{"id":415,"date":"2026-08-28T03:50:34","date_gmt":"2026-08-28T03:50:34","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/jjcybersec\/?page_id=415"},"modified":"2026-09-26T02:54:38","modified_gmt":"2026-09-26T02:54:38","slug":"cyber-strategy-and-policy-cyse425w","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/jjcybersec\/cyber-strategy-and-policy-cyse425w\/","title":{"rendered":"Cyber Strategy and Policy (CYSE425W)"},"content":{"rendered":"\n<p>This course explored how cybersecurity strategy and policy actually get made, from risk management to the relationship between cybersecurity policy and government and business institutions. Throughout the semester, I selected Zero Trust Architecture (NIST 800-207) as my focus and analyzed it through five different lenses: its development, its political implications, its ethical implications, its social implications, and its overall effectiveness. This series taught me that cybersecurity policy cannot be separated from the political, ethical, and social systems it operates within, and that good policy analysis requires looking at the same issue from multiple angles before drawing conclusions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Coursework Artifacts<\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-layout-1 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-layout-1 wp-block-group-is-layout-flex\">\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/pap1-the-development-and-application-of-zero-trust-architecture\/\">Policy Analysis Paper 1 | <strong>The Development and Application of Zero Trust Architecture<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-2 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/pap2-the-political-implications-of-zero-trust-architecture\/\">Policy Analysis Paper 2 | <strong>The Political Implications of Zero Trust Architecture<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-3 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/pap3-the-ethical-implications-of-zero-trust-architecture\/\">Policy Analysis Paper 3 | <strong>The Ethical Implications of Zero Trust Architecture<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-4 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/pap4-the-social-implications-of-zero-trust-architecture\/\">Policy Analysis Paper 4 | <strong>The Social Implications of Zero Trust Architecture<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-5 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-fill\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/pap5-the-effectiveness-of-zero-trust-architecture\/\">Policy Analysis Paper 5 | <strong>The Effectiveness of Zero Trust Architectur<\/strong>e<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Reflection<\/h2>\n\n\n\n<p>Throughout this course, my role shifted from student to policy analyst. Each paper asked me to look at the same policy, Zero Trust Architecture, from a completely different angle, so I had to keep building new research and new arguments instead of just repeating what I already knew. The biggest challenge was learning not to treat ZTA as only a technical topic. It would have been easy to describe the same framework five times in five different ways, but I had to slow down and think about the political, ethical, and social effects it has on real people and organizations.<\/p>\n\n\n\n<p>Writing these papers taught me that cybersecurity policy does not exist on its own. Every decision to adopt a framework like ZTA comes with political motivations, ethical tradeoffs, and social consequences that go beyond the technology itself. I also learned how to build an argument using scholarly research instead of just my own opinion, which pushed me to think more critically about the sources I used and how they supported my point.<\/p>\n\n\n\n<p>This experience changed how I think about cybersecurity as a field. Before this course, I mostly saw cybersecurity as something technical, focused on building and defending systems. Now I understand that policy and strategy are just as important, since they determine how those systems get used and who they affect. This shift has already influenced how I approach my other projects, and it confirmed that I want to keep developing both my technical skills and my policy knowledge as I move forward in my career.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This course explored how cybersecurity strategy and policy actually get made, from risk management to the relationship between cybersecurity policy and government and business institutions. Throughout the semester, I selected Zero Trust Architecture (NIST 800-207) as my focus and analyzed it through five different lenses: its development, its political implications, its ethical implications, its social&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/jjcybersec\/cyber-strategy-and-policy-cyse425w\/\">Read More<\/a><\/div>\n","protected":false},"author":27457,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/pages\/415"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/users\/27457"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/comments?post=415"}],"version-history":[{"count":4,"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/pages\/415\/revisions"}],"predecessor-version":[{"id":625,"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/pages\/415\/revisions\/625"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/jjcybersec\/wp-json\/wp\/v2\/media?parent=415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}