Assessment · IT audit

Collins Aerospace IT Audit: Post-Incident Assessment

A graduate IT-audit engagement on a simulated aerospace breach: COBIT-framed planning, NIST 800-30 risk assessment, CMMC Level 3 gap analysis, five headline findings and a costed remediation roadmap.

Status
Academic · Completed
Area
Assessments
Period
Fall 2025 · ITMM 586, Illinois Tech
Stack
COBIT 2019NIST 800-30NIST 800-171CMMC 2.0ISO 27001
Audit lifecycle from planning through risk assessment, control testing and reporting to remediation, with the five findings ranked by severity
The engagement as it ran, and the five findings ranked by severity. Click to open full size.
5Key findings
18Risks identified
$4.5M+Remediation estimate
$2.3BContracts at risk

Conduct a comprehensive IT audit engagement of Collins Aerospace’s information security controls following a simulated cybersecurity incident. This graduate-level project demonstrates practical application of IT audit frameworks, risk assessment methodologies, CMMC Level 3 gap analysis, and remediation planning for an enterprise aerospace organization.

Frameworks & Methodologies Applied

COBIT 2019 · NIST SP 800-30 · NIST SP 800-53 · NIST SP 800-171/172 · CMMC 2.0 · ISO/IEC 27001:2022 · COSO · Risk Assessment · Control Testing · Remediation Planning

Critical Audit Findings

1. Inadequate MFA Critical 60.5% of VPN accounts lack MFA
2. Privileged Access Gaps High No reviews in 30 months
3. Incident Response High 16-18 hour detection delay
4. Backup & DR Critical No air-gapped backups
5. Vendor Security Medium 47 vendors unassessed

Project Deliverables

  • Audit Planning Memo: Comprehensive planning documentation and scope definition
  • Executive Presentation: Board-level findings and recommendations presentation
  • Control Testing Procedures: Detailed testing methodology and evidence collection
  • Remediation Roadmap: Prioritized implementation plan with cost estimates
  • Incident Timeline Analysis: Attack timeline reconstruction and root cause analysis
  • NIST Risk Assessment: 8 complete assessment tables with threat modeling

Business Impact Analysis

Direct Incident Costs: $15M+ in losses

Operational Impact: 217 flights cancelled, 2.8M transactions lost

Compliance Risk: CMMC Level 3 certification required Q2 2026

Academic Context

Completed as part of ITMM 586 - Information Technology Auditing at Illinois Institute of Technology (Fall 2025). The project included 12+ weekly discussions on audit concepts, ethics case studies, and real-world incident analysis including the CrowdStrike global outage (July 2024).

Related writing

Notes from the same work.

All writing