E. Ologunde Case file
UNCLASSIFIED // FOR ACADEMIC USE — Zero Trust · ICAM · CMMC Presentation Research Guide
Cybersecurity Architecture · Academic Reference

Zero Trust, ICAM & CMMC
Presentation Research Guide

A slide-by-slide research walkthrough: what to read, where to find it, and what to watch — so every slide answers why this matters for your specific system.

Before you start: The assignment says "show understanding, not definition dumping." That means every slide should answer the question why does this matter for my specific system? — not just explain what a term means. Read that requirement again before writing a single word.
SLIDES 1–3

Foundation: Your System, Your Environment

SLIDE 01

Title Slide

No research needed here. Choose your system environment before you fill in anything else — it drives every other slide. Pick something specific: a military logistics platform, a healthcare network, a defense contractor IT system, a university research lab, a state emergency management network. The more specific your scenario, the easier every other slide becomes.

SLIDE 02

System and Mission Overview

What this slide is really asking If this system goes down or gets compromised, what real-world consequence follows? Describe the mission first, then the technology that supports it.
What to research
YouTube — watch to understand mission context
  • Search "DoD Zero Trust strategy explained 2024" — look for DISA, AFCEA, or government conference panels
  • Search "why Zero Trust matters for government systems" — NetworkChuck or John Hammond
SLIDE 03

Architecture Context

What this slide is really asking What type of environment are you securing — and what makes it hard to secure? Budget, legacy systems, remote users, and uptime requirements all change what security decisions are available to you.
What to research
YouTube
  • Search "cloud vs hybrid vs on-prem security architecture explained"
  • Search "legacy system security challenges government"

SLIDES 4–5

Users and Threats

SLIDE 04

Operator and User Needs

What this slide is really asking Security that makes operators slower or unable to do their jobs is not good security — it is a different kind of failure. Who uses the system, what speed or access do they need, and what does friction look like in your scenario?
What to research
  • DoD Zero Trust Strategy, pages 6–8 — user experience requirements alongside security dodcio.defense.gov · DoD-ZTStrategy.pdf
  • OMB Memorandum M-22-09 — how agencies balance user needs with Zero Trust mandates Search: OMB M-22-09 zero trust whitehouse.gov PDF
  • FICAM Architecture (idmanagement.gov) — user roles and access patterns idmanagement.gov/arch/
YouTube
  • Search "zero trust user experience challenges"
  • Search "identity-centric security explained simply" — IBM Technology or Microsoft Security
SLIDE 05

Threats Relevant to This System

What this slide is really asking Do not write "ransomware" and "phishing" as generic threats. Write the specific threat that would target your specific system — and explain the realistic damage it would cause to the mission, not just to data.
What to research
YouTube
  • Search "advanced persistent threat APT explained" — SANS Institute or CISA
  • Search "insider threat cybersecurity government 2023 2024"
  • Search "supply chain attack cybersecurity explained" — John Hammond or CISA YouTube

SLIDES 6–7

Zero Trust

SLIDE 06

Zero Trust: Core Concepts

What this slide is really asking Explain the four concepts in your own words. What does "never trust, always verify" actually mean when a user tries to open a file? What does "least privilege" mean in practice? Do not quote definitions — write what these mean and why they exist.
What to research
Key idea to understand Zero Trust does not mean you trust nothing forever — it means you verify continuously and grant access only for what is needed, for as long as it is needed. The perimeter is no longer the network edge. The perimeter is now the identity and the device.
YouTube — highly recommended
  • Search "Zero Trust security model explained NIST 800-207"
  • Search "never trust always verify zero trust explained" — IBM Technology, Microsoft Security, or NetworkChuck
  • Search "zero trust architecture beginner 2024" — Professor Messer or TechTarget
SLIDE 07

Where Zero Trust Applies in This System

What this slide is really asking Take the concepts from Slide 6 and connect them to your specific scenario. Where are the trust boundaries in your system? Who or what makes access decisions? What replaced the old "inside the firewall = trusted" model?
What to research
YouTube
  • Search "zero trust network access ZTNA explained" — Cloudflare or Zscaler
  • Search "micro-segmentation zero trust explained"
  • Search "policy decision point policy enforcement point zero trust"

SLIDES 8–10

ICAM

SLIDE 08

ICAM: Core Concepts

What this slide is really asking Explain each part of the acronym — Identity, Credential, Access Management — and explain the identity lifecycle (join, role change, departure). Then explain why none of Zero Trust works without ICAM.
What to research
Key idea to understand Authentication answers "Are you who you say you are?" Authorization answers "Are you allowed to do what you are trying to do?" Both are required. ICAM manages both — plus the full lifecycle of who has access and why.
YouTube
  • Search "identity credential access management ICAM explained"
  • Search "identity lifecycle management joiner mover leaver" — Microsoft Security or IBM Technology
  • Search "privileged access management PAM explained" — CyberArk YouTube
  • Search "authentication vs authorization explained"
SLIDE 09

ICAM Applied to the System

What this slide is really asking Move from concepts to your specific scenario. How does your system know who a user is? How does it limit what they can access? What happens when someone changes roles or leaves? How is privileged access controlled differently from standard access?
What to research
  • FICAM Playbooks — practical implementation guides for provisioning, PIV, federation (scroll to "Playbooks" section) idmanagement.gov/arch/
  • NIST SP 800-63B — authentication assurance levels (AAL1, AAL2, AAL3) Search: NIST SP 800-63B digital identity guidelines PDF
  • ICAM Program Management 101 — provisioning, deprovisioning, and governance idmanagement.gov/university/pm/
YouTube
  • Search "role-based access control RBAC vs attribute-based ABAC explained"
  • Search "zero trust identity governance explained 2024"
  • Search "multi-factor authentication MFA explained" — Professor Messer or Microsoft Security
SLIDE 10

Device Trust and Access Decisions

What this slide is really asking In Zero Trust, it is not enough to know who you are — the device you are using also matters. A managed, patched, compliant device is treated differently than a personal or unmanaged one. What device signals matter and how do they factor into access decisions?
What to research
YouTube
  • Search "device compliance conditional access zero trust explained" — Microsoft Mechanics or John Savill
  • Search "endpoint detection response EDR zero trust"
  • Search "mobile device management MDM explained"

SLIDES 11–12

CMMC

SLIDE 11

CMMC: Purpose and Scope

What this slide is really asking What is CMMC actually trying to protect, and which of the three levels fits your system? Do not list control numbers. Explain the purpose in plain language: protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) from adversaries who target the defense supply chain.
What to research
LEVEL 1 — Foundational
Basic cyber hygiene. For contractors handling Federal Contract Information (FCI) but not sensitive CUI. Annual self-assessment.
LEVEL 2 — Advanced
Aligns to NIST SP 800-171 (110 practices). For contractors handling CUI. Third-party assessment required for most contracts.
LEVEL 3 — Expert
For the most sensitive DoD programs. Based on NIST SP 800-172. Government-led assessment.
YouTube
  • Search "CMMC 2.0 explained 2024" — Cyber AB or official DoD channels
  • Search "what is controlled unclassified information CUI explained"
  • Search "CMMC Level 1 Level 2 Level 3 difference explained"
  • Watch: youtube.com/watch?v=MJtontfUEYs — DoD Zero Trust podcast (also relevant for Slide 15)
SLIDE 12

Where CMMC Applies in This Architecture

What this slide is really asking Which parts of your system fall under CMMC scope? How do the Zero Trust and ICAM controls you described earlier directly satisfy CMMC requirements — without being implemented just to check a box? And why is "we passed our assessment" not the same as "we are secure"?
What to research
YouTube
  • Search "compliance is not security cybersecurity explained"
  • Search "CMMC scope CUI boundary assessment"
  • Search "Zero Trust CMMC relationship explained DoD"

SLIDES 13–15

Analysis, Judgment, and Real-World Insight

SLIDE 13

Security vs Mission Tradeoffs

What this slide is really asking There is no such thing as perfect security that does not cost something. Identify at least five real tradeoffs in your specific system and explain the reasoning behind each choice — not just what the tradeoff is, but why you landed where you did.
What to research
YouTube
  • Search "zero trust least privilege vs productivity tradeoff"
  • Search "security operations usability tradeoff explained"
  • Search "continuous monitoring performance overhead cybersecurity"
SLIDE 14

Mission-Focused vs Check-the-Box Security

What this slide is really asking Give a real-world example of when compliance-only security failed to prevent harm — and contrast it with a case where designing around the mission improved security outcomes. This is where your analysis matters most.
Real compliance-failure case studies to look up
  • OPM data breach (2015) — OPM had passed audits but lacked basic identity controls
  • SolarWinds supply chain attack (2020) — systems were compliant but not monitored continuously
  • Colonial Pipeline ransomware (2021) — basic credentials, no MFA on legacy VPN
  • DoD Zero Trust Strategy executive summary — the shift from compliance-based to outcomes-based security dodcio.defense.gov · DoD-ZTStrategy.pdf
Tip: Build original analysis Use one real case (e.g., OPM) as your compliance-failure example, then build a hypothetical improvement based on your own system design using Zero Trust and ICAM principles. This shows original thinking.
YouTube
  • Search "OPM data breach explained cybersecurity lessons"
  • Search "SolarWinds attack explained supply chain" — SANS Institute or CISA
  • Search "Colonial Pipeline hack ransomware explained"
  • Search "mission-driven security design vs compliance"
SLIDE 15

Podcast Insight: Zero Trust in Practice

What this slide is really asking Listen to the assigned podcast, take notes, and pull out one idea that changed or shaped how you think about your design. Paraphrase — do not quote. Explain why that idea matters more than a textbook model would suggest.
Required source — listen to this
What to listen for in the podcast What gaps did the speakers say exist between theory and real DoD implementation? What did they say about legacy systems, budget constraints, or cultural resistance? Any of these can be your "key insight."
Additional YouTube context
  • Search "DoD zero trust implementation challenges real world"
  • Search "zero trust journey federal government lessons learned" — AFCEA, DISA, or NDU conference panels

SLIDES 16–18

Synthesis: Your Architecture and Conclusions

SLIDE 16

Target Architecture Summary

What this slide is really asking Show how Zero Trust, ICAM, and CMMC are not three separate things — they reinforce each other. ICAM provides the identity foundation. Zero Trust enforces continuous verification using that identity. CMMC validates that the controls are in place. What risk is reduced and what mission capability is preserved?
What to research
YouTube
  • Search "zero trust ICAM CMMC integration explained"
  • Search "DoD zero trust pillars explained 2024"
  • Search "zero trust architecture overview full explanation" — SANS Institute or IBM Technology
SLIDE 17

Implementation Phases

What this slide is really asking Nobody implements Zero Trust overnight. What are the realistic short, mid, and long-term steps for your system? Quick wins (MFA, asset inventory, log collection) come first. Mid-term (micro-segmentation, identity governance) takes longer. Long-term maturity (continuous monitoring, automated response, full device trust) is the goal.
What to research
YouTube
  • Search "zero trust implementation roadmap steps 2024"
  • Search "zero trust quick wins where to start" — Microsoft Security, Crowdstrike, or CISA
  • Search "MFA identity as first zero trust step explained"
SLIDE 18

Conclusion + Sources

What this slide is really asking Distill your entire argument to three things: what matters most in your architecture, why mission context is the driver (not the framework or the standard), and one specific thing you learned or reconsidered while building this presentation.

No new research needed here — this is synthesis. Look back at your notes and identify the single most important idea that changed how you think about security design.

APA citations — format your required sources

Quick Reference — All Sources

Additional Recommended Sources
APA Citations (Slide 18)
National Institute of Standards and Technology. (2020). Zero trust architecture (NIST Special Publication 800-207). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207
Department of Defense Chief Information Officer. (2022). DoD zero trust strategy. U.S. Department of Defense. https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf
Cybersecurity and Infrastructure Security Agency. (2023). Zero trust maturity model, version 2. CISA. https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf
Office of Management and Budget. (2022). Moving the U.S. government toward zero trust cybersecurity principles (OMB Memorandum M-22-09). Executive Office of the President. https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf
Department of Defense Chief Information Officer. (2021). Cybersecurity maturity model certification (CMMC) 2.0 model overview. U.S. Department of Defense. https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverview_V2.0_FINAL2_20211202_508.pdf
Federal Chief Information Officers Council. (n.d.). Identity, credential, and access management. CIO.gov. https://www.cio.gov/policies-and-priorities/ICAM/
General Dynamics Information Technology. (n.d.). Innovating for security: Zero trust solutions in the DoD [Podcast episode]. Voices of Innovation. https://podcast.gdit.com/episodes/innovating-for-security-zero-trust-solutions-in-dod
YouTube Channels to Follow
IBM TechnologyZero Trust, ICAM, security architecture explainers
Microsoft SecurityConditional access, identity, Zero Trust implementation
SANS InstituteThreat analysis, incident case studies, framework deep dives
NetworkChuckBeginner-friendly network and security concepts
John HammondReal-world attack analysis, incident response
Professor MesserCompTIA-aligned security concept explanations
CISAOfficial government security guidance videos
Final reminder The assignment is graded on understanding, not on how many sources you cite or how many terms you define. Every slide should answer one question: How does this concept apply to my specific system, and why does it matter for the mission? If you can answer that for every slide, you have done the work correctly.