Digital Security Risk and Audit – Information Security Audit of ABC Air

University:
Coventry University
Subject:
Digital Security Risk and Audit
Module:
Digital Security Risk and Audit
Assignment Type:
MS Technical and scientific writing
Word Count:
2,000 words
Academic Year:
2025

Assignment Overview

This individual coursework for the Digital Security Risk and Audit module requires students to prepare a 2,000-word information security audit report based on a case study involving ABC Air, a small aircraft service company responsible for aircraft maintenance for civil operators. The company records information including aircraft flying hours, servicing time, engineers' man-hours and related maintenance activities. An external contractor has also provided a report outlining a possible solution for ABC Air. Students are required to assess the information security risks associated with the scenario, complete an information security audit and produce a professional report, clearly identifying any assumptions made during the analysis. The assessment requires students to examine risk assessment, identification and analysis as part of the audit process. A suitable auditing approach must be selected and justified, with students considering either a general risk-based approach or a specific control-based approach. The report should explain why the selected approach is appropriate for the ABC Air scenario and demonstrate how it can be applied to the organisation's information security environment. The coursework also requires consideration of potential cyber attacks and their use within an integrated fault event analysis. Students must identify relevant information security threats and examine how an attack could affect the organisation and its information assets. The report should further identify appropriate standards, best practices or guidelines that could be used to mitigate information security breaches. These should be critically evaluated, including discussion of their advantages and disadvantages rather than simply being listed. The assessment develops students' ability to apply information security governance and audit practices within legal, ethical and professional contexts. It also requires consideration of recognised industry frameworks such as COBIT and international standards including the ISO 27000 series. Students are expected to perform systematic risk assessment and analysis, critically evaluate information assurance reference models, and select appropriate information security audit strategies for complex real-world scenarios. The marking criteria place particular emphasis on the quality of the information security audit, identification and adoption of appropriate international standards and frameworks, and critical evaluation of the benefits and limitations of security audit frameworks. The assessment allocates 20% to identifying and applying an appropriate audit approach, 50% to completing the conceptual information security audit and assurance, and 30% to interpreting and critically evaluating information assurance reference models. The report is an individual assessment and must be submitted as a PDF through Aula/Turnitin. The brief states that APA referencing should be used for the work and that all sources and any AI tools used must be acknowledged.

Megaminds Experience

Megaminds has supported academic requirements in digital security risk and audit, digital security risk and audit and related disciplines.