You are interviewed by MASA for a position of cybersecurity consultant to work in a
cybersecurity program. MASA is a science-based company in the field of space
engineering with customers ranging from Australian states and federal government,
overseas space exploring agencies to military and navy. MASA is pioneering in the field,
therefore, the Intellectual property database has 250 IPs. MASA have three offices in BNE,
SYD, MEL with more than 200 employees. Currently most of the data is stored in their
private cloud hosted in Sydney office and some on AWS . As part of the interview, you are
required to complete the following tasks:
• Task 1: discuss why risk assessment is the most critical step in developing and
managing cybersecurity program. in addition, identify and elaborate appropriate
risk assessment process for the organisation.
• Task 2: develop five questions that allow you to identify the most critical
information assets of the organisation then identify and rank top 5 critical assets
for the organisation.
• Task 3: identify and explain the top five vulnerabilities and threats to the
organisation information assets. Support you finding by quoting reputable sources
of information.
• Task 4: let’s assume that MASA’s website is one of the most critical information
asset of the organisation. Discuss how the top five threats could/could not impact


