Session 3: Administrative and Policy-Level Threat Detection
Policy gaps, governance failures, and administrative indicators of threats
Justin Pineda CISSP, CISM
Faculty
Pre-Work
Learning Objectives
Motivation Question
If your organization has strong technical controls but weak policies, are you really secure? Why or why not?
What Are Administrative Threats?
Who is responsible for managing administrative threats?
Policy-Level Threats Explained
Why Policy Gaps Matter
Governance Failures
Administrative Indicators of Threats
Scenario: You are managing a rural bank with increasing number of branches.
Issue: No firewall available but branch needs to open.
Example: Access Control Policy Gap
Example: Incident Response Policy Gap
Shadow IT as an Admin Threat
Compliance vs Security
Policy vs Practice
Third-Party Governance Gaps
Change Management Failures
Scenario: You, in IT Security, learned that your client-facing web application has a critical security vulnerability that allows attackers to remote access the server. What do you do?
Human Factors in Policy Failures
Detecting Policy-Level Threats
Role of Management
Summary
References
Knowledge Check (1/3)
Which of the following is an example of an administrative threat?
Knowledge Check (2/3)
Why are policy gaps dangerous even with strong technical controls?
Knowledge Check (3/3)
What is a common indicator of governance failure?
Debrief / Wrapping Up
What did you learn today about administrative and policy-level threats?
Case Example: BSP-Regulated Bank
Case Example: SME (Non-Regulated)
Case Example: University IT Environment
ISO/IEC 27001 Mapping – Administrative Threats
ISO 27001 Annex A – Key Control Areas
NIST Cybersecurity Framework Mapping
Case Scenarios – Framework Alignment