This 1,500-word report for the Security of Emerging Connected Systems module examines the legal and security implications of a proposed Internet of Things (IoT) system designed for consumers to monitor food intake and bodyweight. The coursework requires students to provide an initial investigation of the potential legal pitfalls associated with the proposed product and identify appropriate solutions or mitigation measures. The report is worth 5 credits and is assessed as an individual written report. The proposed IoT system consists of several connected components. A smartphone application allows users to scan barcodes of processed food to record calorie and nutritional information against their health record. A kitchen scale communicates with the phone application to record the weight of ingredients used in home-cooked meals. A bathroom scale records the user's weight and provides light and sound reminders to encourage regular measurements. A UK-based server stores the collected information and generates individual user reports. The main purpose of the report is to ensure that the company understands the UK and international laws that may apply to the proposed system. Students must identify potential legal issues and recommend appropriate mitigation through technology, organisational policy, licensing arrangements or user agreements. The system definition is deliberately broad, so students should not make unsupported assumptions about its design. Where several options have different legal implications, the report should compare the relevant alternatives and explain their implications rather than presenting only one solution. The initial product is intended for UK residents, while the company is considering future expansion into the United States. Consequently, the report should focus primarily on UK law but also include a short section discussing legal aspects that may need to be reconsidered when entering the US market. The report is intended for company executives and may subsequently be provided to the R&D department. Therefore, high-level outcomes should be communicated early, while useful links to technical information such as encryption schemes, protocols and frameworks may be provided without extensive technical explanations in the main report. The assessment places 50% of the marks on understanding and coverage of UK and US law, 40% on technical recommendations and 10% on report presentation. Strong submissions are expected to provide comprehensive coverage of relevant legislation, connect legal issues with the wider security context, analyse technical recommendations for both regions, identify differences between UK and US requirements and support arguments with appropriate citations and a wide range of sources. The assignment learning outcomes focus on critically evaluating the role of security policy in protecting information assets and proposing appropriate policies for internet-based technologies. They also require students to demonstrate an understanding of key legislation relating to information security and how legislation influences organisational security policy. The final report should therefore combine legal analysis with practical security recommendations, addressing the proposed IoT system from both UK and US perspectives while remaining suitable for both technical staff and non-technical management.
IoT Security · Internet of Things · Legal Aspects · UK Law · US Law · Data Protection · Privacy · Information Security Legislation · Security Policy · Security Policies · Technical Recommendations · IoT Devices
Megaminds has supported academic requirements in security of emerging connected systems, security of emerging connected systems and related disciplines.