Using NIST SP 800-53, I conducted a vulnerability assessment based on a small e-commerce website. The assignment demanded a full assessment of the company's attack surfaces, as well as the likelihood and severity of exploitation of these surfaces with various vectors. The assignment provided me an opportunity to learn NIST frameworks and apply likelihood and severity assessments to surfaces and vectors to gain an understanding of threat order and priority.
Log analysis and data visualization are a critical part of becoming an effective cybersecurity analyst. With tools like Splunk, these tasks are made easy. Through Rize, I was given the chance to practice using Splunk by creating charts, organizing information, and sifting through long logs to communicate important metrics and attack patterns in a visual manner. I learned the importance that visual emphasis plays when seeking fraud patterns, especially when communicating these patterns to upper and executive management.
Using a collection of analysis skills, framework knowledge, and executive communication strategy, the Incident Analysis Report and Executive Briefing were performed as my final project, combining all the skills I learned in my first Cybersecurity course with Rize. After filtering noise with log data using CoCalc and log analysis shortcuts, I confirmed an attempt to exfiltrate financial data. The Executive Briefing demanded a combination of presentation and PowerPoint skills with relevant frameworks, such as NIST and MITRE ATT&CK, and jargon-free executive recommendations and recovery procedures. This project combines with my unique skill stack of analytics, organization, and creativity because of its rigid structure with hints of forensic mystery and investigation. Sorting through logs and organizing timelines must be done with precision, care, and structure. On the other hand, critical thinking skills and creativity play a part in knowing where to look first when sifting through initial logs. Finally, this project demanded soft skills such as communication and executive-ready presenting, which rounded out analytical, structural, and critical thinking skills.