, and risk-management lessons without publishing raw lab screenshots, complete reports, scenario artifacts, credentials, or academic submissions.

This page excludes:

  • raw Enigma Glass screenshots
  • full lab reports
  • scenario datasets
  • credentials
  • private academic materials
  • complete organizational case details
  • sensitive scenario evidence

Instead it focuses on:

  • investigation workflow
  • risk analysis
  • governance thinking
  • decision-making
  • policy implications
  • professional lessons learned

Investigation and Risk Workflow
#

1

Identify the Security Event
#

Review the scenario and identify suspicious behavior, incident indicators, affected assets, and possible organizational impact.

Detection

2

Investigate Technical Evidence
#

Analyze available evidence to understand what occurred, which systems were affected, and what risks are present.

Investigation

3

Assess Risk
#

Translate technical findings into organizational risk by evaluating likelihood, impact, affected stakeholders, and operational consequences.

Risk Assessment

4

Consider Governance and Compliance
#

Review policy implications, governance responsibilities, privacy concerns, and potential compliance obligations.

Governance

5

Recommend Action
#

Develop remediation, mitigation, monitoring, recovery, and governance recommendations.

Remediation

6

Communicate Findings
#

Document findings in a format useful to both technical and nontechnical stakeholders.

Reporting


Enigma Glass Investigation Themes
#

The strongest investigation-oriented evidence involved Enigma Glass scenarios.

Topics included:

  • ransomware activity
  • suspicious user behavior
  • compromised credentials
  • data-exfiltration concerns
  • unauthorized access
  • organizational security events
  • incident triage
  • security impact assessment
  • security monitoring concepts

The labs emphasized interpretation and decision-making rather than tool memorization.


Governance, Risk & Privacy Themes
#

The course also focused heavily on governance and organizational security management.

Areas explored included:

  • governance structures
  • security leadership
  • policy development
  • privacy considerations
  • compliance awareness
  • risk treatment strategies
  • organizational security culture
  • business continuity
  • contingency planning
  • executive communication

These topics matter because security programs are not built entirely around technology. They also depend on people, process, governance, and leadership.


Ransomware Response Themes
#

Several labs and discussions examined ransomware-style scenarios.

Key themes included:

  • attack impact
  • operational disruption
  • containment priorities
  • business recovery
  • incident communication
  • backup strategy
  • governance decisions
  • risk acceptance
  • executive decision-making

This reinforced that ransomware events are both technical and organizational incidents.


Credential Compromise Themes
#

Credential compromise scenarios focused on:

  • authentication risk
  • suspicious access patterns
  • account abuse concerns
  • identity-based attacks
  • privilege exposure
  • monitoring requirements
  • user awareness
  • remediation planning

This connects directly to many modern security operations workflows.


Data Exfiltration Themes
#

Data-exfiltration scenarios emphasized:

  • identifying potential data exposure
  • understanding business impact
  • privacy implications
  • governance concerns
  • stakeholder communication
  • reporting requirements
  • mitigation planning

These scenarios highlighted the importance of combining technical investigation with governance awareness.


Capability-to-Evidence Map
#

Capability
Evidence from IST 456
Status
Security Operations Thinking
Reviewed ransomware, credential-compromise, and investigation-oriented scenarios using structured analysis methods.
Demonstrated
Risk Assessment
Evaluated likelihood, impact, business consequences, and mitigation priorities.
Demonstrated
Governance Awareness
Connected technical findings to policy, privacy, compliance, and leadership concerns.
Demonstrated
Incident Communication
Translated investigation findings into stakeholder-oriented recommendations and reporting.
Demonstrated
Contingency Planning
Reviewed recovery planning, continuity concepts, and organizational resilience considerations.
Demonstrated

Professional Lessons Learned
#

The strongest lessons from IST 456 were:

  • technical findings must support business decisions
  • risk should be evaluated in organizational context
  • governance influences security effectiveness
  • privacy concerns affect incident handling
  • compliance is part of security decision-making
  • ransomware is both a technical and business problem
  • communication quality affects response effectiveness
  • recovery planning matters before incidents occur
  • executive stakeholders need understandable reporting
  • cybersecurity work benefits from both technical and governance perspectives

Professional Relevance
#

This page is especially relevant for:

  • ServiceNow SecOps
  • vulnerability management
  • cybersecurity analyst roles
  • governance-oriented security work
  • security operations
  • GRC-aware security positions

It demonstrates the ability to connect technical investigation with governance, risk, privacy, compliance, and business decision-making.

That combination is increasingly important in modern cybersecurity environments.


Difference from Other Portfolio Pages
#

CYBER 440 focuses on incident response and forensic investigation.

CYBER 366 focuses on malware analysis.

IST 454 focuses on digital forensics.

IST 456 focuses on what happens after the technical findings are understood:

  • risk evaluation
  • governance decisions
  • policy considerations
  • compliance concerns
  • privacy implications
  • executive communication
  • recovery planning

That makes it one of the strongest governance-oriented pages in the portfolio.


Related Portfolio Areas#

CYBER 440 Capstone
#

Incident response, investigation workflow, forensic evidence, timelines, impact assessment, and remediation planning.

Incident Response

IST 432 Cyber Law, Privacy & GRC
#

Cyber law, privacy, governance, surveillance, digital policy, and legal considerations.

Governance

SRA 311 Risk Analysis
#

Risk evaluation, source credibility, threat modeling, and risk-treatment concepts.

Risk Analysis

ServiceNow SecOps Lab Hub
#

Ownership, remediation, validation, triage, workflow management, and security operations processes.

SecOps


Next Steps
#

Future improvements could include:

  • governance workflow diagrams
  • risk-treatment decision trees
  • privacy impact assessment examples
  • executive reporting examples
  • governance-to-remediation workflow maps
  • ServiceNow IRM/GRC relationship notes

For now, this page serves as the portfolio-safe summary of my IST 456 security risk management and Enigma Glass investigation work.