// Assignment at a Glance
| Part | What You Do | Final Product |
|---|---|---|
| Part 1 | Research one cybersecurity framework | 3–4 slides explaining the framework |
| Part 2 | Define policies, procedures, and 3 control types | 2 slides with definitions and examples |
| Part 3 | Prompt AI, paste the response, then critique it | 3–4 slides of AI output and your analysis |
| Part 4 | Rewrite the AI plan with realistic, prioritized controls | 1–2 slides of your revised plan |
| Part 5 | Reflect on when AI should and should not be trusted | 1–2 slides of written reflection |
✓ What Earns Full Credit
- Specific, original analysis of the AI output
- Examples tied directly to your chosen framework
- A realistic revised plan that shows real constraints
- Reflection that references actual laws or breaches
- Your own words throughout
✗ What Loses Credit
- Accepting the AI output without criticism
- Generic definitions copied from Wikipedia
- Examples that do not connect to your framework
- Vague critique like "the AI was too general"
- Reflection with no real-world grounding
Framework Research
Choose one framework, research it thoroughly, and explain it in your own words with cited sources.
// Step 1 — Choose Your Framework
Pick one of the four frameworks below. Read about it before building slides — your analysis in later parts will be stronger if you genuinely understand your choice.
NIST Cybersecurity Framework (CSF 2.0)
Developed by the U.S. government. Widely adopted across industries. Organized around six functions: Govern, Identify, Protect, Detect, Respond, Recover.
ISO/IEC 27001
International standard for Information Security Management Systems (ISMS). Organizations can be formally certified. Mandatory in some regulated industries worldwide.
CIS Critical Security Controls v8
A prioritized list of 18 practical security controls. Popular with smaller organizations. Mapped directly to real-world attack data and threat intelligence.
COBIT 2019
Focuses on IT governance and management. Widely used by auditors and large enterprises. Connects business goals to IT security controls and accountability structures.
// Step 2 — Build Your Framework Slides
Your Part 1 slides must answer all five questions below in your own words. Do not copy text directly from the framework's website.
Part 1 Checklist
- Framework chosen and clearly named on your first slide
- All five questions answered in your own words — not copied from the framework's homepage
- Major domains or functions listed with at least one sentence explaining each
- At least 2 credible sources cited (in-slide or in notes)
- Explanation of how the framework improves security maturity — not just what it is
Policies, Procedures & Controls
Define five core security terms in your own words, then give real examples aligned to your chosen framework.
// Step 1 — Define the Five Terms
Write definitions in your own words. The goal is to show you understand the difference between these terms — not to recite a textbook. Pay attention to the distinctions column.
| Term | Plain-Language Meaning | Common Mistake to Avoid |
|---|---|---|
| Policy | A high-level statement of intent or rules set by leadership. Says what must happen and why. Does not explain how. | A policy says "employees must use strong passwords" — it does not say how to create one. That is a procedure. |
| Procedure | A step-by-step process for carrying out a policy. Says how to do something in a specific situation. | "Open your password manager, click New Password, set 16 characters..." is a procedure, not a policy. |
| Technical Control | A control enforced by technology: software, hardware, or system configuration. Examples: firewalls, MFA, encryption, endpoint detection. | The tool only becomes a control when it is configured to enforce a security requirement. A firewall that allows everything is not a control. |
| Administrative Control | A control based on people, processes, and governance. Examples: security training, background checks, access reviews, hiring policies. | Administrative controls are often underestimated. An untrained employee can bypass even the best technical controls. |
| Physical Control | A control that protects physical access to systems or facilities. Examples: locked server rooms, security cameras, keycards, cable locks. | Physical controls are not just locks. Environmental controls (fire suppression, temperature monitoring) are also physical controls. |
// Step 2 — Build the Examples Slide
Create one slide that provides a concrete example of each term. All examples must align with your chosen framework and fit the same organizational context.
Part 2 Checklist
- All five terms defined in your own words — not copied from a source
- Definitions show you understand how the terms differ from each other
- One examples slide with all six required items present
- Each example explicitly linked to a named part of your chosen framework
- Policy and procedure examples are clearly distinct from each other
AI Evaluation Challenge
Prompt an AI tool, paste its full response into your slides, then critically analyze its strengths and weaknesses.
// Step 1 — Run This Exact Prompt
Use any AI tool (ChatGPT, Claude, Gemini, Copilot, or similar). Copy and paste this prompt word-for-word:
// Step 2 — Answer All Six Critique Questions
On the slides that follow the AI response, answer every question below. Reference specific sentences or sections from the AI output — do not critique in the abstract.
// Step 3 — Identify At Least 3 AI Weaknesses
For each weakness, explain why it matters in the real world — not just that it is a problem, but what could actually go wrong because of it.
No Industry Specificity
The same advice given to a clinic could apply to a retail store. HIPAA requires specific technical safeguards. Generic advice leaves those gaps uncovered.
No Cost Consideration
Enterprise SIEM platforms cost thousands per year. A 20-person clinic may have near-zero IT security budget. An unaffordable plan is the same as no plan.
Enterprise-Level Tools
Recommending a full SOC, dedicated security team, or 24/7 monitoring assumes staff and infrastructure most small clinics simply do not have.
Missing Incident Response
Saying "have an incident response plan" without specifying what to do during a ransomware attack on patient records leaves staff with no usable guidance when it matters most.
No Risk Prioritization
Listing 20 equal recommendations forces an under-resourced clinic to guess where to start. In practice, organizations with no guidance tend to start with the easiest items, not the most critical ones.
Missing Regulatory Teeth
Framing HIPAA as a "best practice" understates the consequences. HIPAA civil penalties range from $100 to over $50,000 per violation, with annual caps up to $1.9 million per category.
Part 3 Checklist
- Full, unedited AI response included and clearly labeled in slides
- All six critique questions answered with references to specific parts of the AI output
- HIPAA addressed directly — explain what it actually requires, not just that it exists
- At least 3 AI weaknesses identified with real-world explanations of the consequences
- Analysis quotes or paraphrases specific lines from the AI response — not vague general statements
Human Judgment Revision
Rewrite the AI plan into something realistic, prioritized, and actually usable by a small healthcare clinic.
This is where your judgment replaces the AI output. Your revised plan must be practical, specific, and grounded in the real constraints of a 20-person clinic with limited budget and no dedicated security staff.
// Your Revised Plan Must Include All Four of These
Part 4 Checklist
- Controls are prioritized (High / Medium / Low) with reasoning for each level
- Budget and staffing constraints acknowledged — no unrealistic enterprise-scale recommendations
- At least one free or low-cost tool named specifically
- Incident response outline with at least 4 actionable, plain-language steps
- At least one specific HIPAA Security Rule section referenced by name or code number
- Written explanation of what you changed from the AI plan and why
Reflection
Answer three critical questions about human judgment, professional responsibility, and the real limits of AI in cybersecurity.
This section should go beyond surface-level observations. Use what you observed in Parts 3 and 4 as evidence. You may reference real-world breaches, regulatory enforcement actions, or published news to strengthen your arguments.
// Answer All Three Questions in 1–2 Slides
- Change Healthcare breach (2024) — Ransomware attack on a healthcare payment processor. Disrupted medical claims processing nationwide for weeks.
- Advocate Health Care settlement (2016) — Unencrypted laptops containing 4 million patient records stolen. $5.55 million HIPAA settlement with HHS.
- MGM Resorts (2023) — Social engineering attack disabled systems for days. Automated security tools failed to detect early lateral movement.
- Colonial Pipeline (2021) — Ransomware shut down fuel supply to the U.S. East Coast. An incident response plan existed but had not been practiced or tested.
Part 5 Checklist
- All three questions answered with substantive discussion — not just listed as bullet points
- At least one real regulation named with a specific consequence for non-compliance
- Explanation of why AI cannot replace legal or professional accountability
- Optional but valued: reference to a real breach or enforcement case with a brief explanation of relevance
- Reflection demonstrates your own professional judgment — not a generic paragraph praising AI as a useful tool
📊 Grading Breakdown
Graded on depth of analysis and quality of reasoning — not slide count. A 10-slide presentation with strong analysis outscores a 30-slide deck with surface-level content.
| Component | Points | What Earns Full Points |
|---|---|---|
| Part 1 — Framework Research | 25 | All five questions answered thoroughly, 2+ credible citations, genuine understanding shown beyond the framework homepage |
| Part 2 — Definitions and Examples | 20 | All five terms defined in original words, examples clearly aligned to the chosen framework, distinction between terms demonstrated |
| Part 3 — AI Critique | 25 | Full AI response included, all six questions answered with specific references, 3+ weaknesses explained with real-world consequences |
| Part 4 — Human Revision | 20 | Realistic prioritized plan, HIPAA addressed with specific citation, incident response included, written explanation of what changed and why |
| Part 5 — Reflection | 10 | All three questions answered with specificity, real regulation or breach referenced, demonstrates professional judgment rather than AI enthusiasm |
- Accepting the AI response without critique — significant deduction across Parts 3 and 4
- Definitions copied from a textbook or website — no credit for Part 2 definitions
- Examples with no framework connection — Part 2 examples receive partial credit only
- Reflection that only praises AI — Part 5 requires critical analysis, not enthusiasm
- No HIPAA mention in Part 3 or 4 — the scenario involves patient health records; addressing HIPAA is not optional
- Framework analysis that goes beyond the official overview — shows you actually read the framework document
- AI critique that quotes specific lines and explains precisely why each is problematic for this scenario
- Revised plan that feels like it was written by someone who has thought about a real clinic's constraints
- Reflection that names real consequences (HIPAA fines, breach notification timelines, professional liability) not just theoretical risks
- The framework from Part 1 appears as a through-line across all five parts of the presentation