CYB 6010 · St. Francis College

Implementation Roadmap

Implementation Roadmap

Phased delivery: Foundations (6 mo) → Program Maturity (18 mo) → Continuous Improvement (Year 3).

Foundations · Months 1-6
$45K-$60K
Completion15%

MFA to 100%

in-progress

Phishing baseline simulation

planned

KnowBe4 / Proofpoint deployed

Dependency: Phishing baseline

planned

Vendor inventory completed

planned

IRP documented

planned

Tabletop exercise scheduled

Dependency: IRP documented

planned
Program Maturity · Months 7-18
$15K-$28K
Completion0%

PAM deployed for admin accounts

Dependency: MFA to 100%

planned

Tier-1 vendor questionnaires complete

Dependency: Vendor inventory

planned

Contract clauses updated

Dependency: Tier-1 questionnaires

planned

Click-through rate below 10%

Dependency: KnowBe4 deployed

planned

First FERPA audit log review

planned

Quarterly board scorecard running

Dependency: IRP documented

planned
Continuous Improvement · Years 2-3
Sustaining
Completion0%

Click-through rate below 5%

Dependency: Click-through < 10%

planned

Zero Trust fully implemented

Dependency: PAM deployed

planned

Vendor monitoring automated

Dependency: Tier-1 questionnaires

planned

Annual IRP test complete

Dependency: Tabletop exercise

planned

ISO 27001 readiness assessment

planned

Board charter annual review

planned

Year 1 prioritizes human-factor risk reduction (phishing), identity hardening (MFA), and governance foundations (vendor inventory, IRP) because these deliver the highest risk reduction per dollar for a small college without extended procurement cycles.

Phase 1 Rationale

MFA enforcement and phishing simulation deliver the highest risk-reduction per dollar invested and can be deployed without extended procurement cycles. Vendor inventory and IRP documentation establish the governance foundation required for Phase 2 maturity milestones including PAM deployment and Tier-1 vendor questionnaires.

Phase 1

Months 1-6

$45K-$60K

MFA, phishing baseline, vendor inventory, IRP

Phase 2

Months 7-18

$15K-$28K

PAM, vendor questionnaires, FERPA audit

Phase 3

Years 2-3

Sustaining

Zero Trust, ISO 27001 readiness, automation

Framework alignment

NIST Cybersecurity Framework 2.0 · Primary governance structure
ISO/IEC 27001:2022 · ISMS design principles
FERPA · Mandatory compliance
NY SHIELD Act · State regulatory requirement
CISA Education Sector Guidance · Baseline posture reference

St. Francis College Cybersecurity Governance Portal · CYB 6010 · For executive and board use