{"id":233,"date":"2024-09-16T14:50:15","date_gmt":"2024-09-16T14:50:15","guid":{"rendered":"https:\/\/wp.odu.edu\/cyberimpact-template\/?page_id=233"},"modified":"2026-08-18T02:04:41","modified_gmt":"2026-08-18T02:04:41","slug":"cybersecurity-governance-risk-policy","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/troybannister\/cybersecurity-governance-risk-policy\/","title":{"rendered":"Cybersecurity Governance, Risk &amp; Policy"},"content":{"rendered":"\n<p>Cybersecurity governance and risk management connect technical security requirements to organizational priorities, policies, and decision-making. My coursework increasingly shifted my attention toward this part of the field by requiring me to consider not only whether a security control works, but why it is needed, how it should be implemented, who is responsible for it, and how organizations determine acceptable risk. The artifacts below demonstrate that development through security frameworks and policy enforcement, public cybersecurity policy, and enterprise information assurance.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h2 class=\"wp-block-heading\">Structured Policy Enforcement and NIST Frameworks<\/h2>\n\n\n\n<p><strong>Course:<\/strong> CYSE 280 \u2013 Windows System Management and Security<br><strong>Artifact Type:<\/strong> Cybersecurity Research Paper<br><br><strong>Artifact Description<\/strong><br>This research paper examined how structured policy enforcement can strengthen security in Windows-based environments when administrative tools are aligned with the NIST Cybersecurity Framework (CSF) 2.0. I evaluated technologies including Group Policy, Windows Defender, Event Viewer, BitLocker, and Windows Firewall against CSF functions and subcategories and considered how automation, centralized administration, and configuration affect security outcomes. The paper also compared Windows security management with Linux and macOS and used the WannaCry ransomware incident to illustrate the consequences of weak patch and policy enforcement<\/p>\n\n\n\n<p><strong>Skills Demonstrated<\/strong><\/p>\n\n\n\n<ul>\n<li>NIST Cybersecurity Framework application<\/li>\n\n\n\n<li>Security policy and control analysis<\/li>\n\n\n\n<li>Windows security administration concepts<\/li>\n\n\n\n<li>Cross-platform security comparison<\/li>\n\n\n\n<li>Risk-based evaluation of technical controls<\/li>\n\n\n\n<li>Framework-to-technology mapping<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1318\" height=\"1122\" src=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CYSE280-NIST-Table.png\" alt=\"\" class=\"wp-image-451\" \/><figcaption class=\"wp-element-caption\"><em>Evaluation of common Windows security tools against NIST Cybersecurity Framework 2.0 functions and subcategories.<\/em><\/figcaption><\/figure>\n\n\n\n<div data-wp-interactive=\"\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!selectors.core.file.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CYSE280-Research-Paper-Troy-Bannister-.pdf\" type=\"application\/pdf\" style=\"width:100%;height:900px\" aria-label=\"Embed of Policy Enforcement and NIST Analysis.\"><\/object><a id=\"wp-block-file--media-cf8040b0-c829-4816-b5b5-94459b67f6e7\" href=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CYSE280-Research-Paper-Troy-Bannister-.pdf\">Policy Enforcement and NIST Analysis<\/a><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h2 class=\"wp-block-heading\">National Digital &amp; Media Literacy Policy Analysis<\/h2>\n\n\n\n<p><strong>Course:<\/strong> CYSE 425W \u2013 Cybersecurity Strategy and Policy<br><strong>Artifact Type:<\/strong> Four-Part Policy Analysis<br><br><strong>Artifact Description:<\/strong><br>This four-part policy project examined the potential use of a national digital and media literacy curriculum as part of a broader cybersecurity strategy. I first evaluated digital literacy as a human-layer defense against social engineering, misinformation, and online manipulation, using examples from Finland, Estonia, and U.S. state-level policies. The later stages examined the same proposal through political, ethical, and social perspectives, including federal versus state authority, political bias, privacy, individual autonomy, unequal access to digital-literacy education, and the potential effects on public resilience and institutional trust.<\/p>\n\n\n\n<p><strong>Skills Demonstrated<\/strong><\/p>\n\n\n\n<ul>\n<li>Cybersecurity policy analysis<\/li>\n\n\n\n<li>Human-centered security analysis<\/li>\n\n\n\n<li>Political and ethical analysis<\/li>\n\n\n\n<li>Comparative policy research<\/li>\n\n\n\n<li>Social engineering and digital-literacy concepts<\/li>\n\n\n\n<li>Evaluation of policy tradeoffs and unintended consequences<\/li>\n\n\n\n<li>Research-based professional writing<\/li>\n<\/ul>\n\n\n\n<div data-wp-interactive=\"\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!selectors.core.file.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CYSE425W-Policy-Analysis-Bannister-Final.pdf\" type=\"application\/pdf\" style=\"width:100%;height:900px\" aria-label=\"Embed of National Digital &amp; Media Literacy Policy Analysis.\"><\/object><a id=\"wp-block-file--media-31cf7c3e-e6db-4adb-aeef-b9b385994a96\" href=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CYSE425W-Policy-Analysis-Bannister-Final.pdf\">National Digital &amp; Media Literacy Policy Analysis<\/a><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<h2 class=\"wp-block-heading\">Enterprise Information Assurance and Ransomware Risk Analysis<\/h2>\n\n\n\n<p><strong>Course: <\/strong>CS 465 &#8211; Information Assurance for Cybersecurity<br><strong>Artifact Type: <\/strong>Scenario-Based Enterprise Information Assurance Project<br><br><strong>Artifact Description:<\/strong><br>This final project required me to assume the role of Chief Information Assurance Officer for a fictional 1,000-employee defense-sector manufacturer following a ransomware incident. I evaluated the organization&#8217;s critical assets and vulnerabilities, developed a threat matrix and communications plan, proposed an information assurance reporting structure, and recommended technical, administrative, and organizational controls tied directly to identified risks. The project required me to consider cybersecurity as an enterprise responsibility involving governance, risk assessment, business operations, communication, information technology, operational technology, and organizational accountability.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"3058\" height=\"1904\" src=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CS465-Information-Assurance-Project-Bannister-14.png\" alt=\"\" class=\"wp-image-454\" \/><figcaption class=\"wp-element-caption\"><em>The submitted report progresses from the incident itself into a vulnerability assessment, threat matrix, communications plan, governance structure, and preventive recommendations.<\/em><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><br>Skills Demonstrated<\/h3>\n\n\n\n<ul>\n<li>Enterprise cybersecurity risk assessment<\/li>\n\n\n\n<li>Information assurance governance<\/li>\n\n\n\n<li>Asset criticality and vulnerability analysis<\/li>\n\n\n\n<li>Threat analysis<\/li>\n\n\n\n<li>Security policy and control development<\/li>\n\n\n\n<li>Incident communications planning<\/li>\n\n\n\n<li>Organizational responsibility and accountability<\/li>\n\n\n\n<li>IT\/OT security considerations<\/li>\n<\/ul>\n\n\n\n<div data-wp-interactive=\"\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!selectors.core.file.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CS465-Information-Assurance-Project-Bannister.pdf\" type=\"application\/pdf\" style=\"width:100%;height:900px\" aria-label=\"Embed of Information Assurance Ransomware Risk Analysis.\"><\/object><a id=\"wp-block-file--media-ea806c9d-aa57-4988-9f88-8b11e85f5aaf\" href=\"https:\/\/sites.wp.odu.edu\/troybannister\/wp-content\/uploads\/sites\/37008\/2026\/08\/CS465-Information-Assurance-Project-Bannister.pdf\">Information Assurance Ransomware Risk Analysis<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity governance and risk management connect technical security requirements to organizational priorities, policies, and decision-making. My coursework increasingly shifted my attention toward this part of the field by requiring me to consider not only whether a security control works, but why it is needed, how it should be implemented, who is responsible for it, and&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/troybannister\/cybersecurity-governance-risk-policy\/\">Read More<\/a><\/div>\n","protected":false},"author":29675,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/233"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/users\/29675"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/comments?post=233"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/233\/revisions"}],"predecessor-version":[{"id":485,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/233\/revisions\/485"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/media?parent=233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}