ICT805 HarbourLink Logistics: Reading the Incident Evidence
In ICT805 Cybersecurity Assessment 3 at Southern Cross Institute, the HarbourLink Logistics scenario gives you eight scattered incident events and says they "do not conclusively establish a single attack path". That sentence is the real task.
Three habits separate strong reports from average ones:
- Map every event to a MITRE ATT&CK technique, for example failed vendor logins → brute force, RDP to the finance workstation → lateral movement, encoded PowerShell → obfuscation.
- Give an innocent explanation for each event, such as a travelling vendor or routine internet scanning, then explain which reading is more likely and why.
- Admit the limits. With only seven days of logs and no central SIEM, certainty is impossible, and saying so earns marks.
Then build a phased plan (contain, harden, detect, mature) that fits the AUD 250,000 budget, a four-person IT team and four-hour outage windows.
Read the complete walkthrough with a risk register and NIST CSF roadmap: ICT805 Assessment 3 HarbourLink guide. Sydney students can also get tutoring from Punjab Assignment Help.
Comments
Post a Comment