with complete solution
D490 – Cybersecurity Capstone
Task 3: Technology-Supported Security Solution
A. Describe the policies adopted as a result of your implemented
project.
MoBank Credit Union has implemented comprehensive security policies
to strengthen its cybersecurity framework and ensure compliance with
industry regulations. The Zero Trust policy requires strict authorization
before granting access to any user or device. To enhance security further,
Multi-Factor Authentication is now mandatory for all system logins,
reducing the risk of unauthorized access due to compromised credentials.
With the principle of least privilege, Identity Access Management ensures
that users only have access to the data and systems needed for their roles.
This minimizes the risk of insider threats and unauthorized access. End-to-
end encryption is enforced for all financial transactions and stored customer
data, protecting sensitive information from potential breaches.
MoBank has also introduced continuous security monitoring and an
incident response policy with the adoption of automated Intrusion Detection
Systems and Security Information and Event Management tools, enabling
real-time threat detection, automated alerts, and structured response
procedures to address cyber threats quickly. To further strengthen security,
the company mandates regular vulnerability scans, penetration testing, and
timely patch management to identify and fix weaknesses proactively. For
remote employees, a Remote Work Security Policy enforces using secure
Virtual Private Networks, device security protocols, and endpoint protection
to safeguard against external threats. Recognizing the role of human error
in cyber incidents, MoBank has also made cybersecurity training and
phishing awareness programs mandatory, helping employees identify and
prevent social engineering attacks. Finally, regular compliance audits
,aligned with NIST, PCI-DSS, GLBA, and FFIEC standards ensure MoBank
complies with federal and financial security regulations. By implementing
, these policies, MoBank has built a robust security posture, protecting its
customers and business operations from evolving cyber threats.
B. Describe how your solution meets the following cybersecurity
assurance criteria:
Promoting Automation in Cybersecurity
Implementing Microsoft 365 Business promotes automation in
cybersecurity for MoBank by leveraging AI-driven security features,
automated threat detection, and integrated identity and access
management. Microsoft 365’s cloud-based security ecosystem provides
continuous monitoring, real-time alerts, and automated responses,
enhancing MoBank’s ability to detect, prevent, and mitigate cyber threats
efficiently. Microsoft 365 includes Microsoft Defender for Business, which
automates threat detection, investigation, and response to malware,
phishing, and ransomware attacks. Microsoft Sentinel (SIEM/SOAR)
provides automated security event monitoring, aggregating data from
multiple sources to detect anomalies and generate alerts (Microsoft, 2024).
Microsoft 365’s Data Loss Prevention policies automatically detect and
restrict the sharing of sensitive financial information, ensuring compliance
with NIST, PCI-DSS, GLBA, and FFIEC regulations. Using Microsoft Intune,
MoBank can automate device security management, software updates, and
compliance enforcement across all employee devices, ensuring endpoints
are protected against vulnerabilities. Automated security policies enforce
firewall settings, encryption, and application restrictions, reducing the risk
of compromised devices.
Improving and Modernizing Security
MoBank has adopted a Zero Trust Architecture, ensuring all users and
devices are continuously authenticated and authorized before accessing
resources. With Azure Active Directory, MoBank will enhance user identity
verification and access control through features like Conditional Access,