CYB 200 Project Three
Southern New Hampshire University
1
CYB 200 Project Three
A. Identify your threat actors and characterize their motivations or desired outcomes. The
threat actor seems to be Jan or at the ve
...
CYB 200 Project Three
Southern New Hampshire University
1
CYB 200 Project Three
A. Identify your threat actors and characterize their motivations or desired outcomes. The
threat actor seems to be Jan or at the very least someone working through Jan, their
motivation appears to be gathering information for financial gain. This was notated due to
the observation of Jan’s recent appearance change to wearing nice clothing and expensive
jewelry. Jan has been identified to be the threat actor due to her use of a noncompany
device to take pictures of the schematic from the project we have been working on.
B. Describe best practices or methods for detecting the threat actors from the scenario. The
best practices used for detecting this threat actor particularly were, monitor and respond
to suspicious or disruptive behavior and having an incident response playbook. I
identified these two due to the nature of the incident being insider related, by utilizing
these two best practices a possible ongoing incident was identified and reported on.
C. Describe at least one tactic or method that is important in responding to and countering
this threat actor. In this particular situation being mindful of your surroundings and
changes within them becomes a key part, the combination of Jan’s new clothing and
jewelry alongside noticing her android tablet at lunch and then again in her office
combine in a way that signals multiple red flags. One of these things by themselves may
not raise alarm to most but when combined together leads to a very suspicious situation.
D. Describe at least one tactic or method that would be employed to reduce the likelihood of
the same situation happening again. This was an insider threat, which happens more and
more often partly due to these threat actors know the ins and outs of the security system
that is in place. There are really two tactics or methods that should be employed to help
mitigate the threat of this not only continuing but happening in the future, the first of
which would be implementing more security training among all staff to create a more
[Show More]