Transportation Organization

Using the Center for Information Security (CIS) and MITRE ATT&CK Controls, match recommendations against Transportation Organization threat,
vulnerability, and/or attack (TVA) vectors Create a mitigation/remediation program to improve the overall cybersecurity stature of your organization. Your
results will be presented in a senior staff briefing. Use Transportation Outline for more details on the company.
Policy and Standards: Please highlight the formal development, documentation, review and approval of the information security policies, standards and
guidelines that define the information security requirements, processes and controls to be implemented for protection of an organization’s information and IT
assets.
Privacy: Please highlight the collection, disclosure, retention, use and sharing of privacy-related data across an organization.
Vulnerability identification and remediation: Please highlight an approach for an organization to predict threats, identify and remediate vulnerabilities, detect
and respond to attacks, and strategically develop countermeasures.
Business Development: For this section, please describe their function in the organization and what collaboration can be done to improve information
security across the organization
Human Resources: For this section, please describe their function in the organization and what collaboration can be done to improve information security
across the organization