Final Project Overview
Estimated time needed: 5 minutes
This project will consist of four phases and their related tasks. Each phase is
linked to a module from the course:
Phase 1: Governance, risk, and compliance
o Task: Identify the critical elements of a GRC framework that
Nerdnest needs to implement
Phase 2: Foundations of IT service management
o Task: Identify and apply the ITIL processes to Nerdnest
Phase 3: Understanding cybersecurity laws and regulations
o Task: Identify and apply laws related to Nerdnest's operations
Phase 4: Understanding cybersecurity audits
o Task: Identify the benefits of conducting regular cybersecurity
audits and explain how Nerdnest can prepare for an audit
You will make decisions and provide recommendations based on the scenario
presented.
Below is a structured set of recommendations for Nerdnest, aligned to the
four project phases and their associated tasks. The focus is on practical,
defensible decisions grounded in industry standards.
Phase 1: Governance, Risk, and Compliance (GRC)
Task: Identify the critical elements of a GRC framework for Nerdnest
Nerdnest should implement a GRC framework that integrates governance, risk
management, and compliance into a single operating model.
Critical GRC elements:
1. Governance
o Clearly defined roles and responsibilities (executive oversight,
risk owners, control owners)
o Documented policies and standards (information security, data
protection, acceptable use)
o Alignment of cybersecurity objectives with business goals
2. Risk Management
o A formal risk assessment process to identify, analyze, and
prioritize cybersecurity risks
o Defined risk appetite and tolerance
o Risk treatment strategies (mitigate, transfer, accept, avoid)
o Ongoing risk monitoring and reporting
3. Compliance
o Identification of applicable laws, regulations, and standards
o Mapping of compliance requirements to internal controls
o Evidence collection and documentation for audits
o Continuous compliance monitoring
A centralized GRC approach ensures Nerdnest manages risk proactively rather
than reactively.
Phase 2: Foundations of IT Service Management (ITIL)
Task: Identify and apply ITIL processes to Nerdnest
Nerdnest should adopt core ITIL practices to improve service reliability,
efficiency, and security.
Key ITIL processes to apply:
Incident Management – Restore normal service quickly after security or
system incidents
Problem Management – Identify root causes of recurring incidents and
prevent reoccurrence
Change Management – Ensure system changes are reviewed, approved,
tested, and documented
Service Asset and Configuration Management (SACM) – Maintain an
accurate inventory of IT assets
Service Level Management – Define and monitor service performance
expectations
Applying ITIL helps Nerdnest standardize operations, reduce downtime, and
strengthen operational controls that support cybersecurity.
Phase 3: Understanding Cybersecurity Laws and Regulations
Task: Identify and apply laws related to Nerdnest’s operations
Applicable laws depend on Nerdnest’s data types, customers, and geographic
reach, but likely include:
Data protection and privacy laws
o GDPR (if handling EU personal data)
o State or national privacy laws (e.g., consumer data protection
regulations)
Industry and contractual requirements
o Data breach notification laws
o Customer contractual security obligations
Cybersecurity and record retention requirements
o Logging, monitoring, and incident reporting mandates
Nerdnest should:
Perform a legal and regulatory applicability assessment
Map legal requirements to technical and administrative controls
Train employees on compliance responsibilities
Regularly review laws for changes that may affect operations
Phase 4: Understanding Cybersecurity Audits
Task: Identify the benefits of regular audits and explain how Nerdnest can
prepare
Benefits of regular cybersecurity audits
Identify control gaps and weaknesses before attackers do
Demonstrate regulatory and contractual compliance
Improve overall security maturity
Increase customer and stakeholder trust
Support continuous improvement and risk reduction
How Nerdnest can prepare for audits
Maintain up-to-date policies, procedures, and documentation
Ensure controls are implemented, monitored, and evidenced
Conduct internal audits and self-assessments
Track remediation efforts for identified issues
Assign clear ownership for audit coordination and responses
Preparation transforms audits from stressful events into valuable tools for
improving cybersecurity posture.
Conclusion
By implementing a strong GRC framework, adopting ITIL processes,
complying with relevant cybersecurity laws, and conducting regular audits,
Nerdnest can build a resilient, compliant, and well-governed cybersecurity
program that supports both operational efficiency and business growth.