CMGT/433 · Wk 4 · sample paper

CMGT/433 Wk 4: sample paper, in real form

Reviewed by Lenora Whitcombe, MSN, RN University of Phoenix True APA form Annotated

This page holds a complete CMGT/433 Wk 4 example in true form: a finished security analysis that models credential phishing and vendor payment fraud against a composite credit union, names the control that counters each step of the attack, and ends by stating what risk is left. The organization is invented for the paper, and no real employer or member is described.

1

Credential Phishing and Vendor Payment Fraud at a Regional Credit Union: A Threat Model, Control Selection, and Residual Risk

Student Name

College of Business and Information Technology, University of Phoenix

CMGT/433: Cyber Security

Instructor Name

Month Day, Year

What this page is doingWhy this title works: it names the threat, the kind of organization, and the three things the paper delivers, so a reader knows the genre before the first line of prose. It does not promise a survey of attack types, which is the commonest way a short security paper loses its footing. The block is plain APA 7 student format with no running head, and the course line carries the code the way Phoenix writes it, with the slash. The organization in the title is a composite, and the paper says so in its first sentence rather than leaving it to be assumed.
2

The Organization and the Scope of This Analysis

Cascade Ridge Credit Union is a composite built for this paper and does not describe a real employer. It runs 11 branches in two states, employs 240 staff, and serves about 96,000 members. Email, files, and sign-in all sit in one cloud tenant. Accounts payable is three people who release roughly 640 vendor payments a month, 27 of which move by wire and average 48,000 dollars. Twelve of those wires go to construction and technology vendors whose banking details change often enough that a change request does not look strange when it arrives. Security staffing is two analysts inside a four-person help desk, and no one watches alerts overnight.

The scope here is narrow on purpose. This analysis covers one threat, the theft of employee sign-in credentials by email and the use of that access to redirect a vendor payment, and it stops at the edge of the payment process. Member-facing online banking fraud, card skimming, and branch physical security are all real exposures and none of them are treated here. The narrowing is a choice about evidence rather than convenience, because the credit union's own numbers point at this threat. In the last simulated phishing exercise, 34 of 240 employees opened the message and 10 typed credentials into the fake sign-in page, a 4 percent submission rate concentrated in branch operations and accounts payable.

What this page is doingWhy the profile comes before the threat: every number in it gets used later. The 27 wires a month and the 48,000 dollar average become the impact figure, the 4 percent submission rate becomes the likelihood argument, and two analysts inside a four-person help desk explain why an answer built on constant monitoring would fail here. The scope sentence earns its place by naming what is left out. An unscoped security paper reads as a survey, and a survey cannot be defended with evidence in the space a week four assignment allows.
3

Threat Model: Credential Phishing to Vendor Payment Redirection

The threat modelled here is business email compromise that starts with credential phishing. It was chosen because it is both frequent and expensive at this size of organization. The Internet Crime Complaint Center recorded 21,489 business email compromise complaints in 2023 with adjusted losses above 2.9 billion dollars, second only to investment fraud in the categories it tracks (Federal Bureau of Investigation, 2024). Breach data for the same period puts a human element in 68 percent of the breaches analyzed and measures the median time from opening a phishing message to typing data into it at under a minute (Verizon, 2024). A control that depends on employees slowing down to inspect a message is arguing against both of those figures.

The attack runs in five steps, and every step is a place it can be broken. First, a message arrives that imitates the tenant sign-in page, usually as a shared-document notice or a missed voicemail alert. Second, the employee signs in on the attacker's relay page, which passes the password and the one-time code through to the real service while the employee waits and captures the session cookie that comes back; a push approval or a six-digit code does not survive this step. Third, the attacker signs in with that session, creates a mailbox rule that files anything containing invoice, wire, or ACH into a folder nobody opens, and reads quietly for two or three weeks. Fourth, the attacker waits for a genuine invoice thread rather than starting one. Fifth, the attacker replies inside that real thread with new banking details and a reason for the change.

Impact is easy to size here. One redirected wire at the 48,000 dollar average is recoverable only if the fraud is reported inside the short window in which a recall still works, and reconciliation at this credit union runs weekly, so discovery would often fall outside it. Two redirected payments in one accounts payable cycle would cost more than the two analysts cost in a year. Likelihood is harder to state honestly, and this paper will not attach a percentage to it. With a 4 percent submission rate across 240 employees, an attacker who runs one convincing campaign a quarter needs no unusual skill to obtain a working session, so a mailbox compromise inside twelve months is treated here as likely rather than merely possible.

What this page is doingWhy the attack is numbered instead of described: the next section can then say which step each control breaks, and a reader can check the pairing without taking anything on trust. Notice where the two kinds of evidence sit. National figures carry frequency, the organization's own numbers carry impact, and neither is asked to do the other's work. The paper also refuses to put a percentage on likelihood and says why, which reads as discipline rather than as a hole, since an invented probability is the easiest claim in a security paper to attack.
4

Controls and the Step Each One Counters

Control one is phishing-resistant multifactor authentication, issued as hardware security keys, for the 41 accounts that can approve a payment, change a vendor record, or administer the tenant. It counters step two. A hardware authenticator signs a challenge tied to the real sign-in address, so a relay page hosted somewhere else receives nothing it can replay, and that property is the reason the Cybersecurity and Infrastructure Security Agency (2022) separates this form of multifactor authentication from push prompts and one-time codes. Federal identity guidance draws the same line, treating resistance to impersonation as a property of the authenticator rather than of the user's attention (Grassi et al., 2017). The other 199 staff keep number-matching push while keys are phased in over two quarters.

Control two counters step five, the fraudulent instruction, and it assumes the mailbox is already lost. Any change to vendor banking details triggers a callback to a phone number that was already in the vendor record before the request arrived, made by someone other than the person who received the request, and every wire above 10,000 dollars needs a second approver. Control three counters step three, quiet persistence. Automatic forwarding to outside addresses is blocked at the tenant, and any new inbox rule that deletes messages or moves them out of the inbox raises an alert to the two analysts the same day. Published domain authentication set to reject removes the easy version of the spoofed sender, though not the harder version.

Control four is readiness rather than prevention. A written procedure names who kills active sessions, who freezes the payment queue, and who calls the receiving bank, and it is rehearsed twice a year against this exact scenario, following the preparation and detection phases of the federal incident handling guide (Cichonski et al., 2012). The four controls map to the govern, protect, and detect functions of the current cybersecurity framework, which is already the vocabulary the credit union's examiners use (National Institute of Standards and Technology, 2024). First-year cost is about 34,000 dollars: two keys each for 41 people at roughly 55 dollars a key, a security licensing tier that adds about 10 dollars per employee per month, and about 90 staff hours to write the callback procedure and run the rehearsal.

What this page is doingWhy each control opens by naming the step it counters: that pairing is what turns a recommendation into an argument, and it lets a short list beat a long one. Four controls tied to named steps read better than ten good practices in a bulleted list, because a list cannot be checked or argued with. Cost is there for the same reason. A recommendation carrying a first-year figure can be accepted or rejected by a reader with a budget, and one with no figure attached cannot be either.
5

Residual Risk and What Would Change This Judgement

These controls do not remove the risk, and this analysis would be worth less if it claimed they did. Three gaps remain open. A compromised vendor is untouched by any of it: when the fraudulent instruction is sent from the vendor's own real mailbox, domain authentication passes, the thread is genuine, and only the callback stands between the request and the money. The callback itself fails if the attacker changed the stored phone number first, which is why the number has to be the one on file before the request arrived and why a phone number change is handled as a banking change. And 199 employees keep an authenticator a relay page can defeat, so the argument above holds for the payment path, not for every mailbox in the building.

Stated plainly, the residual position is this. Mailbox compromise stays possible and should be planned for rather than argued away. Compromise that reaches a completed fraudulent payment moves from likely to unlikely within twelve months, because completing it now requires either defeating a hardware authenticator or compromising a vendor and then surviving a callback to a number the attacker did not supply. Expected loss is not zero. A reasonable planning figure is one attempted redirection a year, a small chance that it completes, and roughly 48,000 dollars of exposure per event, which is the argument for keeping the wire recall procedure current instead of assuming it will never be used.

Three measurements would change this judgement rather than confirm it. If the credential submission rate in the next exercise does not fall below 2 percent, the human side of the plan is not working and the key rollout should cover more accounts sooner than planned. If more than one inbox rule alert a month turns out to be genuine, an attacker is already inside and the next dollar belongs in detection rather than in awareness. If accounts payable reports that callbacks get skipped under month-end pressure, the control exists on paper only, and the honest response is to change the payment schedule rather than to retrain the same three people again.

What this page is doingWhy the paper ends on what it did not fix: the three gaps are the part a reader cannot supply on their own, and naming them is what separates an analysis from a sales pitch. The move that does the most work is the last one. Instead of closing on a summary, the paper names three measurements that would overturn its own recommendation, which shows the reasoning is testable. Note the compromised vendor gap in particular. It is the one the control set genuinely cannot reach, and hiding it would have been easy.
6

References

Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide (NIST Special Publication 800-61 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2

Cybersecurity and Infrastructure Security Agency. (2022). Implementing phishing-resistant MFA. U.S. Department of Homeland Security. https://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa

Federal Bureau of Investigation. (2024). Internet crime report 2023. Internet Crime Complaint Center. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf

Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital identity guidelines (NIST Special Publication 800-63-3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63-3

National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

Verizon. (2024). 2024 data breach investigations report. https://www.verizon.com/business/resources/reports/dbir/

How this CMGT 433 Wk 4 example is structured

In many sections the CMGT/433 Wk 4 assignment asks for an analysis of one threat against one organization rather than a survey of attack types, and your classroom's instructions and rubric decide the exact form. By week four of a five-week course, University of Phoenix's undergraduate Cyber Security course has usually moved from vocabulary to application, so this example is built to be applied. The first section gives the organization and says what the analysis leaves out, because a scope sentence is what stops a short paper from becoming a survey. The second section models the attack as five numbered steps. The third recommends four controls and names the step each one breaks, which is the pairing readers check for. The last section states residual risk and the three measurements that would change the judgement.

CMGT/433 Wk 4 questions, answered

Does a CMGT/433 security paper have to use a real company?

No. A composite organization with realistic numbers usually works better, because you can give yourself the details the analysis needs: payment volumes, staffing, and a phishing exercise result. Say in the first sentence that the organization is invented. Sections differ on whether a supplied scenario, your own workplace, or a composite is expected, so follow the instructions your classroom posts.

How many controls should a week 4 security analysis recommend?

Three to five, each attached to a specific step in the attack you modelled. A long list of good practices reads as copied from a checklist and cannot be defended in discussion. The paper above recommends four, names the step each one breaks, and attaches a first-year cost, which is what makes the set arguable instead of decorative.

Will admitting that risk remains cost me points?

The opposite is more common. A paper that ends with the risk removed invites the reply that no control set does that, and a reader who stops believing the ending rereads the middle with suspicion. Name what the controls do not cover, size the exposure that is left, and state the measurement that would change your judgement.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.