Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Security of Connected Systems
4,500 words
CW: Security Evaluation
This assignment is an individual technical report focused on the security evaluation and strategic development of a rapidly expanding Internet of Things (IoT) systems developer based in Coventry. The client specialises in innovative IoT devices and systems for residential and commercial applications, particularly smart energy monitoring, and is planning to scale its operations and expand into new markets. The report is designed to provide practical and strategic guidance on how the organisation can achieve this growth while maintaining strong cybersecurity. The assignment requires students to act as an external IoT Security and Scaling Strategist and critically evaluate the organisation’s current and future security needs. The report covers four principal areas: organisational change strategy, secure design and development strategy, security audit strategy, and security recommendations. The organisational change section considers internal and external factors influencing growth, the development and implementation of an organisational strategy, monitoring against objectives, and approaches to leading and managing strategic change using relevant change management theories and models. The secure design and development section requires an overview and evaluation of possible secure design processes for IoT systems, including their strengths and weaknesses, followed by a recommendation for an appropriate process. The security audit section examines methods such as PTES and OWASP and develops a guide for conducting a security audit, including the testing methodology, rationale for each stage, and evaluation of different approaches. The security recommendations section requires a case study of an IoT security vulnerability, examination of where the security flaw was introduced, assessment of weaknesses in the secure design or audit process, consideration of the resulting security impact, and recommendations for improvement. The report should be written for a technical audience, particularly the client’s software development team, and should use appropriate structure, technical language, diagrams where useful, and APA referencing. The organisational strategy and strategic change proposal should be included in appendices and referenced within the main report. The assessment is worth 30 credits and has a maximum word count of 4,500 words, with the main sections weighted across organisational change, secure design, security auditing, security recommendations, and report structure.
Read Model Answer →
Cyber Security / Internet of Things / Connected Systems
4,500 words
Security Evaluation for Connected Systems: IoT Strategy, Secure Design, Security Auditing and Organisational Change
This Security of Connected Systems assessment requires students to act as an external IoT Security and Scaling Strategist for a rapidly expanding Coventry-based technology startup specialising in connected devices and smart energy-monitoring systems. The client intends to scale its operations and enter new markets and therefore requires both organisational-change guidance and a comprehensive evaluation of its cybersecurity posture. 38f2fba9a933f212c9e46e8cc591cf2… The report combines business strategy with technical cybersecurity analysis. Students must review different secure design and development methodologies, compare their strengths and weaknesses, and recommend an appropriate approach for integrating security into the client's IoT software-development lifecycle. 38f2fba9a933f212c9e46e8cc591cf2… 38f2fba9a933f212c9e46e8cc591cf2… A major component of the assessment focuses on organisational change strategy. Students examine the internal and external factors driving organisational growth, develop a comprehensive strategy for achieving the client's business objectives, and explain how that strategy should be implemented and monitored. The report must also critically evaluate relevant change-management theories and models and address the complexities of leading and managing strategic transformation. This section carries 35% of the marks and is allocated approximately 2,000 words. 38f2fba9a933f212c9e46e8cc591cf2… The Security Audit Strategy section requires students to design a guide for auditing the client's connected system. Different approaches, including methodologies such as PTES and OWASP, should be compared and evaluated. Students must explain each stage of the selected testing methodology and justify why the individual steps are required. 38f2fba9a933f212c9e46e8cc591cf2… The final technical component applies these principles to an IoT vulnerability case study. Students research a real vulnerability in an IoT device, explain where the security flaw was introduced, identify weaknesses in the secure-design or audit process, assess the resulting security impact and propose appropriate corrective actions. 38f2fba9a933f212c9e46e8cc591cf2… Overall, the coursework integrates IoT cybersecurity, secure software development, security auditing, vulnerability analysis, organisational strategy and strategic change management. The marking scheme allocates 35% to organisational-change strategy, 20% each to secure design and development, security auditing and security recommendations, and 5% to report structure. 38f2fba9a933f212c9e46e8cc591cf2… Important: the brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on a website. 38f2fba9a933f212c9e46e8cc591cf2… So use an original public summary like the one above, but do not upload the original brief itself.
Read Model Answer →
Cyber Security
Contextual Risk Assessment and Policy to Address Information Security within Supplier Agreements
This assignment focuses on the development of a contextual risk assessment and an information security policy addressing security requirements within supplier agreements for Heathrow Airport Holdings (LHR). The assessment is an individual postgraduate task worth 60% of the module and requires students to apply information security risk assessment methods, security standards and policy development techniques to a realistic organisational scenario. The assignment is based on a cyber-attack affecting Heathrow and other European airports in September 2025, where disruption to a third-party cloud-based check-in and baggage system affected airport and airline operations. The scenario highlights the security risks associated with interconnected systems, third-party suppliers and dependence on critical digital services. Students are required to assume the role of a new Chief Information Security Officer (CISO) at Heathrow Airport Holdings and investigate the organisation, its environment and the relevant threat landscape. The task requires the development of a clear organisational context, including appropriate assumptions, followed by an asset-based information security risk assessment. The risk assessment should identify and prioritise relevant risks and support the selection of controls needed to manage residual information security risks. The main policy component requires students to develop an “Information Security within Supplier Agreements” policy aligned with the ISO 27000 family. The policy should establish clear security responsibilities between LHR and its suppliers and address the protection of information assets, legal and regulatory requirements, and supplier-related security obligations. Particular attention is required for confidentiality, integrity and availability, together with ISO 27002 controls relating to information security policies and supplier agreements. The assignment also requires consideration of acceptable use of information and other assets, information classification and information labelling. The final submission consists of a cover page, context establishment, an asset-based risk assessment, the supplier information security policy, references and supporting appendices. The context establishment is limited to a maximum of two pages or 1,000 words, while the policy is limited to three pages or 1,500 words. The risk assessment is completed using the supplied template. Students are also required to provide evidence and commentary concerning the development and tailoring of the policy when using an approved AI tool, together with a self-written evaluation addressing strengths, weaknesses, privacy, GDPR and ethical considerations. The assessment is marked across context establishment, asset-based risk assessment, the information security within supplier agreements policy, and presentation, design and references. At least 20 authentic references, including standards and papers accessed through the University library, are required.
Read Model Answer →
Security of Emerging Connected Systems
1,500 words
CW1: Policy and Legal Aspects Report – IoT System
This 1,500-word report for the Security of Emerging Connected Systems module examines the legal and security implications of a proposed Internet of Things (IoT) system designed for consumers to monitor food intake and bodyweight. The coursework requires students to provide an initial investigation of the potential legal pitfalls associated with the proposed product and identify appropriate solutions or mitigation measures. The report is worth 5 credits and is assessed as an individual written report. The proposed IoT system consists of several connected components. A smartphone application allows users to scan barcodes of processed food to record calorie and nutritional information against their health record. A kitchen scale communicates with the phone application to record the weight of ingredients used in home-cooked meals. A bathroom scale records the user's weight and provides light and sound reminders to encourage regular measurements. A UK-based server stores the collected information and generates individual user reports. The main purpose of the report is to ensure that the company understands the UK and international laws that may apply to the proposed system. Students must identify potential legal issues and recommend appropriate mitigation through technology, organisational policy, licensing arrangements or user agreements. The system definition is deliberately broad, so students should not make unsupported assumptions about its design. Where several options have different legal implications, the report should compare the relevant alternatives and explain their implications rather than presenting only one solution. The initial product is intended for UK residents, while the company is considering future expansion into the United States. Consequently, the report should focus primarily on UK law but also include a short section discussing legal aspects that may need to be reconsidered when entering the US market. The report is intended for company executives and may subsequently be provided to the R&D department. Therefore, high-level outcomes should be communicated early, while useful links to technical information such as encryption schemes, protocols and frameworks may be provided without extensive technical explanations in the main report. The assessment places 50% of the marks on understanding and coverage of UK and US law, 40% on technical recommendations and 10% on report presentation. Strong submissions are expected to provide comprehensive coverage of relevant legislation, connect legal issues with the wider security context, analyse technical recommendations for both regions, identify differences between UK and US requirements and support arguments with appropriate citations and a wide range of sources. The assignment learning outcomes focus on critically evaluating the role of security policy in protecting information assets and proposing appropriate policies for internet-based technologies. They also require students to demonstrate an understanding of key legislation relating to information security and how legislation influences organisational security policy. The final report should therefore combine legal analysis with practical security recommendations, addressing the proposed IoT system from both UK and US perspectives while remaining suitable for both technical staff and non-technical management.
Read Model Answer →
Security of Emerging Connected Systems
2,000 words
Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations
This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.
Read Model Answer →
People Practice / Human Resource Management
2,500 words
Business, Culture and Change in Context: Organisational Acquisition Case Study
This CIPD Level 3 assessment examines how the external business environment, organisational culture and planned change influence organisations and their people. The assessment is based on a case study involving Best Pharmacy Ever (BPE), a small group of local pharmacies considering the acquisition of Emrosu, a much larger national pharmacy chain with approximately 100 stores and an established online pharmacy operation. The acquisition creates significant implications for organisational structure, culture, technology, people practices and change management. Learners are required to provide written responses to nine case-based questions. The assessment begins by examining external factors that may affect the acquisition and identifying appropriate post-acquisition business goals. It also requires consideration of the organisations' products, services and customers and the ways technology could support people professionals, improve working practices and strengthen collaboration following organisational growth. A central component of the assessment concerns organisational culture. Learners must explain the meaning and importance of culture, consider organisations as interconnected systems, and assess how the actions of people professionals can influence wider organisational outcomes. The final questions focus on planned organisational change, the contribution people professionals can make during periods of transition and the potential impact of significant change on employees. The unit therefore develops understanding of environmental analysis, organisational systems, workplace culture, technology and effective change management from a people-practice perspective. Written answers should make clear and consistent use of the case study and demonstrate application of relevant people-practice concepts rather than providing generic theoretical descriptions. The required submission is approximately 2,500 words, with a permitted variation of ±10%, subject to the CIPD word-count policy.
Read Model Answer →