Activity 01
Design Challenge: Security Policy for a Fictional Organization
Groups receive a profile of a fictional organization (a healthcare clinic, a small retailer, a school district) and must design a cybersecurity policy addressing authentication, patch management, backup, and incident response. Groups present to the class, which asks one probing question each. Groups revise based on feedback.
Explain various mitigation strategies for common cyber threats.
Facilitation TipDuring the Design Challenge, provide a rubric that explicitly ties security decisions to cost, usability, and risk reduction to guide student reasoning.
What to look forPresent students with a scenario describing a common cyber threat (e.g., phishing email, ransomware attempt). Ask them to identify the primary threat and list two specific mitigation strategies they would recommend, explaining why each is effective.