ACME Security Vulnerability Improvement Project Plan
Name
Affiliation
Course Unit: Course Name
Instructor
, 2
ACME Security Vulnerability Improvement Project Plan
Project Background
In response to changing business needs, ACME Company ordered an assessment of its
internal networks to understand underlying vulnerabilities within the network. A network
assessment revealed significant vulnerabilities in three domains, people, processes and
technology. In response to the report detailing the vulnerabilities, the management of the
company requested a project plan for addressing the vulnerabilities. The goal of the current
project plan is to present the project charter, scope of the project, communication plan, timeline,
and discuss how the project manager will manage scope creep to ensure that the project is
completed successfully.
Project Charter
Mission Statement
Risk Domain of People: Cyber Security Training and Awareness
The primary aim of introducing formal cyber security training and awareness is to
enhance the robustness of ACME network by eliminating human error and insider threat
emerging from members of the organization. The aim of the initiative is to improve the security
culture of the organization, and reduce susceptibility to human-related cyber security threats such
as social engineering, phishing and policy violations. Insider malicious intent and negligence
accounts for more than 77% of all cyber security breaches, necessitating robust cyber security
training and awareness programs (Tolossa, 2023).
Risk Domain of Processes: Absence of a Formal Incident Response Plan
The goal of this initiative is to implement a comprehensive, and formalized incident
response system that outlines clear roles and responsibilities for detecting, containing, and