Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

201 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Audit Methodology” Clear filters

Available Model Answers (3)

Real-time Database Sync
Cybersecurity / Information Security Auditing 3,000 words

Physical Security Audit of University Computing Facilities Using ISO/IEC 27002:2022

This postgraduate information-security coursework requires students to act as an IT Security Auditor working for CyberSAFE Auditors and conduct a professional physical-security audit of computing resources used by students at the University of Greenwich. The audit focuses on public student-study and open computing areas within the Dreadnought and Stephen Lawrence Buildings, with findings evaluated against relevant physical-security controls from ISO/IEC 27002:2022 Section 7. 202526 SL-COMP1431 CWK 2026-am … The project begins with planning and project-control activities. Students must define their audit tasks, plan the work independently and document progress through two Work-in-Progress reports, one produced near the beginning of the project and another approximately halfway through. Each WIP report is limited to 250 words and records completed activities, encountered or anticipated problems, planned next steps and potential risk areas. 202526 SL-COMP1431 CWK 2026-am … The second phase involves practical fieldwork. Students must visit the specified university buildings and decide on suitable audit methods, timetable and evidence-gathering procedures. The audit is restricted to public student areas and must not include staff rooms, seminar rooms or utility areas. Students must also comply with client-imposed constraints, including not communicating with university staff and approaching the audit from the perspective of an ordinary student rather than conducting highly technical operating-system or server-level investigation. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … The final professional audit report evaluates secure areas and equipment security, including physical security perimeters, entry controls, protection of rooms and facilities, working in secure areas, equipment siting, supporting utilities and cabling security. Findings should distinguish between expected controls and observed controls, identify gaps and provide justified recommendations for immediate and future management action. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … Assessment places particular emphasis on practical audit methodology, secure-area analysis, equipment security, audit conclusions, gap analysis, professional reporting and the two WIP reports. 202526 SL-COMP1431 CWK 2026-am … Overview word count: approximately 355 words. AI-use note: the brief states that this coursework does not lend itself to reliance on AI-based applications such as ChatGPT and emphasises original analysis, fieldwork and proper attribution of sources. 202526 SL-COMP1431 CWK 2026-am …

Read Model Answer →
Digital Security Risk and Audit 2,000 words

Digital Security Risk and Audit – Information Security Audit of ABC Air

This individual coursework for the Digital Security Risk and Audit module requires students to prepare a 2,000-word information security audit report based on a case study involving ABC Air, a small aircraft service company responsible for aircraft maintenance for civil operators. The company records information including aircraft flying hours, servicing time, engineers' man-hours and related maintenance activities. An external contractor has also provided a report outlining a possible solution for ABC Air. Students are required to assess the information security risks associated with the scenario, complete an information security audit and produce a professional report, clearly identifying any assumptions made during the analysis. The assessment requires students to examine risk assessment, identification and analysis as part of the audit process. A suitable auditing approach must be selected and justified, with students considering either a general risk-based approach or a specific control-based approach. The report should explain why the selected approach is appropriate for the ABC Air scenario and demonstrate how it can be applied to the organisation's information security environment. The coursework also requires consideration of potential cyber attacks and their use within an integrated fault event analysis. Students must identify relevant information security threats and examine how an attack could affect the organisation and its information assets. The report should further identify appropriate standards, best practices or guidelines that could be used to mitigate information security breaches. These should be critically evaluated, including discussion of their advantages and disadvantages rather than simply being listed. The assessment develops students' ability to apply information security governance and audit practices within legal, ethical and professional contexts. It also requires consideration of recognised industry frameworks such as COBIT and international standards including the ISO 27000 series. Students are expected to perform systematic risk assessment and analysis, critically evaluate information assurance reference models, and select appropriate information security audit strategies for complex real-world scenarios. The marking criteria place particular emphasis on the quality of the information security audit, identification and adoption of appropriate international standards and frameworks, and critical evaluation of the benefits and limitations of security audit frameworks. The assessment allocates 20% to identifying and applying an appropriate audit approach, 50% to completing the conceptual information security audit and assurance, and 30% to interpreting and critically evaluating information assurance reference models. The report is an individual assessment and must be submitted as a PDF through Aula/Turnitin. The brief states that APA referencing should be used for the work and that all sources and any AI tools used must be acknowledged.

Read Model Answer →
Security of Emerging Connected Systems 2,000 words

Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations

This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.

Read Model Answer →