Governance, Risk & Privacy Case Study
IST 456 focused on the relationship between security operations, governance, risk management, policy, privacy, and business decision-making. The course combined investigation-oriented Enigma Glass labs with broader security management concepts involving compliance, contingency planning, governance, and organizational risk.
Project Summary#
Overview#
IST 456 explored security risk management through both technical and organizational lenses.
The course combined investigation-style lab work with broader topics involving:
- governance
- risk management
- privacy
- compliance
- policy
- contingency planning
- security leadership
- business impact analysis
- security operations
- incident response decision-making
A significant portion of the course used Enigma Glass scenarios to investigate security events involving ransomware, credential compromise, suspicious activity, and data-exfiltration concerns.
The value of the course was not simply identifying indicators. The value was understanding how technical findings influence business decisions, organizational risk, and security governance.
Why This Project Matters#
Many cybersecurity portfolios focus entirely on technical analysis.
IST 456 is valuable because it demonstrates something different:
Technical findings are only useful if organizations can make decisions from them.
A ransomware event is not only a malware problem.
A credential compromise is not only an authentication problem.
A data-exfiltration event is not only a network problem.
Each of those situations creates:
- operational risk
- financial risk
- governance concerns
- privacy implications
- compliance exposure
- communication challenges
- recovery planning requirements
This project shows how cybersecurity work extends beyond investigation into management, policy, governance, and organizational decision-making.
Portfolio-Safe Publishing Approach#
Security note: This page summarizes investigation methodology, governance concepts, and risk-management lessons without publishing raw lab screenshots, complete reports, scenario artifacts, credentials, or academic submissions.
This page excludes:
- raw Enigma Glass screenshots
- full lab reports
- scenario datasets
- credentials
- private academic materials
- complete organizational case details
- sensitive scenario evidence
Instead it focuses on:
- investigation workflow
- risk analysis
- governance thinking
- decision-making
- policy implications
- professional lessons learned
Investigation and Risk Workflow#
Identify the Security Event#
Review the scenario and identify suspicious behavior, incident indicators, affected assets, and possible organizational impact.
Detection
Investigate Technical Evidence#
Analyze available evidence to understand what occurred, which systems were affected, and what risks are present.
Investigation
Assess Risk#
Translate technical findings into organizational risk by evaluating likelihood, impact, affected stakeholders, and operational consequences.
Risk Assessment
Consider Governance and Compliance#
Review policy implications, governance responsibilities, privacy concerns, and potential compliance obligations.
Governance
Recommend Action#
Develop remediation, mitigation, monitoring, recovery, and governance recommendations.
Remediation
Communicate Findings#
Document findings in a format useful to both technical and nontechnical stakeholders.
Reporting
Enigma Glass Investigation Themes#
The strongest investigation-oriented evidence involved Enigma Glass scenarios.
Topics included:
- ransomware activity
- suspicious user behavior
- compromised credentials
- data-exfiltration concerns
- unauthorized access
- organizational security events
- incident triage
- security impact assessment
- security monitoring concepts
The labs emphasized interpretation and decision-making rather than tool memorization.
Governance, Risk & Privacy Themes#
The course also focused heavily on governance and organizational security management.
Areas explored included:
- governance structures
- security leadership
- policy development
- privacy considerations
- compliance awareness
- risk treatment strategies
- organizational security culture
- business continuity
- contingency planning
- executive communication
These topics matter because security programs are not built entirely around technology. They also depend on people, process, governance, and leadership.
Ransomware Response Themes#
Several labs and discussions examined ransomware-style scenarios.
Key themes included:
- attack impact
- operational disruption
- containment priorities
- business recovery
- incident communication
- backup strategy
- governance decisions
- risk acceptance
- executive decision-making
This reinforced that ransomware events are both technical and organizational incidents.
Credential Compromise Themes#
Credential compromise scenarios focused on:
- authentication risk
- suspicious access patterns
- account abuse concerns
- identity-based attacks
- privilege exposure
- monitoring requirements
- user awareness
- remediation planning
This connects directly to many modern security operations workflows.
Data Exfiltration Themes#
Data-exfiltration scenarios emphasized:
- identifying potential data exposure
- understanding business impact
- privacy implications
- governance concerns
- stakeholder communication
- reporting requirements
- mitigation planning
These scenarios highlighted the importance of combining technical investigation with governance awareness.
Capability-to-Evidence Map#
Professional Lessons Learned#
The strongest lessons from IST 456 were:
- technical findings must support business decisions
- risk should be evaluated in organizational context
- governance influences security effectiveness
- privacy concerns affect incident handling
- compliance is part of security decision-making
- ransomware is both a technical and business problem
- communication quality affects response effectiveness
- recovery planning matters before incidents occur
- executive stakeholders need understandable reporting
- cybersecurity work benefits from both technical and governance perspectives
Professional Relevance#
This page is especially relevant for:
- ServiceNow SecOps
- vulnerability management
- cybersecurity analyst roles
- governance-oriented security work
- security operations
- GRC-aware security positions
It demonstrates the ability to connect technical investigation with governance, risk, privacy, compliance, and business decision-making.
That combination is increasingly important in modern cybersecurity environments.
Difference from Other Portfolio Pages#
CYBER 440 focuses on incident response and forensic investigation.
CYBER 366 focuses on malware analysis.
IST 454 focuses on digital forensics.
IST 456 focuses on what happens after the technical findings are understood:
- risk evaluation
- governance decisions
- policy considerations
- compliance concerns
- privacy implications
- executive communication
- recovery planning
That makes it one of the strongest governance-oriented pages in the portfolio.
Related Portfolio Areas#
CYBER 440 Capstone#
Incident response, investigation workflow, forensic evidence, timelines, impact assessment, and remediation planning.
Incident Response
IST 432 Cyber Law, Privacy & GRC#
Cyber law, privacy, governance, surveillance, digital policy, and legal considerations.
Governance
SRA 311 Risk Analysis#
Risk evaluation, source credibility, threat modeling, and risk-treatment concepts.
Risk Analysis
ServiceNow SecOps Lab Hub#
Ownership, remediation, validation, triage, workflow management, and security operations processes.
SecOps
Next Steps#
Future improvements could include:
- governance workflow diagrams
- risk-treatment decision trees
- privacy impact assessment examples
- executive reporting examples
- governance-to-remediation workflow maps
- ServiceNow IRM/GRC relationship notes
For now, this page serves as the portfolio-safe summary of my IST 456 security risk management and Enigma Glass investigation work.