E. Ologunde Case file
Cybersecurity Policy  ·  Final Project

Policy Framework Analysis
Frameworks, Controls & The Limits of AI

Research a real cybersecurity framework, define core security concepts, critically evaluate AI-generated security advice, and revise it using your own professional judgment.
PowerPoint Presentation No Slide Count Minimum 5 Parts Depth > Length Critical Thinking Required
Overview Part 1 · Frameworks Part 2 · Controls Part 3 · AI Eval Part 4 · Revision Part 5 · Reflection Grading
🎯 What This Assignment Is Really About
This is not just a research assignment. It tests whether you can think critically about AI-generated security advice — a skill every modern security professional needs. AI tools can produce convincing-sounding plans that miss critical details, ignore regulations, or give unrealistic recommendations. Your job is to spot those gaps and fix them.

// Assignment at a Glance

PartWhat You DoFinal Product
Part 1Research one cybersecurity framework3–4 slides explaining the framework
Part 2Define policies, procedures, and 3 control types2 slides with definitions and examples
Part 3Prompt AI, paste the response, then critique it3–4 slides of AI output and your analysis
Part 4Rewrite the AI plan with realistic, prioritized controls1–2 slides of your revised plan
Part 5Reflect on when AI should and should not be trusted1–2 slides of written reflection

✓ What Earns Full Credit

  • Specific, original analysis of the AI output
  • Examples tied directly to your chosen framework
  • A realistic revised plan that shows real constraints
  • Reflection that references actual laws or breaches
  • Your own words throughout

✗ What Loses Credit

  • Accepting the AI output without criticism
  • Generic definitions copied from Wikipedia
  • Examples that do not connect to your framework
  • Vague critique like "the AI was too general"
  • Reflection with no real-world grounding
📁 Submission Format
Upload as .ppt or .pptx to Canvas. Free-style design — no template required. No minimum slide count. Depth and critical thinking matter more than quantity. Every slide should have written explanation, not just bullet points.
1

Framework Research

Choose one framework, research it thoroughly, and explain it in your own words with cited sources.

// Step 1 — Choose Your Framework

Pick one of the four frameworks below. Read about it before building slides — your analysis in later parts will be stronger if you genuinely understand your choice.

Voluntary

NIST Cybersecurity Framework (CSF 2.0)

Developed by the U.S. government. Widely adopted across industries. Organized around six functions: Govern, Identify, Protect, Detect, Respond, Recover.

nist.gov/cyberframework

Certifiable

ISO/IEC 27001

International standard for Information Security Management Systems (ISMS). Organizations can be formally certified. Mandatory in some regulated industries worldwide.

iso.org/standard/27001

Voluntary

CIS Critical Security Controls v8

A prioritized list of 18 practical security controls. Popular with smaller organizations. Mapped directly to real-world attack data and threat intelligence.

cisecurity.org/controls

Governance

COBIT 2019

Focuses on IT governance and management. Widely used by auditors and large enterprises. Connects business goals to IT security controls and accountability structures.

isaca.org/resources/cobit

// Step 2 — Build Your Framework Slides

Your Part 1 slides must answer all five questions below in your own words. Do not copy text directly from the framework's website.

Slide Set Framework Overview — answer all five questions
  • Purpose — What problem does this framework solve? What is it trying to help organizations do?
  • Audience — Who is it designed for? All industries? Specific sectors? Large or small organizations?
  • Mandatory or Voluntary? — Is compliance legally required for anyone, or is it an optional best practice? For whom?
  • Major Domains or Functions — List and briefly explain the main categories or functions the framework uses to organize security activity.
  • Security Maturity — How does adopting this framework help an organization improve its security posture over time? What does progress look like?
📚 Citation Requirement
You must cite at least 2 credible sources for Part 1. Acceptable: the official framework website, NIST publications, ISACA, peer-reviewed articles, or established security organizations. Wikipedia and generic blogs do not count as primary sources.

Part 1 Checklist

  • Framework chosen and clearly named on your first slide
  • All five questions answered in your own words — not copied from the framework's homepage
  • Major domains or functions listed with at least one sentence explaining each
  • At least 2 credible sources cited (in-slide or in notes)
  • Explanation of how the framework improves security maturity — not just what it is
2

Policies, Procedures & Controls

Define five core security terms in your own words, then give real examples aligned to your chosen framework.

// Step 1 — Define the Five Terms

Write definitions in your own words. The goal is to show you understand the difference between these terms — not to recite a textbook. Pay attention to the distinctions column.

TermPlain-Language MeaningCommon Mistake to Avoid
Policy A high-level statement of intent or rules set by leadership. Says what must happen and why. Does not explain how. A policy says "employees must use strong passwords" — it does not say how to create one. That is a procedure.
Procedure A step-by-step process for carrying out a policy. Says how to do something in a specific situation. "Open your password manager, click New Password, set 16 characters..." is a procedure, not a policy.
Technical Control A control enforced by technology: software, hardware, or system configuration. Examples: firewalls, MFA, encryption, endpoint detection. The tool only becomes a control when it is configured to enforce a security requirement. A firewall that allows everything is not a control.
Administrative Control A control based on people, processes, and governance. Examples: security training, background checks, access reviews, hiring policies. Administrative controls are often underestimated. An untrained employee can bypass even the best technical controls.
Physical Control A control that protects physical access to systems or facilities. Examples: locked server rooms, security cameras, keycards, cable locks. Physical controls are not just locks. Environmental controls (fire suppression, temperature monitoring) are also physical controls.

// Step 2 — Build the Examples Slide

Create one slide that provides a concrete example of each term. All examples must align with your chosen framework and fit the same organizational context.

Required Slide Controls and Examples — one slide, all six items
  • 1 Policy example — e.g., "All remote access must use VPN and MFA, per the Access Control Policy approved by the CISO."
  • 1 Procedure example — e.g., "When an employee is terminated, IT disables their account within 2 hours using the Offboarding Checklist in the ticketing system."
  • 2 Technical control examples — e.g., endpoint detection and response (EDR) software; encrypted off-site backups tested quarterly.
  • 1 Administrative control example — e.g., annual security awareness training required for all staff with completion tracked by HR.
  • 1 Physical control example — e.g., server room access restricted to IT staff via keycard; access log reviewed monthly by the security team.
💡 Alignment Means a Named Connection
If you chose NIST CSF, state which function each example belongs to (e.g., "Protect" or "Detect"). If you chose CIS Controls, reference the control number (e.g., "CIS Control 6 — Access Control Management"). This explicit mapping is what "framework alignment" means.

Part 2 Checklist

  • All five terms defined in your own words — not copied from a source
  • Definitions show you understand how the terms differ from each other
  • One examples slide with all six required items present
  • Each example explicitly linked to a named part of your chosen framework
  • Policy and procedure examples are clearly distinct from each other
3

AI Evaluation Challenge

Prompt an AI tool, paste its full response into your slides, then critically analyze its strengths and weaknesses.

⚠ Blind Trust in AI Is Penalized
The point of this part is not to show that AI is useful. It is to demonstrate that you can identify what AI gets wrong, oversimplifies, or misses entirely. A student who defends the AI response without critique will lose significant points.

// Step 1 — Run This Exact Prompt

Use any AI tool (ChatGPT, Claude, Gemini, Copilot, or similar). Copy and paste this prompt word-for-word:

COPY THIS PROMPT EXACTLY
"Create a security plan for a small healthcare clinic with 20 employees handling patient medical records."
Required Slide(s) Paste the full, unedited AI response here

Copy the complete, unedited AI response into your slides. Use a small font or multi-slide layout if it is long. Do not summarize or cut it. Graders need to see the full output to evaluate your critique.

Label the slide clearly: "AI-Generated Response — Unedited"

// Step 2 — Answer All Six Critique Questions

On the slides that follow the AI response, answer every question below. Reference specific sentences or sections from the AI output — do not critique in the abstract.

1
What did the AI do well?
Identify at least one accurate, helpful, or well-organized section. Honest analysis means acknowledging what worked, not just what failed.
2
What was too generic?
Which recommendations could apply to any organization — a hospital, a coffee shop, a bank? Point to specific advice that ignored the healthcare clinic context and explain what it missed.
3
What risks were missing?
What threats specific to a healthcare clinic did the AI fail to address? Consider: medical device security, ransomware targeting patient records, insider threats from clinical staff, and third-party vendor access to EHR systems.
4
Did it address HIPAA compliance?
HIPAA (the Health Insurance Portability and Accountability Act) sets legally required security standards for organizations handling patient health information. Did the AI mention it? Did it explain what the HIPAA Security Rule actually requires? Or did it treat legal compliance as optional? Note: this is a legal obligation, not a best practice.
5
Were any recommendations unrealistic?
A 20-person clinic has a very different budget and IT capacity than a hospital or large enterprise. Did the AI recommend tools or processes that would be impractical for a small clinic with limited resources? Give at least one specific example.
6
Did it separate policy from controls?
Using what you learned in Part 2 — did the AI correctly distinguish between policies, procedures, and technical, administrative, and physical controls? Or did it blend them together without explanation?

// Step 3 — Identify At Least 3 AI Weaknesses

For each weakness, explain why it matters in the real world — not just that it is a problem, but what could actually go wrong because of it.

No Industry Specificity

The same advice given to a clinic could apply to a retail store. HIPAA requires specific technical safeguards. Generic advice leaves those gaps uncovered.

No Cost Consideration

Enterprise SIEM platforms cost thousands per year. A 20-person clinic may have near-zero IT security budget. An unaffordable plan is the same as no plan.

Enterprise-Level Tools

Recommending a full SOC, dedicated security team, or 24/7 monitoring assumes staff and infrastructure most small clinics simply do not have.

Missing Incident Response

Saying "have an incident response plan" without specifying what to do during a ransomware attack on patient records leaves staff with no usable guidance when it matters most.

No Risk Prioritization

Listing 20 equal recommendations forces an under-resourced clinic to guess where to start. In practice, organizations with no guidance tend to start with the easiest items, not the most critical ones.

Missing Regulatory Teeth

Framing HIPAA as a "best practice" understates the consequences. HIPAA civil penalties range from $100 to over $50,000 per violation, with annual caps up to $1.9 million per category.

Part 3 Checklist

  • Full, unedited AI response included and clearly labeled in slides
  • All six critique questions answered with references to specific parts of the AI output
  • HIPAA addressed directly — explain what it actually requires, not just that it exists
  • At least 3 AI weaknesses identified with real-world explanations of the consequences
  • Analysis quotes or paraphrases specific lines from the AI response — not vague general statements
4

Human Judgment Revision

Rewrite the AI plan into something realistic, prioritized, and actually usable by a small healthcare clinic.

This is where your judgment replaces the AI output. Your revised plan must be practical, specific, and grounded in the real constraints of a 20-person clinic with limited budget and no dedicated security staff.

// Your Revised Plan Must Include All Four of These

1
Prioritized Controls — High / Medium / Low
Choose your top 5–8 controls and rank them. Explain the reasoning behind each priority level for this specific clinic. For example: "MFA on the EHR system is High priority because patient records are the primary ransomware target. Annual security training is Medium because it reduces phishing risk but takes longer to show results."
2
Cost and Staffing Reality
Acknowledge that this clinic likely has no dedicated IT security staff. Recommend free or low-cost tools where possible. Be honest about time requirements. Example: "Enable Windows Defender and configure automatic updates — this costs nothing and requires no specialized knowledge to maintain long-term."
3
A Basic Incident Response Outline
Write a short, practical IR outline that clinic staff who are not security experts can actually follow. It should have at least four steps. "Call your IT provider and disconnect the affected computer from the network" is more useful than "activate your CSIRT."
4
At Least One HIPAA Security Rule Requirement
Reference a specific HIPAA Security Rule section by name or code. For example: "§164.312(a)(1) — Access Controls: limit EHR access to authorized users only, using unique login credentials per staff member." Show that your plan addresses a real legal obligation, not just general best practices.
Example Structure What a Strong Revised Plan Looks Like

HIGH PRIORITY — Implement within 30 days:

  • Enable MFA on EHR system and staff email. Free via Microsoft 365 or Google Workspace settings. Addresses HIPAA §164.312(d) — Person or Entity Authentication.
  • Encrypt all laptops and USB drives containing patient data. Use BitLocker (built into Windows — free). Required under HIPAA Breach Notification Rule to qualify for Safe Harbor.

MEDIUM PRIORITY — Within 90 days:

  • Enable automatic OS and application patching. Reduces attack surface with minimal ongoing staff effort.
  • Conduct phishing awareness training using free CISA resources or KnowBe4 free trial. Document completion for HIPAA audit readiness.

Basic Incident Response Outline:

  1. Detect — Unusual system behavior or a ransom note? Any staff member reports it immediately to the clinic manager or office lead.
  2. Contain — Disconnect the affected device from Wi-Fi and Ethernet. Do not turn the device off. Do not try to fix it yourself.
  3. Notify — Call your IT provider immediately. If patient data may be affected, contact your HIPAA Privacy Officer within 24 hours to begin breach assessment.
  4. Document — Record every action taken and the time it occurred. HIPAA may require formal breach notification to HHS within 60 days if patient records were exposed.
📝 Required: What Did You Change and Why?
At the end of Part 4, include a short written explanation (on the slide or in the speaker notes) answering: What specific things did you remove, add, or change from the AI plan — and what was your reasoning for each change? This is where your critical thinking is most visible.

Part 4 Checklist

  • Controls are prioritized (High / Medium / Low) with reasoning for each level
  • Budget and staffing constraints acknowledged — no unrealistic enterprise-scale recommendations
  • At least one free or low-cost tool named specifically
  • Incident response outline with at least 4 actionable, plain-language steps
  • At least one specific HIPAA Security Rule section referenced by name or code number
  • Written explanation of what you changed from the AI plan and why
5

Reflection

Answer three critical questions about human judgment, professional responsibility, and the real limits of AI in cybersecurity.

This section should go beyond surface-level observations. Use what you observed in Parts 3 and 4 as evidence. You may reference real-world breaches, regulatory enforcement actions, or published news to strengthen your arguments.

// Answer All Three Questions in 1–2 Slides

1
When should cybersecurity professionals NOT rely on AI?
Think about scenarios where AI limitations make it dangerous to follow AI advice directly. AI has no current threat intelligence, no knowledge of your specific environment, no legal accountability, and no ethical judgment. Consider: compliance decisions, incident response during a live breach, risk assessments with legal implications, any context where a wrong recommendation has serious financial or safety consequences.
2
What are the risks of AI-generated compliance advice?
If an organization follows an AI-generated compliance plan and it turns out to be incomplete or wrong, who is responsible? Can AI be held legally accountable? What happens to the organization if an auditor finds gaps the AI plan missed? Reference at least one real regulation (HIPAA, PCI-DSS, GDPR, or SOX) and explain what non-compliance consequences actually look like in practice.
3
Why is human oversight legally and ethically necessary?
AI does not carry professional liability. A certified security professional (CISSP, CISM) or privacy attorney does. Explain why this accountability gap matters for organizations handling sensitive data. You may reference professional codes of conduct (such as ISACA's Code of Professional Ethics), legal frameworks, or cases where human negligence during a breach was found to be legally actionable.
📖 Real-World References You Can Use
  • Change Healthcare breach (2024) — Ransomware attack on a healthcare payment processor. Disrupted medical claims processing nationwide for weeks.
  • Advocate Health Care settlement (2016) — Unencrypted laptops containing 4 million patient records stolen. $5.55 million HIPAA settlement with HHS.
  • MGM Resorts (2023) — Social engineering attack disabled systems for days. Automated security tools failed to detect early lateral movement.
  • Colonial Pipeline (2021) — Ransomware shut down fuel supply to the U.S. East Coast. An incident response plan existed but had not been practiced or tested.

Part 5 Checklist

  • All three questions answered with substantive discussion — not just listed as bullet points
  • At least one real regulation named with a specific consequence for non-compliance
  • Explanation of why AI cannot replace legal or professional accountability
  • Optional but valued: reference to a real breach or enforcement case with a brief explanation of relevance
  • Reflection demonstrates your own professional judgment — not a generic paragraph praising AI as a useful tool

📊 Grading Breakdown

Graded on depth of analysis and quality of reasoning — not slide count. A 10-slide presentation with strong analysis outscores a 30-slide deck with surface-level content.

ComponentPointsWhat Earns Full Points
Part 1 — Framework Research25All five questions answered thoroughly, 2+ credible citations, genuine understanding shown beyond the framework homepage
Part 2 — Definitions and Examples20All five terms defined in original words, examples clearly aligned to the chosen framework, distinction between terms demonstrated
Part 3 — AI Critique25Full AI response included, all six questions answered with specific references, 3+ weaknesses explained with real-world consequences
Part 4 — Human Revision20Realistic prioritized plan, HIPAA addressed with specific citation, incident response included, written explanation of what changed and why
Part 5 — Reflection10All three questions answered with specificity, real regulation or breach referenced, demonstrates professional judgment rather than AI enthusiasm
⛔ Automatic Point Deductions
  • Accepting the AI response without critique — significant deduction across Parts 3 and 4
  • Definitions copied from a textbook or website — no credit for Part 2 definitions
  • Examples with no framework connection — Part 2 examples receive partial credit only
  • Reflection that only praises AI — Part 5 requires critical analysis, not enthusiasm
  • No HIPAA mention in Part 3 or 4 — the scenario involves patient health records; addressing HIPAA is not optional
🏆 What Distinguishes an Excellent Submission
  • Framework analysis that goes beyond the official overview — shows you actually read the framework document
  • AI critique that quotes specific lines and explains precisely why each is problematic for this scenario
  • Revised plan that feels like it was written by someone who has thought about a real clinic's constraints
  • Reflection that names real consequences (HIPAA fines, breach notification timelines, professional liability) not just theoretical risks
  • The framework from Part 1 appears as a through-line across all five parts of the presentation