Last updated: September 2026 · Reviewed by the Punjab Assignment Help cybersecurity team · Reading time: 13 minutes
Quick answer: ICT805 Cybersecurity Assessment 3 at Southern Cross Institute (SCI) is a 40% secure assessment. You submit a ZIP file containing a 1,000–1,500-word PDF business report, technical evidence files and a reflective commentary. The report builds a cybersecurity strategy and implementation plan for HarbourLink Logistics (HLL) after a suspected hybrid-network compromise. To score well, correlate the incident evidence into a likely attack path, give alternative explanations, map risks to NIST CSF / ISO 27001 / MITRE ATT&CK, and produce a prioritised plan that fits AUD 250,000, four IT staff and four-hour outage windows.
ICT805 Assessment 3 at a glance
| Item | Detail |
|---|---|
| Unit | ICT805 Cybersecurity, Southern Cross Institute (Parramatta, Sydney) |
| Title | Assessment 3: Cybersecurity Strategy and Implementation Plan (Secure Assessment) |
| Weight | 40%, individual |
| Due | Week 13 (Semester 2, 2026: Sunday 4 October, 11:59 pm) |
| Length | ~1,000–1,500 words, excluding references and appendices |
| Format | Business report, SCI cover sheet, Calibri or Times New Roman 12, double-spaced, all in PDF inside a labelled ZIP |
| References | At least 10 academic or industry sources, APA 7 |
| Textbook | Easttom, W. C. (2023). Computer Security Fundamentals (5th ed.) |
Step 1: Correlate the incident evidence (answer hint)
The brief says the evidence "does not conclusively establish a single attack path". Markers want to see you build a timeline, map each event to a technique and give an alternative explanation. A table like this in your risk section scores well:
| Observed event | Likely MITRE ATT&CK technique | Alternative explanation | Evidence to look for |
|---|---|---|---|
| Suspicious requests to the public portal | T1190 Exploit Public-Facing Application | Routine internet scanning or bots | Web server / WAF logs, repeated SQLi or path-traversal patterns |
| Repeated failed logins on a vendor service account | T1110 Brute Force / password spraying | Misconfigured vendor script using an old password | Windows Event ID 4625, source IPs, timing pattern |
| Successful VPN login from an unfamiliar IP | T1133 External Remote Services + T1078 Valid Accounts | Vendor technician travelling or using a new ISP | VPN logs, geolocation, no MFA challenge |
| VPN address connecting to internal servers | T1046 Network Service Discovery | Legitimate maintenance | Firewall logs from the 10.20.50.0/24 pool to 10.20.30.0/24 |
| Remote login to finance workstation FIN-WS17 | T1021.001 Remote Desktop Protocol (lateral movement) | IT support session | Event ID 4624 Logon Type 10 |
| Encoded PowerShell command | T1059.001 PowerShell + T1027 Obfuscation | Admin automation script | Event ID 4104 script block logging, decode the Base64 with CyberChef |
| Access to finance files | T1005 Data from Local System / T1039 Network Shared Drive | Normal finance work | File-server audit logs on HL-FILES01 |
| Outbound encrypted connection | T1041 Exfiltration over C2 channel | Cloud backup or software update | Proxy / NetFlow data, destination reputation, bytes transferred |
Most defensible narrative: credential compromise of an unrotated vendor account without MFA → VPN access → flat firewall rules allow reconnaissance → RDP to a finance workstation → obfuscated PowerShell → possible data staging and exfiltration. The portal activity may be a separate event. Say so, and say that 7-day log retention limits your certainty. Stating limitations is explicitly required.
Step 2: Vulnerability and risk analysis (300–400 words)
Turn each preliminary control concern into a risk entry with likelihood × impact. Example format:
| Vulnerability | Likelihood | Impact | Rating | Framework link |
|---|---|---|---|---|
| No MFA on vendor VPN, stale service-account password | High | High | Critical | NIST CSF PR.AA · Essential Eight: MFA |
| Flat network / broad firewall rules | High | High | Critical | ISO 27001 A.8.22 Segregation of networks |
| RDP and SMB exposed across segments | High | Medium–High | High | Essential Eight: restrict admin privileges |
| Outdated TLS on the portal, DB reachable from many zones | Medium | High | High | OWASP Top 10: Cryptographic Failures, Security Misconfiguration |
| Unsupported warehouse IoT firmware | Medium | Medium | Medium | ISO 27001 A.8.8 Technical vulnerabilities |
| No central logging, 7-day retention, no SOC | High | High | Critical | NIST CSF DE.CM Continuous monitoring |
| Domain-joined backups, rare restore tests | Medium | Very High (ransomware) | Critical | Essential Eight: regular backups · NIST CSF RC |
| IR plan not exercised for 2 years | Medium | High | High | NIST SP 800-61 · CSF RS |
Step 3: Strategy and implementation plan (300–400 words)
Organise the plan by NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) or by time phase. A phased roadmap shows you have respected the constraints:
| Phase | Actions | Why first? |
|---|---|---|
| 0–30 days (contain) | Disable or rotate the compromised vendor account, enforce MFA on all VPN access, block the suspicious external IP, isolate FIN-WS17 for forensics, enable PowerShell logging | Low cost, stops the active threat, no downtime |
| 1–3 months (harden) | Restrict vendor VPN to named hosts and ports, remove RDP/SMB from non-admin segments, move the portal DB behind the DMZ only, disable legacy TLS, offline or immutable backups plus a restore test | Closes the lateral-movement path. Changes fit into 4-hour windows |
| 3–6 months (detect) | Cloud SIEM with 90+ day retention, or managed detection and response (MDR) giving 24/7 cover for a 4-person team | Fixes the biggest capability gap: no analyst and no monitoring |
| 6–12 months (mature) | Zero-trust access for vendors, segment the IoT VLAN with compensating controls until firmware is replaced, run a tabletop IR exercise, staff phishing training | Longer projects, and they depend on the earlier phases |
Budget hint: show an indicative split of the AUD 250,000, for example MDR/SIEM as the largest line, then segmentation and firewall work, identity/MFA, backup, IoT compensating controls, training and a contingency reserve. Justify each line against risk reduction. Markers look for trade-off reasoning, such as why MDR beats hiring one analyst who cannot cover 24/7.
Step 4: Technical evidence (200–300 words plus appendix files)
This criterion is worth 20%, so include real artefacts from your lab environment (use only tools and targets your unit approves):
- Nmap scan of a test subnet showing exposed RDP (3389) and SMB (445), used as evidence for segmentation.
- Wireshark capture that separates plaintext traffic from TLS, or shows a TLS 1.0/1.1 handshake.
- testssl.sh or an SSL Labs-style report on a test web server showing weak protocols.
- Windows Event Viewer filtered for 4625, 4624 (type 10) and 4104.
- CyberChef decoding a harmless sample Base64 PowerShell string to show the method.
- Firewall rule before/after screenshots (pfSense or Windows Defender Firewall).
Label each item "Figure X / Evidence E1" with a one-line caption explaining what it proves.
Step 5: Reflective commentary (300–400 words)
Use a model such as Gibbs' Reflective Cycle or Driscoll's What? So what? Now what?. Good talking points:
- How you decided between competing explanations with limited logs
- Why you prioritised MFA and segmentation over replacing warehouse devices
- A challenge you faced with a tool and how you solved it
- How the work maps to ULO1–4 and to professional standards (NIST, ISO 27001)
Suggested report outline
- SCI cover page
- Table of contents
- Introduction (150–200 words)
- Risk and vulnerability analysis (300–400)
- Strategy and implementation plan (300–400)
- Technical evidence and tools (200–300)
- Reflective commentary (300–400)
- Conclusion (100–150)
- References (10+ sources, APA 7), then appendices
Credible sources to cite
- NIST Cybersecurity Framework 2.0 and NIST SP 800-61 (incident handling)
- ISO/IEC 27001:2022 Annex A controls
- Australian Signals Directorate / ACSC Essential Eight and the Annual Cyber Threat Report
- MITRE ATT&CK Enterprise matrix
- OWASP Top 10
- Easttom (2023) plus recent peer-reviewed articles on zero trust, MDR and IoT security
Short on time before the Week 13 deadline?
Our cybersecurity tutors can take you through the HarbourLink attack-path analysis, help you set up Nmap, Wireshark and Event Viewer evidence in your own lab, and review your plan against NIST and the Essential Eight.
WhatsApp "ICT805" for a free risk-register template Get a free quote
ICT805 Assessment 3 answer hints and HarbourLink Logistics case solution approach
Students often search for ICT805 Assessment 3 answers or a HarbourLink Logistics case study solution. This is a secure assessment: your technical evidence must come from your own lab work, so a copied answer will not pass. What you can use is the solution approach above: the event-to-ATT&CK correlation table, the most defensible attack path, the risk register, the phased NIST CSF roadmap within AUD 250,000 and the evidence checklist.
Answer-hint recap: correlate all eight incident events and give alternative explanations, rate each control weakness by likelihood and impact, contain first (MFA and credential rotation), then harden, detect and mature, label every piece of evidence, and reflect on your decisions using Gibbs or Driscoll.
Where can I find ICT805 Assessment 3 answers?
There is no official answer. ICT805 Assessment 3 is a secure assessment that needs your own analysis and lab evidence. Use the HarbourLink solution approach and answer hints on this page as a guide. Our tutors can walk you through the tools and review your plan.
What is the HarbourLink Logistics case study solution approach?
Correlate the incident events into a likely vendor-credential-to-lateral-movement attack path, state alternative explanations and log limits, rate the risks, then propose a prioritised NIST CSF-based plan that fits AUD 250,000, a four-person IT team and four-hour outage windows.
Can I get cyber security assignment help in Sydney or Parramatta?
Yes. Punjab Assignment Help supports Southern Cross Institute and other Sydney cyber security students online with risk analysis, NIST and ISO 27001 mapping, and tool evidence.
Frequently asked questions
What is the most likely attack path in the HarbourLink Logistics case?
The most defensible reading is: vendor service-account compromise (no MFA, old password) → VPN access → reconnaissance through broad firewall rules → RDP to a finance workstation → encoded PowerShell → finance file access → possible exfiltration. You must also give alternative explanations and state that 7-day log retention limits certainty.
Which framework should I use for ICT805 Assessment 3?
NIST CSF 2.0 is the easiest structure for the strategy. Support it with ISO/IEC 27001:2022 controls, MITRE ATT&CK for mapping the incident, the ACSC Essential Eight for Australian context and OWASP for the web portal.
How many references are needed?
At least 10 credible academic or industry sources in APA 7 style.
What technical evidence should I include?
Labelled screenshots, logs, configuration files and tool outputs such as Nmap scans, Wireshark captures, Windows Event logs and TLS test results, each with a caption explaining what it proves.
How should I use the AUD 250,000 budget?
Prioritise low-cost, high-impact controls first (MFA, credential rotation, firewall restrictions), then 24/7 detection through MDR or a cloud SIEM, then longer projects such as zero trust and IoT modernisation, and keep a contingency reserve.
Related help
Academic integrity note: ICT805 Assessment 3 is a secure assessment. Use this guide to understand the task, then produce your own analysis and evidence in line with SCI's academic integrity policy.