0
Detroit Logistics Information Security Program Plan Proposal
IT3358
Lynettee Robinson
5/23/2025
1
Executive Summary
The Executive Summary should highlight the problem statement, research performed,
conclusions, and high-level recommendations.
2
Proposal Request (Scope – Week 1)
Company Information
1. Describe the main business problems and goals.
Detroit Logistics is working towards an autonomous delivery system for transporting
automotive parts that introduces security and operational challenges. The key business problems
at Detroit Logistics include cybersecurity vulnerabilities, operational efficiency, and regulatory
compliance. The limited security measures make the company prone to cyber threats such as data
breaches, unauthorized system access, and service disruptions (Cybersecurity Scenario, n.d.).
Further, the expected transition to autonomous deliveries requires a robust security infrastructure
to prevent system failures, unauthorized interventions, and errors in logistics. The company’s
mission is to optimize logistics efficiency while maintaining security and reliability, while its
vision is to establish itself as an innovative leader in autonomous delivery logistics
(Cybersecurity Scenario, n.d.). The proposed information security program will ensure that
Detroit Logistics can safely integrate autonomous system security, regulatory compliance, and
operational resilience.
Security Program Background.
Currently, the company has limited cybersecurity measures, increasing its risk exposure.
The current security measures include basic processes, such as basic firewall and antivirus
solutions, as well as standard compliance protocols with enforcement gaps (Cybersecurity
Scenario, n.d.). There could also be manual authentication procedures for access control as well
as limited monitoring and incident response (Roshid et al., 2024). The security proposal will
evaluate these weaknesses and implement enhanced controls to safeguard the autonomous
delivery system.
3
Availability, Confidentiality, Authentication, and Integrity Considerations –
Access to Systems and Data.
Any security solution must find a balance between the objectives of confidentiality, integrity,
availability, and authentication. Confidentiality is preserving restrictions on information access
and disclosure, including means of protecting personal privacy and proprietary information,
while integrity guards against improper information adjustment or destruction, ensuring
information authenticity (U.S. Department of Commerce, 2018). Availability means ensuring
timely and reliable access to and use of information, while authentication means the system can
verify system users and devices to prevent unauthorized access. In the case of Detroit Logistics,
availability and authentication will be highly prioritized to ensure autonomous operations are
secured and uninterrupted (U.S. Department of Commerce, 2018).
2. Define the key decision makers.
Here is a table of the project’s key decision makers and a description of their roles.
Decision makers Role
Project Sponsor Strategic oversight and final approval authority
(Robinson, 2023)
Project Manager Oversees the information security program
project
HR Manager Facilitate insider threat mitigation and employee
training (Robinson, 2023).
Security analyst Bridge technical expertise and operational
understanding of the program
IT Security Architects Technical implementers and system designers
Legal and Compliance Officer Ensures compliance with regulations and
4
standards, such as CTPAT and GDPR
(Robinson, 2023).
Operations Manager Represents logistics operations, ensuring the
security solution does not disrupt workflows
3. Describe the company’s unique organizational challenges.
Detroit Logistics faces unique organizational challenges regarding culture, regulations, and
human resources. For instance, Detroit Logistics has human resource personnel limitations with
no cybersecurity professionals that may hinder the implementation of the information security
program (Cybersecurity Scenario, n.d.). With the proposed new information security program,
employees may struggle with adapting to new cybersecurity protocols, especially having gotten
used to the company’s limited information security program. Compliance with existing
cybersecurity laws is important for the smooth running of any logistics company. The limited
information security program could indicate regulatory complexity, especially with the expected
compliance with cybersecurity laws associated with the transportation sector (Cybersecurity
Scenario, n.d.). There could also be system integration risks from having to ensure security
measures don’t disrupt existing logistics operations.
5
4. Identify the project timeline.
Activity Start date End date Key Deliverables
Project Start 6/2/2025 Initial assessment
Define project scope, team
Initial Assessment 6/9/2025 6/23/2025
roles, and security objectives
Identify vulnerabilities,
Risk Assessment & Threat Analysis 6/25/2025 7/10/2025
conduct risk analysis
Draft security framework for
Security Architecture Design 7/15/2025 7/30/2025 authentication, access
controls, and data protection.
Make an outline of security
System Integration Planning 8/2/2025 8/16/2025 measures for autonomous
delivery operations
Deploy security solutions
Implementation 8/20/2025 9/3/2025 like firewalls, authentication
layers, and monitoring tools.
Penetration Testing and Conduct security tests to
9/5/2025 9/10/2025
Vulnerability Assessment identify weaknesses.
Compliance and Regulatory Ensure alignment with
9/13/2025 9/20/2025
Review cybersecurity regulations
Employee Training & Awareness Conduct workshops to
9/22/2025 9/27/2025 familiarize employees with
Program security protocols
Full-scale security
Final System Integration & Testing 9/30/2025 10/10/2025 integration and operational
validation
Document security program
Documentation 10/12/2025 10/19/2025
report and recommendations
6
Activity Start date End date Key Deliverables
Submit the final security
program report and
Project End 10/25/2025 10/25/2025
recommendations to the
project sponsor
7
Risk Management Strategy (Week 2)
1. Describe the organization’s threat environment.
Due to the increased reliance on autonomous delivery and digital logistics, Detroit operates
in a high-risk cybersecurity and operational environment. The transport industry in which Detroit
Logistics operates faces numerous cyber and operational security threats like ransomware
attacks, critical infrastructure disruption, supply chain vulnerabilities, and data breaches that can
result in operational delays and financial losses (Badawi, 2024). Examples of cybersecurity
threats in the transport and logistics industry include data breaches, ransomware attacks, supply
chain attacks, phishing attacks, and vulnerabilities associated with IoT technology (van Niekerk,
2018). Data breaches may occur through unauthorized access to sensitive data such as passenger
information, shipment details, or financial records.
Cybercriminals may demand a ransom payment from an organization once they disrupt
operations by encrypting critical infrastructure systems (van Niekerk, 2018). Workers can also be
victims of deceptive emails or messages, making them reveal sensitive information or install
malware (Badawi, 2024). Furthermore, cybercriminals can exploit vulnerabilities in third-party
systems to compromise an organization's entire supply chain. Examples of operational security
threats in the industry include cargo theft and losses, rerouting of cargo, and traffic disruptions
(van Niekerk, 2018). Further, a lack of physical security measures such as security cameras or
access controls may make an organization’s facilities vulnerable to sabotage or theft.
Cybercriminals may also attempt to reroute cargo, damage temperature-controlled loads, or
misdirect payments (van Niekerk, 2018). Moreover, autonomous delivery vehicles could be
remotely hijacked, and logistics data transmissions could be intercepted and manipulated.
8
2. Define risk evaluation approach.
Managing risks requires Detroit Logistics to implement a structured risk assessment
framework based on probability and impact analysis. Below is an example of a risk register.
Risk ID Description Likelihood Level of Impact Mitigation Plan
R-0100 GPS spoofing Medium High Secure GPS channels and deploy
real-time anomaly detection.
R-0101 Ransomware High Severe Regular backups, network
attack segmentation, and anti-malware
solutions.
R-0102 Data breach High Critical Implement strong encryption and
multi-factor authentication.
R-0103 Phishing Medium High Conduct employee training on the
attack risks of phishing attacks.
Detroit logistics will document and track risks systematically to maintain proactive security
measures. Such measures will include maintaining a centralized risk register regularly updated
by security teams and regular periodic risk assessments using various threat modeling techniques
(van Niekerk, 2018). With the advent of technology, Detroit Logistics may consider using
automated risk-tracking systems to log security incidents and responses. This would be an
effective way to keep track of incidents with the company’s facilities as well as operations and
develop effective mitigation plans (van Niekerk, 2018). Furthermore, implementing a risk
governance framework would be crucial in assigning accountability for mitigation.
9
3. Define the identity and access management (IAM) approach.
Identity and access management (IAM) is a framework used to manage digital identities and
control user access to resources, ensuring only authorized individuals have access to an
organization's data and systems. This framework focuses on managing who accesses company
resources, enabling secure access to applications and data while preventing unauthorized access
(Sindiramutty et al., 2024). Detroit Logistics should implement a robust IAM framework focused
on least privilege access and multi-layer authentication to protect company assets. According to
Sindiramutty et al. (2024), the key IAM measures the company will implement include zero trust
architecture, continuous monitoring, privileged access management (PAM), multi-factor
authentication (MFA), and role-based access control (RBAC).
Zero Trust Architecture (ZTA) allows for dynamic validation of each access request, while
Privileged Access Management protects administrative system access (Rose et al., 2020). ZTA
uses zero-trust principles to plan industrial and enterprise infrastructure and workflows. As such,
ZTA protects resources such as assets, services, workflows, and network accounts, making it an
ideal approach for identity and access management (Rose et al., 2020). Zero trust assumes no
implicit trust is granted to assets or user accounts based only on their physical or network
location or asset ownership. A strong IAM framework will help prevent unauthorized system
intrusions and data exposure.
4. Define the data protection approach. (Be sure to include cryptography.)
There are several techniques Detroit Logistics can use to secure its data at rest, in transit, and
use. Such techniques may include cryptography, intrusion detection, and data loss prevention.
Cryptography involves securing information and communication using codes and encryption,
which makes it unreadable to unauthorized individuals (IBM, 2025). Symmetric and asymmetric
10
cryptography are the common types used. Encryption converts data into an unreadable format
using a key and an algorithm. AES-256 and TLS 1.3 encryptions could be for sensitive data
storage and transmission, respectively (Sindiramutty et al., 2024). Intrusion detection techniques
may involve deploying AI-driven anomaly detection systems to identify suspicious activity or
monitor continuous network traffic (Sindiramutty et al., 2024). Data loss prevention policies may
be applied to restrict unauthorized data transfer while also implementing real-time access
auditing. By leveraging cryptography, intrusion detection, and DLP solutions, Detroit Logistics
enhances security while maintaining business continuity.
5. List policy recommendations.
In order to formalize security controls, I recommend Detroit Logistics adopt the following
policies regarding risk management, identity and access management, and data protection.
Risk management policy recommendation.
Regular security audits are done quarterly.
Incident response protocols to mitigate cyber threats
Vendor security assessments (Sindiramutty et al., 2024).
Identity and access management policy recommendation.
MFA enforcement for all system access.
Access revocation process for inactive user accounts (Sindiramutty et al., 2024).
Privileged access review of administrative credentials
Data protection policy recommendation.
Annual security training programs on cybersecurity awareness
Data retention framework to secure archival and deletion (van Niekerk, 2018).
Mandate AES-256 encryption standards for sensitive data (Sindiramutty et al., 2024).
11
12
System Security Strategy (Week 3)
1. Describe three physical threats and vulnerabilities.
2. Define operation management and personnel security strategies. List one for each
area.
Define data and hardware strategies.
Strategy 1 – Data.
Strategy 2 – Data.
Define the human resources strategy.
Strategy 1 – Human resources.
Strategy 2 – Human resources.
Define the hardware security strategy.
13
3. Define the network security strategy.
4. List the IT service management strategies.
Change.
Asset.
Incident.
(Should be specific to your target company).
5. External and internal network traffic security strategy.
List two tools or strategies specific to your target company.
6. Define operation security policy recommendations.
List physical and network security policy recommendations.
List personnel security policy recommendation.
List the IT service management policy recommendation.
14
OS and Application Security Strategy (Week 4)
1. Define system development threats.
List OWASP (Web application, cloud, and AI top 10 lists).
List common CISA top routinely exploited vulnerabilities.
2. Define the system security strategy.
(Should be specific to your target company and its environment.)
List the high-level requirements for addressing system security using the NIST
Risk Management Framework (RMF).
List the high-level requirements for addressing vulnerabilities using OWASP,
CISA, or other threat intelligence sources.
3. Describe the system development and acquisition strategy.
List Web-based application recommendations.
List the cloud acquisition strategy.
List the artificial intelligence (AI) acquisition strategy.
Include high-level privacy and security contract considerations for IT
acquisitions.
4. Document policy recommendations.
Describe the system development security policy.
List the cloud security policy.
List the AI ethics and security policy.
15
Security Policy (Week 5)
1. Develop executive summary encapsulating the entire course.
(Should be before project scope at the beginning of the paper.)
Key findings.
Analysis.
Requirements.
Recommendations.
2. Describe policy recommendations.
List all policy recommendations from Weeks 2–4.
3. Describe regulatory standards compliance objectives (for example, HIPAA,
Sarbanes Oxley, FDA, FTC, and GDPR).
(Should be defined in project scope.)
4. Describe security Requirements.
(Should be defined in project scope. Could be the same as Confidentiality, Authentication,
Availability, and Integrity under project scope. Should include synopsis of Weeks 2–4
strategies.)
16
References
Badawi, H. (2024). Cyber Security Challenges in the Transportation Industry: A Comprehensive
Analysis and Recommendations. Journal of Management and Training for Industries. 11.
16-41. 10.12792/JMTI.11.2.16.
Cybersecurity Scenario. (n.d.). [Link]
fpx3358element249948/[Link]?sso=true
IBM. (2025, April 17). What is cryptography? [Link]
Robinson, N. (2023). Human factors security engineering: The future of cybersecurity
teams. EDPACS, 67(5), 1-17.
Rose, S., Borchert, O., Mitchell, S. and Connelly, S. (2020). Zero Trust Architecture, Special
Publication (NIST SP). National Institute of Standards and Technology, Gaithersburg.
MD, [online]. [Link]
Roshid, M. M., Waaje, A., Meem, T. N., & Sarkar, A. (2024). Logistics 4.0: A Comprehensive
Literature Review of Technological Integration, Challenges, and Future Prospects of
Implementation of Industry 4.0 Technologies. International Journal of Technology,
Knowledge and Society, 20(1), 65.
Sindiramutty, S. R., Jhanjhi, N. Z., Tan, C. E., Khan, N. A., Shah, B., & Manchuri, A. R. (2024).
Cybersecurity measures for logistics industry. In Navigating Cyber Threats and
Cybersecurity in the Logistics Industry (pp. 1-58). IGI Global.
U.S. Department of Commerce. (2018). Risk management framework for information systems
and organizations. NIST Special Publication, 800, 37.
17
van Niekerk, B. (2018). Analysis of cyber-attacks against the transportation sector. In Cyber
Security and Threats: Concepts, Methodologies, Tools, and Applications (pp. 1384-
1402). IGI Global.
Appendices
Appendix A: System Diagram (Use as needed; not every project will have a system design.)
Appendix B: Acronyms and Definitions