Introduction
For Milestone 2, we will focus on the development of security policies. To prepare for this Milestone, begin by reviewing the following resources:
- Coastal Carolina University - Office of Information Technology Services - Information Security
- IBM. What is the NIST Cybersecurity Framework?
- NIST Special Publication 3101: NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational Profiles
- NIST Special Publication 1299: NIST Cybersecurity Framework 2.0: Resource & Overview Guide
Requirements
Your team will conduct research and prepare a written milestone report that covers the following topics:
- Provide an overview of the NIST Cybersecurity Framework. Explain the purpose, the resources available, the focus/audience, and the various parts of the framework. Be sure to include the six functions of the CSF 2.0.
- Summarize CCU's information security policies.
- Compare the SC Division of Information Security policies (below) with the NIST standards. In what ways are the policies harmonious with the NIST standards, and in what ways do they conflict?
- Specifically evaluate the conflicts between the NIST SP800-63B-4 Authentication & Authenticator Management guidelines (section 3.1) and the password change policies utilized by the State of South Carolina and Coastal Carolina University. Refer to the SCDIS Information Security Policy - Access Control (section 1.6) policy and to the passwords section on the Student Computing Services - Information Security Awareness page.
- Consider the State of South Carolina's Mobile Security Policy and the Coastal Carolina University Multi-Factor Authentication policy. A CCU employee (who is also, by definition, a state employee) might be asked to install an authenticator application on a personal cell phone in order to use MFA. If an employee doesn't have a smartphone, the employee could install and use an authenticator application on someone else's phone instead. How does CCU's implementation of MFA align with or conflict with the State of South Carolina's Mobile Security Policy?
- Make recommendations to harmonize CCU's information security policies with the relevant NIST guidelines. Identify situations in which harmonization with the NIST guidelines would conflict with SCDIS policies.
Organization
- A title page that includes the report title and the names of all team members, with the team leader for this milestone listed first and indicated as such (for example, John Smith (Team Leader)).
- A brief introduction section that provides an overview of your work.
- One or more sections of narrative text that covers the above list of topics.
- A brief conclusion section that summarizes major points.
- A References section that lists all references cited. Please remember that there should be at least 1 inline citation for each work listed in the References section!
- A final page detailing the contributions of each team member (including the leader) to the final report. Contributions should be listed as bullet points under each person's name.
Formatting
The paper should be formatted as follows:
- Use a 12 point font.
- Double-space the text.
- Use 1 inch margins with a standard US letter (8.5 x 11 inch) page size.
- For the title and section headings, use the formatting tools provided in your word processing software to select "title" or "heading" format. Do NOT manually change the font size or font style/weight to make a heading or title. Using the word processing software’s defined styles for headings and titles helps make the resulting PDF file more accessible to people with disabilities.
The length of the middle part of the paper, excluding the title page, references, and contributions pages, should be:
- 8 pages if your team has 2 people, or
- 15 pages if your team has 3 people, or
- 22 pages if your team has 4 people, or
- 29 pages if your team has 5 people.
References
For your references:
- Try to cite at least 1 article published in an academic journal or conference proceedings.
- Do NOT cite Wikipedia articles directly. Instead, look up the references in the Wikipedia articles and cite those references.
- You MAY cite any of the works (including mine) that I provide in the Starting Points section, below.
- You may use ANY citation format you prefer, as long as each cited reference has some kind of inline citation and each reference listed at the end contains enough information to find the original source. Popular citation formats include APA, IEEE, ACM, Springer Lecture Notes in Computer Science, etc. MLA and Turabian (University of Chicago Style) are also acceptable, although they aren’t as widely used in the computing disciplines. The important things with citation styles are to be consistent and to ensure that each source listed in the References section has at least one inline citation somewhere in the text.
- If you use Artificial Intelligence (AI) tools as part of your research, cite the AI tools used. These citations are in addition to the required number of references for the paper.
- If you use AI tools to assist with the writing, include additional references for the AI tool(s) used. You can simply include a sentence at the end of the paper stating which AI tools were used and include inline citations to those tools. Note that AI tool citations are in addition to the minimum number of required references.
The minimum number of required references (exclusive of AI tools) is:
- 6, if your team has 2 people, or
- 10, if your team has 3 people, or
- 15, if your team has 4 people, or
- 20, if your team has 5 people.
IMPORTANT: If you use AI tools to facilitate your work, please remember that you (the humans) are ultimately responsible for the content of the paper. Verify the output of all AI algorithms!
Team Leader
One person should be designated as the team leader for this milestone. Team leaders must rotate between milestones so that each person serves as team leader at least one time. It is up to each team to determine who will serve as leader for each individual milestone.
In general, the Team Leader should NOT be doing most of the research for the milestone. Instead, the team leader should:
- Manage the team, ensuring that everyone is communicating and is on track. Report any issues to the professor immediately. Convey any questions or requests for clarification to the professor in a timely manner.
- Compile and join the narrative text written by the team members, ensuring that it flows together in a single document.
- Write the introduction and conclusion sections.
- Combine the references found by the other team members and format them into the chosen reference style in the References section. (Again, any citation style as fine – just be consistent.)
- Ensure that each reference in the References section has at least one inline citation elsewhere in the paper.
- Check that all inline citations are using the same format (it doesn’t matter which format, as long as they are consistent).
- Proofread the paper and fix spelling and grammar issues.
- Export the completed report into PDF format.
- Share the completed document with the team and communicate to be sure no additional changes are needed.
- Submit the final PDF document before the milestone submission closes. Note that I have set Moodle to allow updating your submission, so you can share the document by submitting it. Each team member should be able to download the submission to complete the previous step. If changes are needed, simply resubmit an updated PDF.
Other Team Members
Non-leader team members should:
- Conduct the research to obtain the required number of sources.
- Write a substantial portion of the narrative section of the paper, citing the sources found.
- Communicate with each other and with the team leader to ensure that the work is completed in a timely manner. Remember that the team leader needs time to compile the final document.
- Record and document individual contributions to the team effort.
- Read the final report before the assignment submission closes.
- Verify that the milestone report has been submitted.
I have based the length requirements for the paper on the assumption of 7 pages of writing and 5 sources per regular team member, plus a half-page introduction and a half-page conclusion written by the Team Leader. That said, teams are free to divide the workload differently, as long as each person is making a substantial and roughly equal contribution according to the above guidelines.
Starting Points
The following resources (which you may cite in your paper) can help you get started on this Milestone:
- National Institute of Standards and Technology
- Coastal Carolina University
- South Carolina Department of Administration - Division of Information Security
- South Carolina Department of Administration - Division of Information Security
- SCDIS Information Security Policy Handbook
- SCDIS Information Security Program Master Policy
- SCDIS-201: Information Security and Privacy Incident Response Standards
- SCDIS Information Security Policy - Access Control
- SCDIS Information Security Policy - Asset Management
- SCDIS Information Security Policy - Business Continuity Management
- SCDIS Information Security Policy - Data Protection and Privacy
- SCDIS Information Security Policy - Human Resource and Security Awareness
- SCDIS Information Security Policy - Information Systems Acquisitions, Development, and Maintenance
- SCDIS Information Security Policy - IT Risk Strategy
- SCDIS Information Security Policy - Mobile Security
- SCDIS Information Security Policy - Physical & Environmental Security
- SCDIS Information Security Policy - Risk Management
- SCDIS Information Security Policy - Threat and Vulnerability Management
Submission
Once the report is complete, the Team Leader should export it into PDF format and upload it as the submission for this milestone. Only the Team Leader needs to submit the final report, although another team member can submit in the event of an emergency involving the Team Leader. That said, everyone in the team should read the final report and double-check that their individual contributions are listed correctly at the end. Also, each team member should verify that the Team Leader has uploaded the final PDF before the assignment closing date in Moodle.
ABET Assessment
This activity supports the following ABET program SLOs:
- SLO 1. Analyze a complex problem and apply principles of computing and other relevant disciplines to elaborate solutions to it.
- SLO 2. Design, implement, and evaluate a computing-based solution to meet a given set of requirements in the context of the program's discipline.
- SLO 3. Communicate effectively in a variety of professional contexts.
- SLO 4. Recognize professional responsibilities and make informed judgments in computing practice based on legal and ethical principles.
- SLO 5. Function effectively as a member and leader of a team engaged in activities appropriate to the program's discipline.