Case Study // Audit & Assurance
Cybersecurity Audit & Assessment Playbook
A source-backed route from enterprise assessment strategy to evidence, prioritized risks, remediation, and stakeholder reporting.
Overview
This case study combines an enterprise assessment approach with a cybersecurity key-risk playbook. Together, the documents show how I move from assessment scope and control expectations to a concise risk summary with accountable recommended actions.
The playbook contains 13 scenario-based risks: three Critical, five High, four Elevated, and one Moderate.
Scenario
A fictional financial-services environment needs an enterprise security assessment that reaches beyond vulnerability identification. Leadership needs to understand control effectiveness, evidence quality, business impact, remediation ownership, and what should be monitored after the assessment.
Aegis Quantum Trust is a fictional enterprise environment used across selected portfolio projects to demonstrate governance, risk, compliance, audit, security, and AI governance decision-making in a consistent business context.
Objective
Create a repeatable, risk-based and compliance-informed assessment method, then translate source observations into a prioritized key-risk playbook that leaders, control owners, and assurance stakeholders can use.
My Approach
- Defined assessment scope by domain, system, data type, stakeholder, and control owner.
- Used a hybrid risk-based and compliance-informed strategy to evaluate enterprise control effectiveness.
- Connected risk to control expectation, expected evidence, remediation, and continuing monitoring.
- Reviewed user-domain access, RBAC, zero-trust access, SOP quality, training consistency, and application interactions.
- Converted technical observations into 13 risk statements with severity, business impact, recommended next step, and responsible area.
- Preserved evidence limitations and avoided claiming that recommendations had been implemented.
Frameworks & Methods
- NIST as a flexible enterprise control framework
- OWASP concepts for applications processing sensitive information
- Risk-based assessment scoping
- RBAC, least privilege, MFA, and zero-trust access review
- Evidence planning and control documentation
- Probability-impact severity bands
- Remediation ownership and stakeholder reporting
Key Findings
- Unsupported SQL Server and Windows Server platforms drive the three Critical risks.
- Default credentials, shared administrative access, and privilege misalignment weaken accountability and increase blast radius.
- Legacy VPN design lacks consistently demonstrated MFA, segmentation, and role-specific access.
- Vendor and contractor connectivity requires business justification, permission review, segmentation, and retained evidence.
- BYOD, broad file-access defaults, weak certificate signatures, and job-role leakage expand the control surface beyond patching alone.
What This Demonstrates
Audit readiness, enterprise assessment planning, evidence design, risk prioritization, control analysis, remediation thinking, identity and vendor-risk awareness, and technical-to-business communication.
Artifact Preview
| ID | Band | Risk area | Recommended direction | Owner |
|---|---|---|---|---|
| RISK-001 | Critical | Legacy SQL Server platform | Upgrade and migrate to a supported platform | IT / Infrastructure |
| RISK-003 | Critical | HTTP.sys remote-code-execution exposure | Migrate Windows Server and validate web configuration | Systems Engineering |
| RISK-006 | High | Privileged-access misalignment | Separate standard/admin accounts and review Domain Admins | IAM / Security Governance |
| RISK-008 | High | Vendor and contractor remote access | Segment, justify, review, and retain access evidence | Third-Party Risk / IT |
| RISK-010 | Elevated | File-access governance gaps | Centralize controls and reduce default visibility | Data Owners / IAM |
View / Download Artifact
Assessment method + key-risk playbook
Download the methodology document and the corresponding 13-risk executive playbook.
Source Note / Disclosure
Both documents are scenario-based portfolio artifacts derived from academic/source materials. AQT is fictional. Findings are assessment observations and recommendations, not claims of client work or completed control implementation. Two supplied playbook filenames were byte-for-byte identical; only one public copy is included.