{"id":93,"date":"2024-09-16T14:50:15","date_gmt":"2024-09-16T14:50:15","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/cyberimpact1\/?page_id=93"},"modified":"2026-08-18T01:24:30","modified_gmt":"2026-08-18T01:24:30","slug":"degree-reflection","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/troybannister\/degree-reflection\/","title":{"rendered":"Degree Reflection"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Abstract<\/h3>\n\n\n\n<p style=\"font-size:15px\">This reflection examines how my undergraduate cybersecurity program developed three skill areas that now define my academic and professional direction: technical systems and security analysis; cybersecurity governance, risk, and policy; and interdisciplinary cybersecurity analysis and communication. The nine artifacts selected for my ePortfolio show a progression from understanding individual systems and vulnerabilities to evaluating organizational risk, policy, human behavior, and strategic effects. Building the portfolio also required me to reconsider earlier assignments as evidence of a larger professional story rather than isolated course requirements. The process clarified both my preparation for governance, risk, and compliance work and the areas in which I still need deeper hands-on experience. Overall, the degree strengthened my technical foundation while giving me a more deliberate way to connect systems, people, policy, communication, and mission risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Introduction<\/h3>\n\n\n\n<p style=\"font-size:15px\">Selecting artifacts for this portfolio forced me to answer a harder question than simply which assignments received the best grades. I had to decide what I can actually demonstrate after completing an interdisciplinary cybersecurity degree and whether those skills matter outside the classroom. The three areas I selected are technical systems and security analysis; cybersecurity governance, risk, and policy; and interdisciplinary cybersecurity analysis and communication. They overlap by design. Harris and Clayton (2018) argue that employability skills operate together rather than as isolated traits, and cybersecurity work requires the same combination. The NICE Framework similarly describes cybersecurity work through tasks, knowledge, and skills that can be developed and demonstrated rather than through one technical specialty (Petersen et al., 2020). My analysis of the GDIT Information Security Analyst Principal position reinforced that point because the role combined vulnerability assessment, RMF, security tools, documentation, prioritization, and communication (General Dynamics Information Technology [GDIT], 2026). The artifacts show that I have developed a relevant foundation, but they also make clear that academic preparation is not the same as already possessing principal-level experience.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Technical Systems and Security Analysis<\/h3>\n\n\n\n<p style=\"font-size:15px\">My <strong>IT 315 Network Infrastructure Case Analysis<\/strong> is the most basic artifact in this category, but that is part of why it belongs here. I had to translate a building layout into an actual network plan by calculating copper and fiber requirements, placing equipment and telecommunications rooms, selecting hardware, estimating costs, and considering VLAN segmentation, firewall placement, backup power, and resiliency. The assignment made infrastructure less abstract because technical decisions had physical and budget constraints. It also reinforced that security cannot simply be added after a network has already been designed. Segmentation, access, equipment placement, and redundancy were part of the design itself.<br><br>The <strong>CS 462 MOVEit Zero-Day Exploit Analysis<\/strong> expanded that systems view into vulnerability research. I examined how CVE-2023-34362 allowed attackers to exploit MOVEit Transfer through SQL injection, deploy web shells, exfiltrate data, and compromise organizations through trusted third-party software.The larger lesson was that an organization can manage its own systems reasonably well and still inherit exposure through software or vendors. Researching the incident helped me connect exploit details with patching, monitoring, segmentation, least privilege, and vendor management. That connection is relevant to vulnerability-management work because identifying a CVE is only the beginning. Someone must interpret its importance to the organization and decide what response is appropriate.<br><br><strong>CYSE 368 Cybersecurity Internship<\/strong> was different because the artifact reflected work I was already performing rather than a classroom scenario. Writing the final reflection made me evaluate troubleshooting, firewall coordination, account access, logging, system validation, documentation, and service-disruption processes through a cybersecurity lens. The largest change was recognizing repeatable procedures and documentation as security controls rather than administrative overhead. I also had to communicate technical problems across departments and recognize when an issue required escalation. That combination of technical judgment, documentation, and communication resembles the type of cybersecurity work described in the GDIT advertisement more closely than proficiency with any one tool.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cybersecurity Governance, Risk, and Policy<\/h3>\n\n\n\n<p style=\"font-size:15px\">The <strong>CYSE 280 Windows System Management Policies and Procedures paper<\/strong> was one of the first assignments that made the relationship between technical controls and governance explicit. I mapped Windows tools such as Group Policy, Defender, BitLocker, Event Viewer, and Windows Firewall to NIST Cybersecurity Framework functions and compared policy enforcement across operating systems. The important lesson was that possessing a security feature does not mean an organization is managing risk effectively. Configuration, administrative ownership, automation, and policy determine whether the control actually provides value. CSF 2.0 reinforces that idea by adding Govern to Identify, Protect, Detect, Respond, and Recover and treating governance as part of managing cybersecurity risk rather than something outside the technical process (National Institute of Standards and Technology [NIST], 2024).<br><br><strong>CYSE 425W Digital and Media Literacy Policy Analysis<\/strong> pushed governance beyond technical frameworks. My four-part project examined the same proposed national curriculum through cybersecurity, political, ethical, and social perspectives. I began with a policy I strongly supported, but the later papers required me to address federal versus state authority, political bias, privacy, autonomy, unequal access, and the possibility that poor implementation could damage the trust the policy was intended to strengthen. That process matters to my career goals because a security policy is not automatically good because its objective is good. Governance requires considering stakeholders, implementation problems, unintended consequences, and competing values. The project also strengthened my interest in moving cybersecurity awareness beyond annual compliance toward an actual security culture.<br><br>The <strong>CS 465 Information Assurance Project<\/strong> most directly represents where I want to go professionally. In the scenario, I acted as the CIAO for a fictional defense manufacturer after a ransomware incident, performed a vulnerability assessment, constructed a threat matrix and communications plan, proposed an information assurance reporting structure, and mapped recommendations to findings and organizational responsibilities. NIST describes RMF as a structured life-cycle process connecting categorization, controls, assessment, authorization, and continuous monitoring, while SP 800-53 provides controls organizations tailor according to mission and risk (Joint Task Force, 2018, 2020). The project helped me understand why security controls require ownership and accountability. I was not only recommending MFA, backups, segmentation, or training; I had to explain who should own those functions and why the organization should care. It is my strongest academic bridge from systems administration toward GRC, but it remains a scenario rather than evidence that I have independently performed CIAO or ISSO responsibilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Interdisciplinary Cybersecurity Analysis and Communication<\/h3>\n\n\n\n<p style=\"font-size:15px\"><strong>CYSE 201S Cybersecurity Awareness and Digital Literacy<\/strong> was where the human side of cybersecurity became a sustained academic interest. My presentation compared surface-level awareness rules with deeper approaches involving social engineering, trust, privacy, behavioral habits, and critical evaluation of information. The assignment challenged the assumption that telling users what not to click is enough to create secure behavior. It also required communicating a technical and social problem through a presentation rather than another research paper. The ability to explain why a behavior or control matters to people without the same technical background is directly relevant to security awareness, governance, and stakeholder communication.<br><br><strong>IDS 300W Interdisciplinary Analysis of Public Trust and Institutional Resilience<\/strong> gave me a formal process for something I had previously done more intuitively. My research used political science, media studies, and sociology to examine institutional performance, media framing, and social proximity. The difficult part was not finding three perspectives; it was identifying where those perspectives conflicted and developing common ground without simply declaring one discipline correct. The National Academies&#8217; work on interdisciplinary research emphasizes breaking through disciplinary boundaries when complex problems cannot be adequately addressed from one field alone (National Academy of Sciences et al., 2005). That is the part of interdisciplinary thinking I now value most. In cybersecurity, a technically correct solution can still fail because of law, organizational incentives, user behavior, communication, culture, or mission requirements.<br><br>The <strong>CYSE 426 Cyber War Project<\/strong> gave me the clearest opportunity to apply that habit to an advanced cybersecurity problem. I entered the project treating destructive hacking, propaganda, social-media manipulation, and other hostile digital activity as variations of cyberwarfare. The research did not support that framing. I had to distinguish technical cyber operations from information warfare, separate tactical effects from strategic effects, and evaluate WhisperGate, Viasat, Industroyer2, Ukrainian digital resilience, and information campaigns without assuming that technical sophistication automatically produced strategic success.<br><br>The value of this artifact is not that I proved my original argument. It is that I changed it. Becoming willing to revise a conclusion when the evidence does not support my initial assumption is one of the most useful research habits I developed during the degree.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Portfolio Development and Career Readiness<\/h3>\n\n\n\n<p style=\"font-size:15px\">Building the ePortfolio changed how I viewed these assignments collectively. Nguyen (2013) describes the ePortfolio as a \u201cliving portal\u201d through which students reinterpret experience and present an evolving identity. The artifact-selection process did that for me. Assignments from IT 315, CYSE 368, CYSE 425W, and CS 465 were completed at different times for different purposes, but putting them together revealed a progression from understanding and supporting systems toward asking how cybersecurity decisions are governed, justified, and communicated. Nguyen&#8217;s research specifically emphasizes reflection and reinterpretation as central to meaningful portfolio development. McAdams&#8217;s (2001) concept of narrative identity helps explain why this feels different from a transcript. A transcript records courses; a portfolio requires me to decide which experiences are evidence of the professional story I am actually telling.<br><br>That story also has to remain credible. My GDIT job-ad analysis identified gaps in ACAS, SCAP, Splunk, eMASS, POA&amp;M ownership, and principal-level RMF responsibilities. The portfolio does not erase those gaps. Instead, it demonstrates why moving into an ISSO, information assurance, or GRC position is a reasonable next step. The NICE Framework&#8217;s emphasis on demonstrable tasks, knowledge, and skills supports that distinction between preparation and title inflation (Petersen et al., 2020). My artifacts demonstrate systems knowledge, vulnerability analysis, framework awareness, policy development, research, documentation, and communication. They do not demonstrate years of independent authorization ownership. Knowing both sides of that equation is useful because it identifies what I can contribute now and what I still need to develop.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Conclusion<\/h3>\n\n\n\n<p style=\"font-size:15px\">My cybersecurity degree did more than add technical knowledge to experience I already had. It changed how I organize that knowledge and how I approach problems. Technical systems and security analysis gave me a stronger foundation for understanding what is happening inside an environment. Governance, risk, and policy taught me to ask how controls are selected, justified, owned, and communicated. Interdisciplinary analysis taught me to look for relationships that a single technical perspective may miss and to change my position when evidence requires it.<\/p>\n\n\n\n<p style=\"font-size:15px\">Those skills matter together. Risk decisions require technical evidence, but they also require policy, communication, organizational context, and judgment. The portfolio therefore represents both an academic conclusion and a professional starting point. I am leaving the undergraduate program better prepared to move from secure systems support toward RMF and GRC responsibilities, with a clearer understanding of both the value of my existing experience and the work still required to become the cybersecurity professional I intend to be.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">References<\/h3>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"font-size:15px\"><div class=\"wp-block-group__inner-container\">\n<p>General Dynamics Information Technology. (2026). <em>Info. security analyst principal (RQ222538)<\/em> [Job advertisement]. https:\/\/www.gdit.com\/careers\/job\/d560c6554\/info-security-analyst-principal\/<\/p>\n\n\n\n<p>Harris, R., &amp; Clayton, B. (2018). Editorial: The importance of skills\u2014but which skills? <em>International Journal of Training Research, 16<\/em>(3), 195\u2013199. https:\/\/doi.org\/10.1080\/14480220.2018.1576330<\/p>\n\n\n\n<p>Joint Task Force. (2018). <em>Risk management framework for information systems and organizations: A system life cycle approach for security and privacy<\/em> (NIST Special Publication 800-37, Revision 2). National Institute of Standards and Technology. https:\/\/doi.org\/10.6028\/NIST.SP.800-37r2<\/p>\n\n\n\n<p>Joint Task Force. (2020). <em>Security and privacy controls for information systems and organizations<\/em> (NIST Special Publication 800-53, Revision 5). National Institute of Standards and Technology. https:\/\/doi.org\/10.6028\/NIST.SP.800-53r5<\/p>\n\n\n\n<p>McAdams, D. P. (2001). The psychology of life stories. <em>Review of General Psychology, 5<\/em>(2), 100\u2013122. https:\/\/doi.org\/10.1037\/1089-2680.5.2.100<\/p>\n\n\n\n<p>National Academy of Sciences, National Academy of Engineering, &amp; Institute of Medicine. (2005). <em>Facilitating interdisciplinary research<\/em>. The National Academies Press. https:\/\/doi.org\/10.17226\/11153<\/p>\n\n\n\n<p>National Institute of Standards and Technology. (2024). <em>The NIST Cybersecurity Framework (CSF) 2.0<\/em> (NIST Cybersecurity White Paper 29). https:\/\/doi.org\/10.6028\/NIST.CSWP.29<\/p>\n\n\n\n<p>Nguyen, C. F. (2013). The ePortfolio as a living portal: A medium for student learning, identity, and assessment. <em>International Journal of ePortfolio, 3<\/em>(2), 135\u2013148.<\/p>\n\n\n\n<p>Petersen, R., Santos, D., Smith, M. C., Wetzel, K. A., &amp; Witte, G. (2020). <em>Workforce framework for cybersecurity (NICE Framework)<\/em> (NIST Special Publication 800-181, Revision 1). National Institute of Standards and Technology. https:\/\/doi.org\/10.6028\/NIST.SP.800-181r1<\/p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Abstract This reflection examines how my undergraduate cybersecurity program developed three skill areas that now define my academic and professional direction: technical systems and security analysis; cybersecurity governance, risk, and policy; and interdisciplinary cybersecurity analysis and communication. The nine artifacts selected for my ePortfolio show a progression from understanding individual systems and vulnerabilities to evaluating&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/troybannister\/degree-reflection\/\">Read More<\/a><\/div>\n","protected":false},"author":29675,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/93"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/users\/29675"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/comments?post=93"}],"version-history":[{"count":4,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/93\/revisions"}],"predecessor-version":[{"id":475,"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/pages\/93\/revisions\/475"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/troybannister\/wp-json\/wp\/v2\/media?parent=93"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}