Four Threats, Four Controls, and What Remains: A Security Risk Analysis for a Regional Water District's Business Network
[Candidate Name]
School of Technology, Western Governors University
D430 Fundamentals of Information Security
Task 2 Performance Assessment
[Course Instructor]
August 11, 2026
Model document written by our desk. The district, its systems and every figure here are composites built for teaching; no real organization or network is described, and no method of attack is given.
Scope, Assets and the Security Objectives at Stake
Bell Creek Regional Water District is a composite public water district serving 38,000 households with 62 employees, one treatment plant and 14 remote pump and monitoring sites. Its systems fall into two groups: a business network of 71 workstations and 4 servers, including a billing platform holding names, service addresses and bank details for 22,400 automatic payment accounts, and a separate control network carrying operational monitoring. This analysis covers the business network and the boundary between the two networks. It excludes process operation, physical plant security and personnel screening, which sit with other owners. The analysis is defensive throughout: it names threats and the control classes that counter them, and it does not describe how any weakness would be exploited.
Andress (2019) treats confidentiality, integrity and availability as the three objectives every control serves, and naming which one an asset needs most keeps a control list from becoming a shopping list. For the billing platform, confidentiality ranks first, because 22,400 bank records are the most exposing holding the district has. For work-order and monitoring records, integrity ranks first, because a false reading is worse than a missing one. At the network boundary, availability ranks first, because 38,000 households depend on continuity of service and no district can ask them to wait for a restore. These rankings are what decide where money goes when a budget of $148,000 will not cover everything.
Risk was rated with the qualitative approach described in NIST Special Publication 800-30, Revision 1: each risk carries a likelihood and an impact on a five-level scale, and the pair sets the risk level. Three inputs feed the ratings. The district's own event history over 36 months records 41 reported phishing messages, 2 confirmed credential compromises and no ransomware. Published guidance on threat activity against small public utilities supplies the outside view. The third input is the state of the control that would have to fail first. Assigned levels are judgments rather than measurements, and this paper says so wherever a rating is genuinely contestable.
Threats and Vulnerabilities Identified
R1, credential theft through phishing, is rated high likelihood and moderate impact, which places it at high risk. The district logged 41 reported phishing messages and 2 confirmed credential compromises across 36 months, and staff email accounts are protected today by a password alone. The objective at stake is the confidentiality of every billing record those accounts can reach. R2, ransomware on the business network, is rated moderate likelihood and high impact, also high. The weakness here is not the malware but the backup design: the single backup copy sits inside the same domain as the servers it protects, and the last full restore test ran 61 hours against a stated recovery objective of 24 hours.
R3, unmanaged vendor access at the network boundary, is rated moderate likelihood and very high impact, which makes it the highest-ranked entry in the register. The pump maintenance vendor works through one shared account used by five technicians, and that account stands open between visits. Two properties make the combination severe: a shared account destroys attribution, so the district cannot establish who did what, and standing access removes the limit that a scheduled task would otherwise impose. R4, excess internal privilege, is rated high likelihood and moderate impact. Twenty-seven of 62 staff hold local administrative rights on their workstations, and 9 hold billing database access wider than their role requires, three of them because they changed roles and kept what they already had.
Two further candidates were considered and deliberately left out of the register. Physical intrusion at the remote sites is a real threat, but the cabinets already carry locks, tamper alarms and a monthly inspection, and what remains is owned by operations rather than by this analysis. Denial of service against the public website is possible, but the site carries published information only, and an outage would touch neither billing nor operations. Including both would have made the register look thorough while spreading a fixed budget across risks that rank below the four above. A register is a ranking device, and a ranking that includes everything ranks nothing.
Controls Recommended, Each Against a Named Threat
Each control below answers one named risk, carries a price, and maps to published guidance so the recommendation does not rest on preference. Against R1: phishing-resistant multifactor authentication on email and remote access, with hardware authenticators for the 9 accounts that reach the billing database and application-based verification for the other 53 staff. NIST Special Publication 800-63B ranks authenticators by resistance to interception rather than convenience, and CISA lists strong authentication among its performance goals. Cost is $4,910 a year in licensing plus $990 one time for hardware. Against R2: a second backup copy held offline and immutable outside the domain, with a restore test every quarter against a written recovery objective. Cost is $11,400 a year plus 16 staff hours per quarter.
Against R3: retirement of the shared vendor account in favor of named accounts, access granted per work order and expiring with it, denied by default at the boundary, with session logging retained for 12 months. NIST Special Publication 800-82, Revision 3 treats a controlled boundary and least privilege across it as the core of protecting an operational network, and the change costs $18,000 for the access broker plus roughly 40 hours of configuration. Against R4: removal of local administrative rights from the 27 workstations that do not need them, recertification of the 9 billing accounts every quarter, and central logging with an alert on any privilege change. Cost is $9,200 in licensing and about 120 staff hours in the first year.
The four controls consume $44,500 of the $148,000 annual security budget, which leaves the awareness program already committed for the year untouched. Sequence follows risk, not ease. Vendor access changes first, because it carries the highest impact and the smallest change footprint. Authentication is second, because it closes the entry route the district has already seen used twice. The backup redesign is third, because it changes what a bad day costs rather than whether one arrives. Privilege reduction runs last only because it needs the most staff time, and it is scheduled rather than deferred. Mapped to the functions in the Cybersecurity Framework 2.0, all four sit under Protect, with their logging elements carrying Detect.
Residual Risk, Trade-offs and What Is Not Covered
No control on this list removes its risk, and the register carries what is left. Strong authentication does nothing once an intruder is operating from a workstation the user has already signed in on, so R1 falls from high to moderate rather than to low, and the remainder is watched by the logging added under C4. An offline backup copy restores service but cannot unpublish data taken before encryption, so the extortion half of R2 survives the control and belongs in the incident response plan rather than the backup plan. Named vendor accounts fix attribution inside the district, but the vendor's own workstation hygiene stays outside district control, which is why the contract adds a right to audit and a 24-hour notification duty.
One risk cannot be treated inside this budget cycle. Two monitoring devices at remote sites run software the manufacturer stopped supporting in 2021, and neither can support modern authentication at all. Replacement falls in the 2028 capital cycle at an estimated $214,000, so the interim answer is compensating rather than corrective: the devices sit in their own segment, the boundary denies by default, the monitoring path is read only, and the cabinets keep physical control and inspection. The residual is then accepted in writing by the general manager with a review date, because acceptance is a decision an accountable owner makes and records, not a gap that quietly stays open because nobody wrote it down.
Two trade-offs are worth stating plainly. Vendor access granted per work order adds delay to an emergency call-out, so the plan carries a documented emergency path with review after the fact, since a control that people route around in a crisis is not a control. Removing local administrative rights will generate support tickets and some resentment, and the first quarter after the change should be resourced for it. Effectiveness will be measured rather than assumed, on four figures: the phishing reporting rate, the count of accounts holding standing privilege, hours to complete a tested restore against the 24-hour objective, and vendor sessions opened without a matching work order. Each figure has a named owner and a review every quarter.
References
Andress, J. (2019). Foundations of information security: A straightforward introduction. No Starch Press.
Cybersecurity and Infrastructure Security Agency. (2023). Cross-sector cybersecurity performance goals. U.S. Department of Homeland Security. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). U.S. Department of Commerce. https://csrc.nist.gov/pubs/sp/800/30/r1/final
National Institute of Standards and Technology. (2017). Digital identity guidelines: Authentication and lifecycle management (NIST Special Publication 800-63B, includes updates as of March 2, 2020). U.S. Department of Commerce. https://csrc.nist.gov/pubs/sp/800/63/b/final
National Institute of Standards and Technology. (2023). Guide to operational technology (OT) security (NIST Special Publication 800-82, Rev. 3). U.S. Department of Commerce. https://csrc.nist.gov/pubs/sp/800/82/r3/final
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce. https://www.nist.gov/cyberframework
How this D 430 Task 2 example is structured
Task instructions and rubric aspects are not published and they change between course versions, so this is a worked example of the genre: in many versions this task supplies an organization and asks for the threats it faces, the controls that answer them and a justification for each, while your own task instructions decide the exact form. This D430 Task 2 example is built so every claim can be traced. Scope and objectives come first, naming which of confidentiality, integrity and availability each asset needs most. The risk register follows, with a stated rating method and the reasons two candidate risks were left out. Controls come third, one per risk, priced and referenced. Residual risk closes the paper, including the one device that cannot be fixed in this budget cycle and is accepted in writing instead.
D430 Task 2 questions, answered
What does D430 Task 2 usually ask for?
Task instructions are not published and they change between course versions, so treat this as the genre rather than the prompt. In many versions the task supplies an organization and asks which threats it faces, which controls answer them, and why each control fits. Your own task instructions and rubric aspects decide the exact form, including how the risks must be presented.
Is this course cleared by an exam or by written work?
Some courses at Western Governors University clear by a proctored objective assessment, which is an exam, and this library does not touch exams at all. What it covers is written performance assessment work: a document you submit to an evaluator, who scores it aspect by aspect against the rubric and returns any aspect not yet met for revision, which is a routine step rather than a failure.
How many controls should the analysis recommend?
No official count is published, so the honest answer is that coverage matters more than quantity. Four controls fully argued, each answering one named threat with its cost and its residual risk, reads far stronger than twelve listed without justification. If a control in your draft cannot be traced to a threat you named earlier, it is padding and an evaluator will read it that way.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official Western Governors University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.