# project / synthetic GRC readiness case study
NIST SP 800-171 REV. 3 · CUI · RISK MANAGEMENT · POA&M
Asterion Defense Systems: from control gaps to a 60-day readiness roadmap
I built a fictional aerospace and defense contractor assessment to practice the part of security work that turns technical effort into an executive decision: defining scope, testing evidence, prioritizing risk, and explaining what should happen next.
Asterion Defense Systems is fictional. The company, architecture, evidence, scores, owners, dates, and risks are synthetic. This is a readiness/gap assessment—not a certification audit, CMMC assessment, legal opinion, or representation of a real employer or contractor.
In this fictional operating model, Asterion supports government programs that may involve classified information, including Top Secret material. Classified work is handled in a separate accredited facility and classified information system boundary. It is not stored in, transmitted through, or assessed as part of the unclassified CUI engineering enclave documented here.
01 / framing the assessment
The assessment starts with the boundary
Asterion is modeled as a 250-person aerospace and defense manufacturer processing CUI and export-controlled technical data in a dedicated engineering enclave while separately supporting classified government programs. This assessment covers corporate IT, identity, endpoints, network security, logging, backup, incident response, suppliers, and the unclassified systems that protect the CUI enclave.
Scoped readiness alignment for the CUI enclave.
Govern, Identify, Protect, Detect, Respond, and Recover.
Evidence statements are synthetic but follow an assessment-oriented structure informed by NIST SP 800-171A Rev. 3.
Residual risk applies a documented control-effectiveness assumption and a defined treatment band.
02 / methodology and assessment logic
How the findings were produced
This was not a checklist exercise. I modeled an evidence-led readiness assessment: define the CUI boundary, identify the systems and data flows that affect it, examine the available records, represent interviews and workshops, evaluate control operation, score the outcomes, and convert material gaps into owned remediation work. The evidence is synthetic, but the assessment structure is designed to mirror how a real engagement would be organized.
What methodology was used?
Scope and data-flow definition; evidence review; interview and workshop inputs; control-family analysis; maturity scoring; risk calculation; POA&M creation; and a business-impact crosswalk. The assessment structure follows NIST SP 800-171 Rev. 3 and uses NIST SP 800-171A Rev. 3 examine, interview, and test concepts.
What systems and tools were evaluated?
The modeled environment includes Windows 11, Windows Server Active Directory, Entra ID, Cisco firewalls and switching, a Windows administrative jump host, Splunk SIEM, Windows Event Forwarding, Windows Defender telemetry, Tenable, and Datto BCDR with on-premises protection and cloud recovery copies.
What evidence was represented?
Policy and charter review, executive risk discussion, CMDB and enclave inventory records, a CUI data-flow workshop, risk-register review, privileged-access and workstation sampling, Splunk source and retention review, incident-response runbook review, Datto backup/restore review, and supplier questionnaires. Each evidence item is identified in the evidence register.
How were findings selected?
A finding was created where the modeled evidence showed an incomplete boundary, inconsistent enforcement, unreliable visibility, untested recovery, uncontrolled data movement, or an immature response/supplier process. Each finding has a threat scenario, affected process, risk score, owner, evidence reference, treatment, and closure condition.
How was remediation determined?
Remediation was sequenced by residual risk and dependency: establish the CUI boundary first, reduce privileged blast radius, prove Datto restoration, close Splunk telemetry gaps, control CUI transfer paths, then exercise incident response and tier suppliers. The complete actions are recorded in the POA&M.
How was CUI scope separated from classified scope?
The CUI assessment includes the unclassified engineering enclave and the corporate, identity, network, security, backup, and supplier services that protect it. Classified operations are modeled as a separate accredited facility and classified information system boundary. They are acknowledged for boundary awareness but excluded from this assessment because classified handling and authorization require separate contract-specific controls and oversight.
How was maturity scored?
Eight outcome areas were scored from 0 to 4: 0 Not started, 1 Ad hoc, 2 Partial, 3 Defined, and 4 Measured. Current maturity is the average of the eight current scores: 1.625/4.0. The target profile averages 3.750/4.0. The 2.125-point difference is a maturity gap, not a compliance percentage.
How was risk calculated?
Inherent risk equals likelihood × impact. Residual risk applies the documented control-effectiveness assumption: ROUND(inherent risk × (1 − control effectiveness), 0). Residual scores of 15+ are Critical, 8–14 High, 4–7 Moderate, and 0–3 Low.
How were technical findings translated into business risk?
Each finding was connected to an operational consequence: incomplete scope affects the ability to prove protection; privileged access affects blast radius; missing telemetry affects detection and investigation; unproven restoration affects downtime and delivery commitments; uncontrolled transfer affects CUI disclosure; and an untested response process affects containment, communication, and contract remediation.
03 / current posture
Tools existed; evidence was inconsistent
The simulated environment has foundational capabilities, but the assessment treats a control as mature only when the organization can demonstrate its coverage, ownership, repeatability, and outcome. The largest gap is Respond: the enclave has not been exercised against a realistic ransomware and CUI-exfiltration scenario.
Without it, asset ownership, supplier scope, logging coverage, and recovery priorities remain uncertain.
Separate administrator identities and strong MFA reduce the impact of a compromised credential.
A SIEM cannot reconstruct activity from sources that never reached it or were not retained.
Recovery time, recovery point, integrity, and corrective actions must be demonstrated.
04 / priority findings
Six findings connect technical conditions to business consequences
Each finding has an owner, evidence references, a treatment priority, and a measurable closure condition. That makes the register useful for a leadership conversation instead of leaving it as a list of technical problems.
Without an authoritative boundary, Asterion cannot reliably prove where CUI resides, which systems protect it, or which assets require ownership and monitoring.
Legacy and emergency access paths create concentrated blast radius around identities that can reach engineering files, security tooling, or virtualization hosts.
Missing enclave sources create detection and investigation blind spots, increasing dwell time and the cost of reconstructing unauthorized activity.
Unapproved transfer paths or devices could move technical data outside the intended boundary without timely detection or an auditable exception.
Successful Datto BCDR jobs reduce risk, but they do not prove that the enclave can be restored within a defined recovery objective.
Untested response decisions and inconsistent supplier tiering could lengthen disruption or create an unplanned contract remediation burden.
05 / risk treatment
Risk scoring turns a gap list into a decision
The two critical risks are the incomplete CUI boundary and inconsistent privileged-access enforcement. Four additional findings remain high priority because they affect detection, containment, recovery, data transfer, and supplier exposure. The scores are synthetic assumptions used to demonstrate the method.
F-001 · boundary and assets
20
16 · critical
Mitigate immediately
F-002 · privileged access
20
15 · critical
Mitigate immediately
F-003 · telemetry
16
10 · high
Prioritize remediation
F-004 · CUI transfer
15
11 · high
Prioritize remediation
F-005 · recovery
15
9 · high
Prioritize remediation
F-006 · response and suppliers
12
8 · high
Prioritize remediation
06 / remediation roadmap
Six actions, sequenced around evidence closure
The 60-day sprint begins with scope and privilege, then validates recovery, monitoring, data transfer, incident response, and supplier risk. The point is not to buy more tools; it is to create evidence that a control is owned, operating, and improving.
- 01Define the CUI boundary
Publish the boundary diagram, data-flow map, asset register, and accountable owners. Closure requires every in-scope asset to have a location, data type, owner, and protection status.
- 02Reduce privileged blast radius
Remove shared privileged accounts and require unique, approved, MFA-protected, reviewed, and logged administrator identities.
- 03Prove recovery
Run a full enclave restoration exercise and document recovery time, recovery point, data integrity, and corrective actions.
- 04Close telemetry gaps
Create a source-coverage matrix, onboard missing firewall and file-server sources, define retention, and validate alert delivery.
- 05Control CUI movement
Approve transfer paths, implement removable-media approval and logging, and retain auditable exception records.
- 06Exercise response and suppliers
Run a ransomware/CUI-exfiltration tabletop and tier suppliers by CUI access and business criticality.
07 / artifacts and limits
The deliverable is the evidence story
The assessment is presented here as a readable, self-contained case study. The useful parts of the report and workbook are shown directly on the page so the reader can follow the reasoning without opening a file.
Every gap is tied to an evidence question, accountable owner, and closure condition.
Likelihood, impact, inherent risk, residual risk, treatment, and remediation target are summarized above.
The roadmap sequences scope, privilege, recovery, telemetry, transfer controls, and response/supplier readiness.
The assessment is scoped at an outcome and control-family level. A real engagement would add exact requirement identifiers, assessment objectives, source locations, collection dates, evidence owners, and artifact hashes.
The companion project demonstrates hands-on evidence preservation, Windows investigation, and incident-response reasoning.
08 / selected control mapping
From business concern to control family
This is a selected mapping for communication—not a claim that six findings represent the full NIST requirement set. It shows how the assessment translates operational concerns into a framework conversation.
F-001 · boundary and assets
Asset Management
Can we prove what is in scope and who owns it?
F-002 · privileged access
Identity and Access Management
Can a compromised identity reach the enclave without a reviewed control?
F-003 · telemetry
Continuous Monitoring
Can we detect and reconstruct activity across the boundary?
F-004 · CUI transfer
Data Security
Can CUI leave through an approved, visible, accountable path?
F-005 · recovery
System and Services Acquisition / Contingency Planning
Can the enclave be restored and verified within its recovery objectives?
F-006 · response and suppliers
Incident Response / Supply Chain Risk Management
Are response decisions and supplier dependencies exercised before an event?
09 / workbook transcription
Assessment dashboard and scope record
The following tables reproduce the workbook’s operating content. Values are shown as assessed, including the formula outputs: 8 outcome areas, current maturity 1.625/4.0, target maturity 3.750/4.0, average gap 2.125, and 6 high/critical residual risks.
Assessment items
8
Scoped outcome areas
Current maturity
1.625 / 4.0
Average current score across A-001 through A-008
Target maturity
3.750 / 4.0
Average target profile
Average maturity gap
2.125 points
Target minus current
High/Critical residual risks
6
Two Critical and four High
Govern
1.5
3.5
2.0
Risk appetite, policy ownership, exceptions, and supplier governance are not consistently formalized.
Identify
1.5
3.5
2.0
The CUI boundary and authoritative asset ownership are incomplete.
Protect
2.0
4.0
2.0
Baseline capabilities exist, but privileged access, workstation drift, and transfer evidence remain inconsistent.
Detect
2.0
4.0
2.0
Identity and endpoint telemetry is present; enclave firewall and file-server coverage is unreliable.
Respond
1.0
4.0
3.0
No enclave-focused ransomware/CUI-exfiltration tabletop was completed in the last 12 months.
Recover
2.0
4.0
2.0
Datto BCDR on-premises protection and cloud recovery copies exist, but full enclave recovery is not evidenced.
10 / architecture and scope
What was assessed
Corporate IT
Windows 11 endpoints, Windows Server Active Directory, Entra ID, commercial collaboration tenant, productivity systems.
CUI prohibited; policy and DLP controls prevent intentional storage.
CUI Engineering Enclave
Dedicated directory, virtualized Windows servers, encrypted engineering file shares, CAD workstations, controlled transfer gateway.
In scope; primary system boundary.
Network Security
Cisco perimeter and enclave firewalls, Cisco switching, Windows administrative jump host, segmented engineering and production networks.
In scope where components enforce or monitor the enclave boundary.
Security Operations
Windows Event Forwarding, Windows Defender endpoint telemetry, Splunk SIEM, Tenable vulnerability management, centralized ticketing and evidence repository.
In scope as protective and detective services.
Resilience and Suppliers
Datto BCDR for on-premises server protection and cloud off-site recovery copies, restoration procedures, remote contractors, approved suppliers, controlled file exchange.
In scope where services store, transmit, or protect CUI.
Classified Operations
Separate accredited facility and classified information system boundary supporting government programs that may include Top Secret material; dedicated personnel, access controls, handling procedures, and approved classified workflows.
Not assessed here; isolated from Corporate IT and the unclassified CUI enclave.
Fictional 250-person aerospace and defense manufacturer.
Evaluate readiness to protect CUI, prioritize business risk, and produce an actionable remediation roadmap.
Classified systems and government-furnished systems are part of the broader fictional operating model but are excluded from this unclassified CUI assessment, along with physical production machinery and an independent CMMC certification assessment.
No real employer stack, proprietary information, production evidence, or real company claims are represented.
11 / complete CSF assessment
Outcome-by-outcome assessment matrix
Current and target maturity use the workbook’s 0–4 scale: 0 Not started, 1 Ad hoc, 2 Partial, 3 Defined, 4 Measured.
A-001
Govern
Risk Strategy and Oversight
CUI obligations, risk appetite, security responsibilities, policies, and exceptions are documented and reviewed.
2
4
2
Partial
E-001, E-002
Leadership can make informed tradeoffs between mission delivery, contract obligations, and security investment.
A-002
Identify
Asset Management and Boundary
Hardware, software, accounts, data stores, interfaces, and CUI flows are inventoried and assigned owners.
1
4
3
Gap
E-003, E-004
The organization can identify what must be protected and what could affect customer delivery.
A-003
Identify
Risk Assessment
Threats, vulnerabilities, likelihood, impact, and residual risk are assessed using a repeatable method.
2
3
1
Partial
E-005
Security spending is tied to business consequences instead of isolated technical opinions.
A-004
Protect
Access, Configuration, and Media
Least privilege, strong authentication, secure baselines, patching, encryption, and approved transfer paths protect CUI.
2
4
2
Partial
E-006
A stolen credential or removable device is less likely to expose engineering information.
A-005
Detect
Audit and Continuous Monitoring
Identity, endpoint, server, and network events are collected, retained, correlated, and reviewed.
2
4
2
Partial
E-007
The security team can identify suspicious activity earlier and reconstruct events with defensible evidence.
A-006
Respond
Incident Management and Exercises
The enclave has response roles, decision points, communications, exercises, and lessons-learned tracking.
1
4
3
Gap
E-008
A security incident causes less confusion, downtime, and delayed customer communication.
A-007
Recover
Backups and Restoration
Critical systems and CUI data are protected by Datto BCDR on-premises and in the cloud, then restored through tested procedures.
2
4
2
Partial
E-009
Recovery time and customer delivery commitments are based on demonstrated capability.
A-008
Govern
Supply Chain Risk
Suppliers that can affect CUI confidentiality, integrity, or availability are tiered, evaluated, and monitored.
1
3
2
Gap
E-010
Third-party weaknesses are identified before they interrupt programs or create disclosure risk.
12 / complete risk register
Findings, threat scenarios, scoring, owners, and evidence
Inherent score equals likelihood × impact. Residual score applies the documented control-effectiveness assumption. Risk bands are Critical at 15+, High at 8–14, Moderate at 4–7, and Low at 0–3.
F-001
CUI system boundary and asset inventory are incomplete
Asterion cannot reliably prove which systems protect CUI or identify every asset that could affect contract data. An unmanaged system could become an entry point.
Planning; Risk Assessment
4
5
20
20%
16
Critical
GRC Manager
Mitigate
2026-09-30
E-003, E-004
F-002
Privileged access controls are not consistently enforced
A compromised administrator account could provide access to engineering files, security tooling, or virtualization hosts, creating operational disruption and CUI exposure.
Access Control; Identification and Authentication
4
5
20
25%
15
Critical
Infrastructure Manager
Mitigate
2026-09-30
E-006
F-003
Security telemetry coverage and retention are inconsistent
The security team may be unable to detect or reconstruct unauthorized activity quickly, increasing dwell time, investigation cost, and customer notification risk.
Audit and Accountability
4
4
16
35%
10
High
SOC Lead
Mitigate
2026-10-31
E-007
F-004
CUI transfer and removable-media controls lack consistent evidence
Technical data could be copied to an unapproved device or service without timely detection, creating disclosure and contract risk.
Media Protection; System and Communications Protection
3
5
15
30%
11
High
Security Architect
Mitigate
2026-10-31
E-006
F-005
Backup restoration capability has not been fully demonstrated
Recovery time and data integrity remain assumptions until a full enclave restoration is tested and documented.
System and Information Integrity
3
5
15
40%
9
High
Infrastructure Manager
Mitigate
2026-09-30
E-009
F-006
Incident response and supplier-risk processes are immature
Untested response decisions or supplier weaknesses could lengthen downtime, delay containment, or create an unplanned contract remediation burden.
Incident Response; Supply Chain Risk Management
3
4
12
30%
8
High
Security and GRC Leads
Mitigate
2026-10-31
E-008, E-010
13 / complete POA&M
Plan of Action and Milestones
Each remediation item is written as a measurable outcome with an owner, start date, due date, dependency, and closure condition. Every item begins as Not Started.
P-001
F-001
Publish CUI boundary, data-flow map, asset register, and accountable owners.
GRC Manager
Critical
2026-08-24
2026-09-30
100% of in-scope assets have owner, location, data type, and protection status.
Not Started
Engineering and infrastructure workshops
P-002
F-002
Remove shared privileged accounts and enforce hardware-backed MFA for enclave administration.
Infrastructure Manager
Critical
2026-08-24
2026-09-30
All privileged identities are unique, MFA-protected, approved, reviewed, and logged.
Not Started
Directory and jump-host changes
P-003
F-005
Perform a full enclave restoration exercise using Datto BCDR and document RTO/RPO results.
Infrastructure Manager
High
2026-09-01
2026-09-30
Full Datto BCDR restore test completed with documented results and corrective actions.
Not Started
Backup owner and isolated test window
P-004
F-003
Create telemetry coverage matrix and onboard missing firewall and file-server sources.
SOC Lead
High
2026-09-08
2026-10-31
All in-scope identity, endpoint, server, and network sources report healthy status.
Not Started
Asset boundary and firewall owners
P-005
F-004
Approve CUI transfer paths and implement removable-media approval and logging.
Security Architect
High
2026-09-15
2026-10-31
All approved transfer paths are documented and exception records are auditable.
Not Started
Data-flow map and engineering process owners
P-006
F-006
Run an enclave ransomware and CUI-exfiltration tabletop; tier suppliers by CUI access.
Security and GRC Leads
High
2026-09-21
2026-10-31
Exercise completed, decisions recorded, corrective actions assigned, and CUI-impacting suppliers tiered.
Not Started
Updated enclave playbooks and supplier inventory
14 / complete evidence register
Evidence statements used in the assessment
These are synthetic evidence statements. In a real engagement, each record would point to a source location, evidence owner, collection date, and artifact hash.
E-001
Document review
Security charter and policy set
Policies exist but do not consistently define CUI ownership, exception expiration, or risk acceptance authority.
Medium
Supports current-state scoring and/or finding linkage
E-002
Interview
Executive risk discussion
Leadership prioritizes program delivery but risk appetite is not formally recorded.
Medium
Supports current-state scoring and/or finding linkage
E-003
System record
CMDB and enclave inventory
Corporate inventory is operationally useful; enclave inventory is separate and contains duplicate records.
Medium
Supports current-state scoring and/or finding linkage
E-004
Workshop
CUI data-flow workshop
Engineering shares and approved transfer gateway were identified; a legacy supplier exchange path remains unresolved.
Medium
Supports current-state scoring and/or finding linkage
E-005
Risk register review
Enterprise risk register
Cyber risks are present but not consistently linked to systems, owners, or treatment dates.
High
Supports current-state scoring and/or finding linkage
E-006
Access and endpoint review
Privileged access and workstation sample
Separate administrator identities exist for most staff; two legacy service accounts remain shared and 18 percent of sampled engineering workstations show baseline drift.
High
Supports current-state scoring and/or finding linkage
E-007
SIEM source and retention review
Splunk source list
Windows identity, endpoint, and server events are covered; two Cisco enclave firewalls and one Windows engineering file server do not forward reliably, and retention varies by source.
High
Supports current-state scoring and/or finding linkage
E-008
Exercise and runbook review
Incident response evidence
Enterprise response plan exists, but no enclave-focused tabletop was completed in the last 12 months.
High
Supports current-state scoring and/or finding linkage
E-009
Backup and restore review
Datto BCDR evidence
Critical systems have successful on-premises backups and cloud off-site copies; a full enclave recovery test is not documented.
High
Supports current-state scoring and/or finding linkage
E-010
Supplier review
Supplier security questionnaires
High-value suppliers are reviewed inconsistently and CUI access tiering is not standardized.
Medium
Supports current-state scoring and/or finding linkage
15 / method and references
How the assessment was performed
Primary requirements lens
NIST SP 800-171 Rev. 3 readiness alignment for the CUI enclave.
Assessment procedures
NIST SP 800-171A Rev. 3 concepts: examine, interview, and test evidence.
Executive communication
NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, Recover.
Risk method
NIST SP 800-30 Rev. 1 concepts: threat, vulnerability, likelihood, impact, and residual risk.
Classified-program treatment
The classified environment is represented as a separate operational boundary. This page does not assess Top Secret handling, classified system accreditation, personnel clearance eligibility, facility clearance, or contract-specific DD 254 requirements.
Maturity scale
0 Not started · 1 Ad hoc · 2 Partial · 3 Defined · 4 Measured.
Risk bands
Residual score 15+ Critical · 8–14 High · 4–7 Moderate · 0–3 Low.
NIST Cybersecurity Framework 2.0
Executive communication and organizational profile.
NIST SP 800-171 Rev. 3
CUI protection requirements and control-family lens.
NIST SP 800-171A Rev. 3
Assessment procedures, evidence, and assessment depth.
NIST SP 800-30 Rev. 1
Likelihood, impact, and risk treatment method.
32 CFR Part 117 / NISPOM
Classified contractor security context; referenced for boundary awareness only, not assessed for compliance.
This workbook is a portfolio simulation using fictional company details and synthetic evidence. It does not establish compliance, certification eligibility, legal sufficiency, a CMMC score, a facility clearance, or authorization to handle classified information. The classified-program references describe a separate boundary that would require its own contract-specific security requirements, facility/personnel controls, system authorization, and government oversight.
FOLLOW-UP / INCIDENT RESPONSE PROGRAM
The assessment ends with a handoff to operations
The GRC work identifies six priority findings. The linked follow-up turns those findings into a directive incident-response program for the same fictional environment: Entra identity compromise, Windows endpoints, FortiGate containment, Splunk investigation, Datto recovery, provider handoffs, playbooks, and a tabletop.
Open the incident-response follow-up ↗16 / incident-response operating model
The response plan turns the gap into a capability
The GRC assessment identified response, supplier coordination, telemetry, and recovery evidence as decision gaps. The companion plan makes those gaps operational: who declares an incident, which provider acts, what evidence is preserved, what can be contained, and what must be proven before recovery.
Cloud identity is the control plane; the on-premises domain controller is treated as a dependency that requires separate scoping and evidence.
FortiGate provides perimeter, VPN, policy, and administrative control points for containment and investigation.
File, application, and database dependencies are assessed and recovered as separate services with integrity checks.
Endpoint isolation, Defender evidence, Windows event collection, reimage criteria, and user communication are defined.
The SOC triages and preserves telemetry; the security lead owns incident decisions and corrective actions.
On-premises protection and cloud recovery copies support recovery, but a backup job is not accepted as restoration evidence.
Separate responsibilities, escalation rules, evidence requirements, and no-unilateral-closure expectations are documented.
17 / architecture and trust boundaries
Response decisions follow the actual environment
The fictional environment is intentionally small enough to reason about and realistic enough to expose dependency risk. There is one internet path, one identity stack with hybrid dependency, one file server, one application server, one SQL server, Windows workstations, centralized detection, and a separate backup control plane.
Internet edge
One ISP → FortiGate perimeter firewall → internal Cisco switching
Preserve FortiGate traffic, VPN, admin, and configuration-change evidence; use the firewall as a containment control, not the only source of truth.
Identity
Microsoft Entra ID is the cloud identity plane; AD-DC01 is the on-premises directory dependency
Disable or restrict identities in Entra, invalidate sessions, review privileged roles, and preserve sign-in, audit, and directory evidence.
Workstations
Windows laptops and desktops used by staff and engineering users
Isolate affected endpoints, preserve volatile context where practical, collect Defender and Windows event evidence, and reimage from a trusted baseline when required.
File services
FS01 provides the primary file-server dependency for shared engineering and business data
Check share access, mass-change indicators, staged archives, shadow copies, and the last known-good recovery point before restoring.
Application and database
APP01 hosts the business application; SQL01 hosts its database dependency
Contain application credentials and database access separately; validate application integrity and transaction consistency before service return.
Detection
Splunk receives identity, endpoint, server, and network telemetry
SOC triage must identify source health, search time range, query owner, evidence export location, and retention before closing an incident.
Resilience
Datto BCDR protects on-premises servers and maintains cloud recovery copies
Treat backup consoles and retention policies as high-value targets; preserve configuration evidence and test restoration in an isolated recovery network.
Classified work remains a separate accredited facility and classified information system boundary. This incident-response program covers the unclassified corporate/CUI operating model only; it does not assess classified systems, classified handling, or authorization requirements.
18 / roles and supplier handoffs
Providers execute tasks; the organization owns the decision
The third-party IT company and third-party SOC company are separate on purpose. The SOC provides detection and investigation; IT provides infrastructure execution and recovery. Neither provider can silently accept risk, close a case, or make a CUI-impact determination without the internal security/GRC owner.
Internal leadership
Owns business risk acceptance, customer/contract decisions, materiality, and recovery priority.
Receives severity updates and approves decisions that change mission, legal, or customer exposure.
Third-party IT company
Provides infrastructure administration, FortiGate/Windows/Datto execution, system recovery support, and technical change records.
Acts on approved containment and recovery requests; does not unilaterally close a security incident.
Third-party SOC company
Provides monitoring, triage, Splunk investigation, escalation, detection tuning, and evidence packaging.
Opens and updates the case, preserves relevant telemetry, and hands off with timestamps, queries, and confidence.
Security / GRC lead
Owns incident command, CUI impact assessment, evidence standard, playbook selection, communications cadence, and corrective actions.
Coordinates the providers and connects lessons learned back to the POA&M and risk register.
19 / severity and workflow
Severity is a decision aid, not a label
Severity is based on business disruption, CUI impact, privileged access, spread, evidence confidence, and recovery risk. The plan uses a common clock so the SOC, IT provider, leadership, and security lead can act without waiting for a perfect narrative.
- S1Detect and open
Open one case, capture the initial signal, assign an incident lead, preserve the time window, and record what is still unknown.
- S2Classify and scope
Identify affected users, endpoints, servers, network paths, providers, data types, and possible CUI exposure.
- S3Contain deliberately
Choose identity, endpoint, network, server, or backup-plane containment with an owner, expected impact, rollback condition, and timestamp.
- S4Eradicate and validate
Remove persistence, rotate exposed secrets, close the entry path, verify telemetry, and confirm that the threat is no longer active.
- S5Recover from trusted state
Restore in an isolated network, validate identity and application dependencies, confirm data integrity, and document RTO/RPO results.
- S6Communicate and close
Provide scheduled leadership updates, coordinate customer/contract decisions through authorized owners, and close only after corrective actions are assigned.
20 / playbook catalog
Five playbooks cover the highest-consequence paths
Each playbook uses the same structure: trigger, first-hour actions, investigation questions, containment, recovery, communications, evidence, and after-action requirements. That keeps the plan directive while leaving room for the providers to execute within their approved procedures.
Trigger: Ransom note, mass file changes, archive staging, or evidence of transfer from FS01/engineering workstations.
First move: Isolate affected endpoints; protect identity and backup control planes; preserve evidence; make the CUI-impact decision before broad restore.
Trigger: Impossible travel, unfamiliar MFA activity, token/session abuse, unexpected role assignment, or admin behavior outside change windows.
First move: Disable or restrict the identity, revoke sessions, identify downstream access, and verify no persistence or new privileged principal exists.
Trigger: Defender detection, suspicious PowerShell, persistence, credential theft, or lateral movement from a laptop/desktop.
First move: Network-isolate the endpoint, preserve host context, scope adjacent identities and systems, then reimage or remediate from a trusted baseline.
Trigger: Datto retention changes, protected-device deletion, unusual console access, or failed jobs coinciding with an incident.
First move: Protect Datto administration, preserve console evidence, verify recovery points, and use an isolated restore decision path.
Trigger: Mailbox-rule change, credential phishing, fraudulent payment instruction, or supplier impersonation.
First move: Contain identity and mailbox persistence, validate out-of-band payment/process changes, and check for CUI access or forwarding.
21 / tabletop exercise
A realistic inject tests the seams between teams
The exercise scenario begins with an Entra identity alert and ends with an isolated Datto recovery. It deliberately crosses the SOC, IT provider, security/GRC lead, leadership, and business owners so the test measures coordination—not just whether one person knows a command.
01 / detect
The SOC receives an Entra risky sign-in alert for a user who recently accessed engineering shares.
Who owns the case, what severity is declared, and what evidence is preserved before account action?
02 / scope
The user’s Windows laptop shows PowerShell activity and a new archive staged for transfer.
How do the SOC and IT provider isolate the endpoint while the security lead assesses possible CUI exposure?
03 / contain
FS01 begins showing rapid file modifications; APP01 and SQL01 remain available.
Which systems are isolated, who approves the boundary change, and how is business continuity weighed?
04 / recover
A Datto retention policy was modified shortly before the file changes were detected.
How is the backup plane protected, and what makes a recovery point trusted enough to restore?
05 / communicate
Leadership asks whether customer notification, contract review, or law-enforcement coordination is required.
What is known, what is not known, who can approve external communication, and when is the next update?
06 / improve
The enclave is restored in an isolated network and evidence review finds a telemetry gap.
Which corrective actions become POA&M updates, detection changes, provider SLA changes, or training tasks?
Capture who decided what, when, with which evidence, and what assumption remained open.
Participants identify the affected boundary, protect the backup plane, and choose a trusted restore path.
Every gap becomes an owner, due date, evidence requirement, and retest condition.
22 / detection and evidence
Telemetry is part of the response product
The response plan treats evidence as an operating deliverable. The SOC must preserve enough context for the organization to explain what happened, what was affected, what was contained, and why recovery was trusted.
Identity
Entra sign-in and audit logs; privileged-role changes; risky sign-ins; MFA and session state
SOC / security lead
Preserve before disabling accounts where feasible; record UTC time window and export location.
Perimeter
FortiGate traffic, VPN, admin, policy, and configuration-change logs
IT provider / SOC
Capture policy changes and suspected command-and-control or exfiltration paths.
Windows
Defender alerts, Windows Security logs, PowerShell, scheduled tasks, services, autoruns, and endpoint timeline
SOC / IT provider
Collect from affected laptops, desktops, AD-DC01, FS01, APP01, and SQL01 as applicable.
File activity
FS01 share access, file-change indicators, staged archives, permissions, and shadow-copy status
IT provider
Use to bound CUI exposure and select a last-known-good restore point.
Application / SQL
APP01 application logs, SQL01 authentication, query, job, and integrity indicators
Application owner / IT provider
Validate both service integrity and data integrity before returning to production.
Backups
Datto job history, retention-policy changes, protected-device status, recovery-point inventory, and restore logs
IT provider / security lead
Treat unexpected deletion or retention changes as potential attacker activity.
23 / recovery and validation
Recovery is not complete until the service and the evidence agree
Datto protection reduces the likelihood of permanent loss, but recovery still requires a trusted restore point, a clean identity path, validated dependencies, and a decision record. The program separates restoration from return-to-service so urgency does not erase verification.
Secure Datto administration, preserve policy changes, validate recovery points, and use an isolated restore network.
Check AD-DC01 identity dependency, FS01 data integrity, APP01 behavior, and SQL01 authentication and transactions.
Confirm Entra, FortiGate, Windows, server, and Splunk visibility before reconnecting systems to production.
Leadership and the service owner accept residual risk, recovery results, customer impact, and remaining corrective actions.
24 / GRC-to-IR crosswalk
Every major finding has an operational response hook
Pairing the projects makes the portfolio story stronger because it shows the lifecycle from assessment to action. The GRC register explains why the work matters; the response program shows how the organization would behave under pressure and how lessons return to governance.
F-001 / boundary and assets
IR-01, IR-03
The asset register and data-flow map define which identities, endpoints, servers, network controls, and providers must be searched and contained.
F-002 / privileged access
IR-02, IR-04
Entra privileged-role review, FortiGate administration, Datto console access, and provider access are explicit containment decisions.
F-003 / telemetry
IR-01, IR-03
Splunk source health and Windows/FortiGate/Entra coverage are part of triage; missing telemetry is recorded as a response limitation.
F-004 / CUI transfer
IR-01, IR-05
Archive staging, mailbox forwarding, removable media, and supplier exchange paths are investigated as possible CUI movement.
F-005 / recovery evidence
IR-04
Datto recovery-point integrity, isolated restoration, RTO/RPO results, and corrective actions close the recovery gap.
F-006 / response and suppliers
IR-01 through IR-05
The master plan, provider handoff model, tabletop, and after-action workflow turn the finding into an operating capability.