asterion_readiness.md
1siavash@portfolio:~$ cat asterion_readiness.md

# project / synthetic GRC readiness case study

NIST SP 800-171 REV. 3 · CUI · RISK MANAGEMENT · POA&M

Asterion Defense Systems: from control gaps to a 60-day readiness roadmap

I built a fictional aerospace and defense contractor assessment to practice the part of security work that turns technical effort into an executive decision: defining scope, testing evidence, prioritizing risk, and explaining what should happen next.

Scope note

Asterion Defense Systems is fictional. The company, architecture, evidence, scores, owners, dates, and risks are synthetic. This is a readiness/gap assessment—not a certification audit, CMMC assessment, legal opinion, or representation of a real employer or contractor.

Classified-program boundary

In this fictional operating model, Asterion supports government programs that may involve classified information, including Top Secret material. Classified work is handled in a separate accredited facility and classified information system boundary. It is not stored in, transmitted through, or assessed as part of the unclassified CUI engineering enclave documented here.

01 / framing the assessment

The assessment starts with the boundary

Asterion is modeled as a 250-person aerospace and defense manufacturer processing CUI and export-controlled technical data in a dedicated engineering enclave while separately supporting classified government programs. This assessment covers corporate IT, identity, endpoints, network security, logging, backup, incident response, suppliers, and the unclassified systems that protect the CUI enclave.

primary lensNIST SP 800-171 Rev. 3

Scoped readiness alignment for the CUI enclave.

communicationNIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, and Recover.

evidence modelExamine · interview · test

Evidence statements are synthetic but follow an assessment-oriented structure informed by NIST SP 800-171A Rev. 3.

risk methodLikelihood × impact

Residual risk applies a documented control-effectiveness assumption and a defined treatment band.

02 / methodology and assessment logic

How the findings were produced

This was not a checklist exercise. I modeled an evidence-led readiness assessment: define the CUI boundary, identify the systems and data flows that affect it, examine the available records, represent interviews and workshops, evaluate control operation, score the outcomes, and convert material gaps into owned remediation work. The evidence is synthetic, but the assessment structure is designed to mirror how a real engagement would be organized.

assessment questionanswer in this project

What methodology was used?

Scope and data-flow definition; evidence review; interview and workshop inputs; control-family analysis; maturity scoring; risk calculation; POA&M creation; and a business-impact crosswalk. The assessment structure follows NIST SP 800-171 Rev. 3 and uses NIST SP 800-171A Rev. 3 examine, interview, and test concepts.

What systems and tools were evaluated?

The modeled environment includes Windows 11, Windows Server Active Directory, Entra ID, Cisco firewalls and switching, a Windows administrative jump host, Splunk SIEM, Windows Event Forwarding, Windows Defender telemetry, Tenable, and Datto BCDR with on-premises protection and cloud recovery copies.

What evidence was represented?

Policy and charter review, executive risk discussion, CMDB and enclave inventory records, a CUI data-flow workshop, risk-register review, privileged-access and workstation sampling, Splunk source and retention review, incident-response runbook review, Datto backup/restore review, and supplier questionnaires. Each evidence item is identified in the evidence register.

How were findings selected?

A finding was created where the modeled evidence showed an incomplete boundary, inconsistent enforcement, unreliable visibility, untested recovery, uncontrolled data movement, or an immature response/supplier process. Each finding has a threat scenario, affected process, risk score, owner, evidence reference, treatment, and closure condition.

How was remediation determined?

Remediation was sequenced by residual risk and dependency: establish the CUI boundary first, reduce privileged blast radius, prove Datto restoration, close Splunk telemetry gaps, control CUI transfer paths, then exercise incident response and tier suppliers. The complete actions are recorded in the POA&M.

How was CUI scope separated from classified scope?

The CUI assessment includes the unclassified engineering enclave and the corporate, identity, network, security, backup, and supplier services that protect it. Classified operations are modeled as a separate accredited facility and classified information system boundary. They are acknowledged for boundary awareness but excluded from this assessment because classified handling and authorization require separate contract-specific controls and oversight.

How was maturity scored?

Eight outcome areas were scored from 0 to 4: 0 Not started, 1 Ad hoc, 2 Partial, 3 Defined, and 4 Measured. Current maturity is the average of the eight current scores: 1.625/4.0. The target profile averages 3.750/4.0. The 2.125-point difference is a maturity gap, not a compliance percentage.

How was risk calculated?

Inherent risk equals likelihood × impact. Residual risk applies the documented control-effectiveness assumption: ROUND(inherent risk × (1 − control effectiveness), 0). Residual scores of 15+ are Critical, 8–14 High, 4–7 Moderate, and 0–3 Low.

How were technical findings translated into business risk?

Each finding was connected to an operational consequence: incomplete scope affects the ability to prove protection; privileged access affects blast radius; missing telemetry affects detection and investigation; unproven restoration affects downtime and delivery commitments; uncontrolled transfer affects CUI disclosure; and an untested response process affects containment, communication, and contract remediation.

boundaryevidenceconditionriskownerremediationretest

03 / current posture

Tools existed; evidence was inconsistent

The simulated environment has foundational capabilities, but the assessment treats a control as mature only when the organization can demonstrate its coverage, ownership, repeatability, and outcome. The largest gap is Respond: the enclave has not been exercised against a realistic ransomware and CUI-exfiltration scenario.

current maturity 1.625 / 4.0 target profile 3.750 / 4.0 average gap 2.125 points
01 / scopeThe boundary is the first control

Without it, asset ownership, supplier scope, logging coverage, and recovery priorities remain uncertain.

02 / identityPrivilege determines blast radius

Separate administrator identities and strong MFA reduce the impact of a compromised credential.

03 / detectionCoverage matters more than tooling

A SIEM cannot reconstruct activity from sources that never reached it or were not retained.

04 / recoveryA backup job is not a restore test

Recovery time, recovery point, integrity, and corrective actions must be demonstrated.

04 / priority findings

Six findings connect technical conditions to business consequences

Each finding has an owner, evidence references, a treatment priority, and a measurable closure condition. That makes the register useful for a leadership conversation instead of leaving it as a list of technical problems.

F-001 / CRITICALCUI boundary and asset inventory

Without an authoritative boundary, Asterion cannot reliably prove where CUI resides, which systems protect it, or which assets require ownership and monitoring.

F-002 / CRITICALPrivileged access and MFA

Legacy and emergency access paths create concentrated blast radius around identities that can reach engineering files, security tooling, or virtualization hosts.

F-003 / HIGHTelemetry coverage and retention

Missing enclave sources create detection and investigation blind spots, increasing dwell time and the cost of reconstructing unauthorized activity.

F-004 / HIGHCUI transfer and removable media

Unapproved transfer paths or devices could move technical data outside the intended boundary without timely detection or an auditable exception.

F-005 / HIGHBackup restoration evidence

Successful Datto BCDR jobs reduce risk, but they do not prove that the enclave can be restored within a defined recovery objective.

F-006 / HIGHIncident response and supplier risk

Untested response decisions and inconsistent supplier tiering could lengthen disruption or create an unplanned contract remediation burden.

05 / risk treatment

Risk scoring turns a gap list into a decision

The two critical risks are the incomplete CUI boundary and inconsistent privileged-access enforcement. Four additional findings remain high priority because they affect detection, containment, recovery, data transfer, and supplier exposure. The scores are synthetic assumptions used to demonstrate the method.

findinginherentresidualtreatment

F-001 · boundary and assets

20

16 · critical

Mitigate immediately

F-002 · privileged access

20

15 · critical

Mitigate immediately

F-003 · telemetry

16

10 · high

Prioritize remediation

F-004 · CUI transfer

15

11 · high

Prioritize remediation

F-005 · recovery

15

9 · high

Prioritize remediation

F-006 · response and suppliers

12

8 · high

Prioritize remediation

06 / remediation roadmap

Six actions, sequenced around evidence closure

The 60-day sprint begins with scope and privilege, then validates recovery, monitoring, data transfer, incident response, and supplier risk. The point is not to buy more tools; it is to create evidence that a control is owned, operating, and improving.

  1. 01
    Define the CUI boundary

    Publish the boundary diagram, data-flow map, asset register, and accountable owners. Closure requires every in-scope asset to have a location, data type, owner, and protection status.

  2. 02
    Reduce privileged blast radius

    Remove shared privileged accounts and require unique, approved, MFA-protected, reviewed, and logged administrator identities.

  3. 03
    Prove recovery

    Run a full enclave restoration exercise and document recovery time, recovery point, data integrity, and corrective actions.

  4. 04
    Close telemetry gaps

    Create a source-coverage matrix, onboard missing firewall and file-server sources, define retention, and validate alert delivery.

  5. 05
    Control CUI movement

    Approve transfer paths, implement removable-media approval and logging, and retain auditable exception records.

  6. 06
    Exercise response and suppliers

    Run a ransomware/CUI-exfiltration tabletop and tier suppliers by CUI access and business criticality.

07 / artifacts and limits

The deliverable is the evidence story

The assessment is presented here as a readable, self-contained case study. The useful parts of the report and workbook are shown directly on the page so the reader can follow the reasoning without opening a file.

evidence modelExamine · interview · test

Every gap is tied to an evidence question, accountable owner, and closure condition.

risk registerF-001 → F-006

Likelihood, impact, inherent risk, residual risk, treatment, and remediation target are summarized above.

poa&mSix-action sprint

The roadmap sequences scope, privilege, recovery, telemetry, transfer controls, and response/supplier readiness.

method limitsReadiness—not certification

The assessment is scoped at an outcome and control-family level. A real engagement would add exact requirement identifiers, assessment objectives, source locations, collection dates, evidence owners, and artifact hashes.

related workZombie Lab investigation ↗

The companion project demonstrates hands-on evidence preservation, Windows investigation, and incident-response reasoning.

08 / selected control mapping

From business concern to control family

This is a selected mapping for communication—not a claim that six findings represent the full NIST requirement set. It shows how the assessment translates operational concerns into a framework conversation.

findingcontrol familymanagement question

F-001 · boundary and assets

Asset Management

Can we prove what is in scope and who owns it?

F-002 · privileged access

Identity and Access Management

Can a compromised identity reach the enclave without a reviewed control?

F-003 · telemetry

Continuous Monitoring

Can we detect and reconstruct activity across the boundary?

F-004 · CUI transfer

Data Security

Can CUI leave through an approved, visible, accountable path?

F-005 · recovery

System and Services Acquisition / Contingency Planning

Can the enclave be restored and verified within its recovery objectives?

F-006 · response and suppliers

Incident Response / Supply Chain Risk Management

Are response decisions and supplier dependencies exercised before an event?

09 / workbook transcription

Assessment dashboard and scope record

The following tables reproduce the workbook’s operating content. Values are shown as assessed, including the formula outputs: 8 outcome areas, current maturity 1.625/4.0, target maturity 3.750/4.0, average gap 2.125, and 6 high/critical residual risks.

metricvalueinterpretation

Assessment items

8

Scoped outcome areas

Current maturity

1.625 / 4.0

Average current score across A-001 through A-008

Target maturity

3.750 / 4.0

Average target profile

Average maturity gap

2.125 points

Target minus current

High/Critical residual risks

6

Two Critical and four High

NIST CSF functioncurrenttargetgapassessment interpretation

Govern

1.5

3.5

2.0

Risk appetite, policy ownership, exceptions, and supplier governance are not consistently formalized.

Identify

1.5

3.5

2.0

The CUI boundary and authoritative asset ownership are incomplete.

Protect

2.0

4.0

2.0

Baseline capabilities exist, but privileged access, workstation drift, and transfer evidence remain inconsistent.

Detect

2.0

4.0

2.0

Identity and endpoint telemetry is present; enclave firewall and file-server coverage is unreliable.

Respond

1.0

4.0

3.0

No enclave-focused ransomware/CUI-exfiltration tabletop was completed in the last 12 months.

Recover

2.0

4.0

2.0

Datto BCDR on-premises protection and cloud recovery copies exist, but full enclave recovery is not evidenced.

10 / architecture and scope

What was assessed

zonereference architectureboundary treatment

Corporate IT

Windows 11 endpoints, Windows Server Active Directory, Entra ID, commercial collaboration tenant, productivity systems.

CUI prohibited; policy and DLP controls prevent intentional storage.

CUI Engineering Enclave

Dedicated directory, virtualized Windows servers, encrypted engineering file shares, CAD workstations, controlled transfer gateway.

In scope; primary system boundary.

Network Security

Cisco perimeter and enclave firewalls, Cisco switching, Windows administrative jump host, segmented engineering and production networks.

In scope where components enforce or monitor the enclave boundary.

Security Operations

Windows Event Forwarding, Windows Defender endpoint telemetry, Splunk SIEM, Tenable vulnerability management, centralized ticketing and evidence repository.

In scope as protective and detective services.

Resilience and Suppliers

Datto BCDR for on-premises server protection and cloud off-site recovery copies, restoration procedures, remote contractors, approved suppliers, controlled file exchange.

In scope where services store, transmit, or protect CUI.

Classified Operations

Separate accredited facility and classified information system boundary supporting government programs that may include Top Secret material; dedicated personnel, access controls, handling procedures, and approved classified workflows.

Not assessed here; isolated from Corporate IT and the unclassified CUI enclave.

companyAsterion Defense Systems

Fictional 250-person aerospace and defense manufacturer.

objectiveReadiness and risk prioritization

Evaluate readiness to protect CUI, prioritize business risk, and produce an actionable remediation roadmap.

out of scopeClassified systems, GFE, machinery, independent CMMC

Classified systems and government-furnished systems are part of the broader fictional operating model but are excluded from this unclassified CUI assessment, along with physical production machinery and an independent CMMC certification assessment.

scope disciplineIndependent synthetic environment

No real employer stack, proprietary information, production evidence, or real company claims are represented.

11 / complete CSF assessment

Outcome-by-outcome assessment matrix

Current and target maturity use the workbook’s 0–4 scale: 0 Not started, 1 Ad hoc, 2 Partial, 3 Defined, 4 Measured.

IDfunctioncategoryoutcomecurrenttargetgapstatusevidencebusiness outcome

A-001

Govern

Risk Strategy and Oversight

CUI obligations, risk appetite, security responsibilities, policies, and exceptions are documented and reviewed.

2

4

2

Partial

E-001, E-002

Leadership can make informed tradeoffs between mission delivery, contract obligations, and security investment.

A-002

Identify

Asset Management and Boundary

Hardware, software, accounts, data stores, interfaces, and CUI flows are inventoried and assigned owners.

1

4

3

Gap

E-003, E-004

The organization can identify what must be protected and what could affect customer delivery.

A-003

Identify

Risk Assessment

Threats, vulnerabilities, likelihood, impact, and residual risk are assessed using a repeatable method.

2

3

1

Partial

E-005

Security spending is tied to business consequences instead of isolated technical opinions.

A-004

Protect

Access, Configuration, and Media

Least privilege, strong authentication, secure baselines, patching, encryption, and approved transfer paths protect CUI.

2

4

2

Partial

E-006

A stolen credential or removable device is less likely to expose engineering information.

A-005

Detect

Audit and Continuous Monitoring

Identity, endpoint, server, and network events are collected, retained, correlated, and reviewed.

2

4

2

Partial

E-007

The security team can identify suspicious activity earlier and reconstruct events with defensible evidence.

A-006

Respond

Incident Management and Exercises

The enclave has response roles, decision points, communications, exercises, and lessons-learned tracking.

1

4

3

Gap

E-008

A security incident causes less confusion, downtime, and delayed customer communication.

A-007

Recover

Backups and Restoration

Critical systems and CUI data are protected by Datto BCDR on-premises and in the cloud, then restored through tested procedures.

2

4

2

Partial

E-009

Recovery time and customer delivery commitments are based on demonstrated capability.

A-008

Govern

Supply Chain Risk

Suppliers that can affect CUI confidentiality, integrity, or availability are tiered, evaluated, and monitored.

1

3

2

Gap

E-010

Third-party weaknesses are identified before they interrupt programs or create disclosure risk.

12 / complete risk register

Findings, threat scenarios, scoring, owners, and evidence

Inherent score equals likelihood × impact. Residual score applies the documented control-effectiveness assumption. Risk bands are Critical at 15+, High at 8–14, Moderate at 4–7, and Low at 0–3.

IDfindingthreat scenarioasset/processlikelihoodimpactinherenteffectivenessresidualbandownertreatmenttargetevidence

F-001

CUI system boundary and asset inventory are incomplete

Asterion cannot reliably prove which systems protect CUI or identify every asset that could affect contract data. An unmanaged system could become an entry point.

Planning; Risk Assessment

4

5

20

20%

16

Critical

GRC Manager

Mitigate

2026-09-30

E-003, E-004

F-002

Privileged access controls are not consistently enforced

A compromised administrator account could provide access to engineering files, security tooling, or virtualization hosts, creating operational disruption and CUI exposure.

Access Control; Identification and Authentication

4

5

20

25%

15

Critical

Infrastructure Manager

Mitigate

2026-09-30

E-006

F-003

Security telemetry coverage and retention are inconsistent

The security team may be unable to detect or reconstruct unauthorized activity quickly, increasing dwell time, investigation cost, and customer notification risk.

Audit and Accountability

4

4

16

35%

10

High

SOC Lead

Mitigate

2026-10-31

E-007

F-004

CUI transfer and removable-media controls lack consistent evidence

Technical data could be copied to an unapproved device or service without timely detection, creating disclosure and contract risk.

Media Protection; System and Communications Protection

3

5

15

30%

11

High

Security Architect

Mitigate

2026-10-31

E-006

F-005

Backup restoration capability has not been fully demonstrated

Recovery time and data integrity remain assumptions until a full enclave restoration is tested and documented.

System and Information Integrity

3

5

15

40%

9

High

Infrastructure Manager

Mitigate

2026-09-30

E-009

F-006

Incident response and supplier-risk processes are immature

Untested response decisions or supplier weaknesses could lengthen downtime, delay containment, or create an unplanned contract remediation burden.

Incident Response; Supply Chain Risk Management

3

4

12

30%

8

High

Security and GRC Leads

Mitigate

2026-10-31

E-008, E-010

13 / complete POA&M

Plan of Action and Milestones

Each remediation item is written as a measurable outcome with an owner, start date, due date, dependency, and closure condition. Every item begins as Not Started.

IDfindingactionownerprioritystartduesuccess measurestatusdependency

P-001

F-001

Publish CUI boundary, data-flow map, asset register, and accountable owners.

GRC Manager

Critical

2026-08-24

2026-09-30

100% of in-scope assets have owner, location, data type, and protection status.

Not Started

Engineering and infrastructure workshops

P-002

F-002

Remove shared privileged accounts and enforce hardware-backed MFA for enclave administration.

Infrastructure Manager

Critical

2026-08-24

2026-09-30

All privileged identities are unique, MFA-protected, approved, reviewed, and logged.

Not Started

Directory and jump-host changes

P-003

F-005

Perform a full enclave restoration exercise using Datto BCDR and document RTO/RPO results.

Infrastructure Manager

High

2026-09-01

2026-09-30

Full Datto BCDR restore test completed with documented results and corrective actions.

Not Started

Backup owner and isolated test window

P-004

F-003

Create telemetry coverage matrix and onboard missing firewall and file-server sources.

SOC Lead

High

2026-09-08

2026-10-31

All in-scope identity, endpoint, server, and network sources report healthy status.

Not Started

Asset boundary and firewall owners

P-005

F-004

Approve CUI transfer paths and implement removable-media approval and logging.

Security Architect

High

2026-09-15

2026-10-31

All approved transfer paths are documented and exception records are auditable.

Not Started

Data-flow map and engineering process owners

P-006

F-006

Run an enclave ransomware and CUI-exfiltration tabletop; tier suppliers by CUI access.

Security and GRC Leads

High

2026-09-21

2026-10-31

Exercise completed, decisions recorded, corrective actions assigned, and CUI-impacting suppliers tiered.

Not Started

Updated enclave playbooks and supplier inventory

14 / complete evidence register

Evidence statements used in the assessment

These are synthetic evidence statements. In a real engagement, each record would point to a source location, evidence owner, collection date, and artifact hash.

IDtypeitemobservationconfidenceassessment use

E-001

Document review

Security charter and policy set

Policies exist but do not consistently define CUI ownership, exception expiration, or risk acceptance authority.

Medium

Supports current-state scoring and/or finding linkage

E-002

Interview

Executive risk discussion

Leadership prioritizes program delivery but risk appetite is not formally recorded.

Medium

Supports current-state scoring and/or finding linkage

E-003

System record

CMDB and enclave inventory

Corporate inventory is operationally useful; enclave inventory is separate and contains duplicate records.

Medium

Supports current-state scoring and/or finding linkage

E-004

Workshop

CUI data-flow workshop

Engineering shares and approved transfer gateway were identified; a legacy supplier exchange path remains unresolved.

Medium

Supports current-state scoring and/or finding linkage

E-005

Risk register review

Enterprise risk register

Cyber risks are present but not consistently linked to systems, owners, or treatment dates.

High

Supports current-state scoring and/or finding linkage

E-006

Access and endpoint review

Privileged access and workstation sample

Separate administrator identities exist for most staff; two legacy service accounts remain shared and 18 percent of sampled engineering workstations show baseline drift.

High

Supports current-state scoring and/or finding linkage

E-007

SIEM source and retention review

Splunk source list

Windows identity, endpoint, and server events are covered; two Cisco enclave firewalls and one Windows engineering file server do not forward reliably, and retention varies by source.

High

Supports current-state scoring and/or finding linkage

E-008

Exercise and runbook review

Incident response evidence

Enterprise response plan exists, but no enclave-focused tabletop was completed in the last 12 months.

High

Supports current-state scoring and/or finding linkage

E-009

Backup and restore review

Datto BCDR evidence

Critical systems have successful on-premises backups and cloud off-site copies; a full enclave recovery test is not documented.

High

Supports current-state scoring and/or finding linkage

E-010

Supplier review

Supplier security questionnaires

High-value suppliers are reviewed inconsistently and CUI access tiering is not standardized.

Medium

Supports current-state scoring and/or finding linkage

15 / method and references

How the assessment was performed

method elementdefinition

Primary requirements lens

NIST SP 800-171 Rev. 3 readiness alignment for the CUI enclave.

Assessment procedures

NIST SP 800-171A Rev. 3 concepts: examine, interview, and test evidence.

Executive communication

NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, Recover.

Risk method

NIST SP 800-30 Rev. 1 concepts: threat, vulnerability, likelihood, impact, and residual risk.

Classified-program treatment

The classified environment is represented as a separate operational boundary. This page does not assess Top Secret handling, classified system accreditation, personnel clearance eligibility, facility clearance, or contract-specific DD 254 requirements.

Maturity scale

0 Not started · 1 Ad hoc · 2 Partial · 3 Defined · 4 Measured.

Risk bands

Residual score 15+ Critical · 8–14 High · 4–7 Moderate · 0–3 Low.

referenceuse

NIST Cybersecurity Framework 2.0

Executive communication and organizational profile.

NIST SP 800-171 Rev. 3

CUI protection requirements and control-family lens.

NIST SP 800-171A Rev. 3

Assessment procedures, evidence, and assessment depth.

NIST SP 800-30 Rev. 1

Likelihood, impact, and risk treatment method.

32 CFR Part 117 / NISPOM

Classified contractor security context; referenced for boundary awareness only, not assessed for compliance.

Limitations

This workbook is a portfolio simulation using fictional company details and synthetic evidence. It does not establish compliance, certification eligibility, legal sufficiency, a CMMC score, a facility clearance, or authorization to handle classified information. The classified-program references describe a separate boundary that would require its own contract-specific security requirements, facility/personnel controls, system authorization, and government oversight.

FOLLOW-UP / INCIDENT RESPONSE PROGRAM

The assessment ends with a handoff to operations

The GRC work identifies six priority findings. The linked follow-up turns those findings into a directive incident-response program for the same fictional environment: Entra identity compromise, Windows endpoints, FortiGate containment, Splunk investigation, Datto recovery, provider handoffs, playbooks, and a tabletop.

16 / incident-response operating model

The response plan turns the gap into a capability

The GRC assessment identified response, supplier coordination, telemetry, and recovery evidence as decision gaps. The companion plan makes those gaps operational: who declares an incident, which provider acts, what evidence is preserved, what can be contained, and what must be proven before recovery.

identity planeMicrosoft Entra ID + AD-DC01

Cloud identity is the control plane; the on-premises domain controller is treated as a dependency that requires separate scoping and evidence.

network edgeOne ISP + FortiGate

FortiGate provides perimeter, VPN, policy, and administrative control points for containment and investigation.

server tierFS01 · APP01 · SQL01

File, application, and database dependencies are assessed and recovered as separate services with integrity checks.

endpoint tierWindows laptops + desktops

Endpoint isolation, Defender evidence, Windows event collection, reimage criteria, and user communication are defined.

security operationsSplunk + third-party SOC

The SOC triages and preserves telemetry; the security lead owns incident decisions and corrective actions.

resilienceDatto BCDR

On-premises protection and cloud recovery copies support recovery, but a backup job is not accepted as restoration evidence.

service providersThird-party IT + third-party SOC

Separate responsibilities, escalation rules, evidence requirements, and no-unilateral-closure expectations are documented.

17 / architecture and trust boundaries

Response decisions follow the actual environment

The fictional environment is intentionally small enough to reason about and realistic enough to expose dependency risk. There is one internet path, one identity stack with hybrid dependency, one file server, one application server, one SQL server, Windows workstations, centralized detection, and a separate backup control plane.

zonereference architectureresponse significance

Internet edge

One ISP → FortiGate perimeter firewall → internal Cisco switching

Preserve FortiGate traffic, VPN, admin, and configuration-change evidence; use the firewall as a containment control, not the only source of truth.

Identity

Microsoft Entra ID is the cloud identity plane; AD-DC01 is the on-premises directory dependency

Disable or restrict identities in Entra, invalidate sessions, review privileged roles, and preserve sign-in, audit, and directory evidence.

Workstations

Windows laptops and desktops used by staff and engineering users

Isolate affected endpoints, preserve volatile context where practical, collect Defender and Windows event evidence, and reimage from a trusted baseline when required.

File services

FS01 provides the primary file-server dependency for shared engineering and business data

Check share access, mass-change indicators, staged archives, shadow copies, and the last known-good recovery point before restoring.

Application and database

APP01 hosts the business application; SQL01 hosts its database dependency

Contain application credentials and database access separately; validate application integrity and transaction consistency before service return.

Detection

Splunk receives identity, endpoint, server, and network telemetry

SOC triage must identify source health, search time range, query owner, evidence export location, and retention before closing an incident.

Resilience

Datto BCDR protects on-premises servers and maintains cloud recovery copies

Treat backup consoles and retention policies as high-value targets; preserve configuration evidence and test restoration in an isolated recovery network.

Classified work remains a separate accredited facility and classified information system boundary. This incident-response program covers the unclassified corporate/CUI operating model only; it does not assess classified systems, classified handling, or authorization requirements.

18 / roles and supplier handoffs

Providers execute tasks; the organization owns the decision

The third-party IT company and third-party SOC company are separate on purpose. The SOC provides detection and investigation; IT provides infrastructure execution and recovery. Neither provider can silently accept risk, close a case, or make a CUI-impact determination without the internal security/GRC owner.

roleprimary responsibilityhandoff expectation

Internal leadership

Owns business risk acceptance, customer/contract decisions, materiality, and recovery priority.

Receives severity updates and approves decisions that change mission, legal, or customer exposure.

Third-party IT company

Provides infrastructure administration, FortiGate/Windows/Datto execution, system recovery support, and technical change records.

Acts on approved containment and recovery requests; does not unilaterally close a security incident.

Third-party SOC company

Provides monitoring, triage, Splunk investigation, escalation, detection tuning, and evidence packaging.

Opens and updates the case, preserves relevant telemetry, and hands off with timestamps, queries, and confidence.

Security / GRC lead

Owns incident command, CUI impact assessment, evidence standard, playbook selection, communications cadence, and corrective actions.

Coordinates the providers and connects lessons learned back to the POA&M and risk register.

minimum handoff case ID · UTC timestamps · affected asset/account · confidence · query or action performed · evidence location · next decision owner

19 / severity and workflow

Severity is a decision aid, not a label

Severity is based on business disruption, CUI impact, privileged access, spread, evidence confidence, and recovery risk. The plan uses a common clock so the SOC, IT provider, leadership, and security lead can act without waiting for a perfect narrative.

  1. S1
    Detect and open

    Open one case, capture the initial signal, assign an incident lead, preserve the time window, and record what is still unknown.

  2. S2
    Classify and scope

    Identify affected users, endpoints, servers, network paths, providers, data types, and possible CUI exposure.

  3. S3
    Contain deliberately

    Choose identity, endpoint, network, server, or backup-plane containment with an owner, expected impact, rollback condition, and timestamp.

  4. S4
    Eradicate and validate

    Remove persistence, rotate exposed secrets, close the entry path, verify telemetry, and confirm that the threat is no longer active.

  5. S5
    Recover from trusted state

    Restore in an isolated network, validate identity and application dependencies, confirm data integrity, and document RTO/RPO results.

  6. S6
    Communicate and close

    Provide scheduled leadership updates, coordinate customer/contract decisions through authorized owners, and close only after corrective actions are assigned.

20 / playbook catalog

Five playbooks cover the highest-consequence paths

Each playbook uses the same structure: trigger, first-hour actions, investigation questions, containment, recovery, communications, evidence, and after-action requirements. That keeps the plan directive while leaving room for the providers to execute within their approved procedures.

01 / PLAYBOOKEnclave ransomware + suspected CUI exfiltration

Trigger: Ransom note, mass file changes, archive staging, or evidence of transfer from FS01/engineering workstations.

First move: Isolate affected endpoints; protect identity and backup control planes; preserve evidence; make the CUI-impact decision before broad restore.

02 / PLAYBOOKEntra identity or privileged-account compromise

Trigger: Impossible travel, unfamiliar MFA activity, token/session abuse, unexpected role assignment, or admin behavior outside change windows.

First move: Disable or restrict the identity, revoke sessions, identify downstream access, and verify no persistence or new privileged principal exists.

03 / PLAYBOOKWindows workstation compromise

Trigger: Defender detection, suspicious PowerShell, persistence, credential theft, or lateral movement from a laptop/desktop.

First move: Network-isolate the endpoint, preserve host context, scope adjacent identities and systems, then reimage or remediate from a trusted baseline.

04 / PLAYBOOKBackup-plane compromise

Trigger: Datto retention changes, protected-device deletion, unusual console access, or failed jobs coinciding with an incident.

First move: Protect Datto administration, preserve console evidence, verify recovery points, and use an isolated restore decision path.

05 / PLAYBOOKPhishing / BEC

Trigger: Mailbox-rule change, credential phishing, fraudulent payment instruction, or supplier impersonation.

First move: Contain identity and mailbox persistence, validate out-of-band payment/process changes, and check for CUI access or forwarding.

21 / tabletop exercise

A realistic inject tests the seams between teams

The exercise scenario begins with an Entra identity alert and ends with an isolated Datto recovery. It deliberately crosses the SOC, IT provider, security/GRC lead, leadership, and business owners so the test measures coordination—not just whether one person knows a command.

injectscenariodecision to test

01 / detect

The SOC receives an Entra risky sign-in alert for a user who recently accessed engineering shares.

Who owns the case, what severity is declared, and what evidence is preserved before account action?

02 / scope

The user’s Windows laptop shows PowerShell activity and a new archive staged for transfer.

How do the SOC and IT provider isolate the endpoint while the security lead assesses possible CUI exposure?

03 / contain

FS01 begins showing rapid file modifications; APP01 and SQL01 remain available.

Which systems are isolated, who approves the boundary change, and how is business continuity weighed?

04 / recover

A Datto retention policy was modified shortly before the file changes were detected.

How is the backup plane protected, and what makes a recovery point trusted enough to restore?

05 / communicate

Leadership asks whether customer notification, contract review, or law-enforcement coordination is required.

What is known, what is not known, who can approve external communication, and when is the next update?

06 / improve

The enclave is restored in an isolated network and evidence review finds a telemetry gap.

Which corrective actions become POA&M updates, detection changes, provider SLA changes, or training tasks?

exercise outputDecision log + action register

Capture who decided what, when, with which evidence, and what assumption remained open.

success measureContainment and recovery decisions are timely

Participants identify the affected boundary, protect the backup plane, and choose a trusted restore path.

follow-throughCorrective actions map to POA&M

Every gap becomes an owner, due date, evidence requirement, and retest condition.

22 / detection and evidence

Telemetry is part of the response product

The response plan treats evidence as an operating deliverable. The SOC must preserve enough context for the organization to explain what happened, what was affected, what was contained, and why recovery was trusted.

sourceevidence to preserveownerhandling note

Identity

Entra sign-in and audit logs; privileged-role changes; risky sign-ins; MFA and session state

SOC / security lead

Preserve before disabling accounts where feasible; record UTC time window and export location.

Perimeter

FortiGate traffic, VPN, admin, policy, and configuration-change logs

IT provider / SOC

Capture policy changes and suspected command-and-control or exfiltration paths.

Windows

Defender alerts, Windows Security logs, PowerShell, scheduled tasks, services, autoruns, and endpoint timeline

SOC / IT provider

Collect from affected laptops, desktops, AD-DC01, FS01, APP01, and SQL01 as applicable.

File activity

FS01 share access, file-change indicators, staged archives, permissions, and shadow-copy status

IT provider

Use to bound CUI exposure and select a last-known-good restore point.

Application / SQL

APP01 application logs, SQL01 authentication, query, job, and integrity indicators

Application owner / IT provider

Validate both service integrity and data integrity before returning to production.

Backups

Datto job history, retention-policy changes, protected-device status, recovery-point inventory, and restore logs

IT provider / security lead

Treat unexpected deletion or retention changes as potential attacker activity.

23 / recovery and validation

Recovery is not complete until the service and the evidence agree

Datto protection reduces the likelihood of permanent loss, but recovery still requires a trusted restore point, a clean identity path, validated dependencies, and a decision record. The program separates restoration from return-to-service so urgency does not erase verification.

gate 01 / trustProtect the recovery plane

Secure Datto administration, preserve policy changes, validate recovery points, and use an isolated restore network.

gate 02 / integrityValidate the service chain

Check AD-DC01 identity dependency, FS01 data integrity, APP01 behavior, and SQL01 authentication and transactions.

gate 03 / securityRe-establish monitoring

Confirm Entra, FortiGate, Windows, server, and Splunk visibility before reconnecting systems to production.

gate 04 / businessApprove return to service

Leadership and the service owner accept residual risk, recovery results, customer impact, and remaining corrective actions.

24 / GRC-to-IR crosswalk

Every major finding has an operational response hook

Pairing the projects makes the portfolio story stronger because it shows the lifecycle from assessment to action. The GRC register explains why the work matters; the response program shows how the organization would behave under pressure and how lessons return to governance.

GRC findingIR control pointhow the work connects

F-001 / boundary and assets

IR-01, IR-03

The asset register and data-flow map define which identities, endpoints, servers, network controls, and providers must be searched and contained.

F-002 / privileged access

IR-02, IR-04

Entra privileged-role review, FortiGate administration, Datto console access, and provider access are explicit containment decisions.

F-003 / telemetry

IR-01, IR-03

Splunk source health and Windows/FortiGate/Entra coverage are part of triage; missing telemetry is recorded as a response limitation.

F-004 / CUI transfer

IR-01, IR-05

Archive staging, mailbox forwarding, removable media, and supplier exchange paths are investigated as possible CUI movement.

F-005 / recovery evidence

IR-04

Datto recovery-point integrity, isolated restoration, RTO/RPO results, and corrective actions close the recovery gap.

F-006 / response and suppliers

IR-01 through IR-05

The master plan, provider handoff model, tabletop, and after-action workflow turn the finding into an operating capability.