NEXUS DEFENSE LABS AP CYBERSECURITY 2.1.G

Task: Spot Single-Point Failures & Implement Defense-in-Depth

EV

MEMORANDUM: High Priority Security Audit Task

FROM: Evelyn Vance, Chief Information Security Officer (CISO)

TO: You (Associate Security Analyst, Day 1)

URGENT BRIEFING

Welcome to the Nexus Defense Security Operations Center (SOC).

Our recent internal assessment revealed alarming vulnerabilities across four key enterprise divisions: Executive Finance Portal, R&D Quantum Server Vault, Point-of-Sale Retail System, and Employee Cloud Storage. Each division currently relies on a single security control—a classic Single Point of Failure (SPOF).

As outlined in the AP Cybersecurity Framework (Standard 2.1.G), an enterprise security strategy must employ Defense-in-Depth—a layered security approach spanning six distinct defense domains:

1. Human Layer
2. Physical Layer
3. Network Layer
4. Device Layer
5. Application Layer
6. Data Layer

YOUR OBJECTIVES TODAY:

  1. Spot the Single Layer: Audit each division and identify which single security layer is being relied upon.
  2. Simulate the Attack: Run a Red Team breach simulation to observe how easily a single layer crumbles.
  3. Fortify with Defense-in-Depth: Design a multi-layered defense strategy with at least 3 independent layers for each division.
  4. Present to the Board: Defend your security proposal in front of the Executive Board of Directors.