Cybersecurity / Information Security Auditing
3,000 words
Physical Security Audit of University Computing Facilities Using ISO/IEC 27002:2022
This postgraduate information-security coursework requires students to act as an IT Security Auditor working for CyberSAFE Auditors and conduct a professional physical-security audit of computing resources used by students at the University of Greenwich. The audit focuses on public student-study and open computing areas within the Dreadnought and Stephen Lawrence Buildings, with findings evaluated against relevant physical-security controls from ISO/IEC 27002:2022 Section 7. 202526 SL-COMP1431 CWK 2026-am … The project begins with planning and project-control activities. Students must define their audit tasks, plan the work independently and document progress through two Work-in-Progress reports, one produced near the beginning of the project and another approximately halfway through. Each WIP report is limited to 250 words and records completed activities, encountered or anticipated problems, planned next steps and potential risk areas. 202526 SL-COMP1431 CWK 2026-am … The second phase involves practical fieldwork. Students must visit the specified university buildings and decide on suitable audit methods, timetable and evidence-gathering procedures. The audit is restricted to public student areas and must not include staff rooms, seminar rooms or utility areas. Students must also comply with client-imposed constraints, including not communicating with university staff and approaching the audit from the perspective of an ordinary student rather than conducting highly technical operating-system or server-level investigation. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … The final professional audit report evaluates secure areas and equipment security, including physical security perimeters, entry controls, protection of rooms and facilities, working in secure areas, equipment siting, supporting utilities and cabling security. Findings should distinguish between expected controls and observed controls, identify gaps and provide justified recommendations for immediate and future management action. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … Assessment places particular emphasis on practical audit methodology, secure-area analysis, equipment security, audit conclusions, gap analysis, professional reporting and the two WIP reports. 202526 SL-COMP1431 CWK 2026-am … Overview word count: approximately 355 words. AI-use note: the brief states that this coursework does not lend itself to reliance on AI-based applications such as ChatGPT and emphasises original analysis, fieldwork and proper attribution of sources. 202526 SL-COMP1431 CWK 2026-am …
Read Model Answer →
Cyber Security
Contextual Risk Assessment and Policy to Address Information Security within Supplier Agreements
This assignment focuses on the development of a contextual risk assessment and an information security policy addressing security requirements within supplier agreements for Heathrow Airport Holdings (LHR). The assessment is an individual postgraduate task worth 60% of the module and requires students to apply information security risk assessment methods, security standards and policy development techniques to a realistic organisational scenario. The assignment is based on a cyber-attack affecting Heathrow and other European airports in September 2025, where disruption to a third-party cloud-based check-in and baggage system affected airport and airline operations. The scenario highlights the security risks associated with interconnected systems, third-party suppliers and dependence on critical digital services. Students are required to assume the role of a new Chief Information Security Officer (CISO) at Heathrow Airport Holdings and investigate the organisation, its environment and the relevant threat landscape. The task requires the development of a clear organisational context, including appropriate assumptions, followed by an asset-based information security risk assessment. The risk assessment should identify and prioritise relevant risks and support the selection of controls needed to manage residual information security risks. The main policy component requires students to develop an “Information Security within Supplier Agreements” policy aligned with the ISO 27000 family. The policy should establish clear security responsibilities between LHR and its suppliers and address the protection of information assets, legal and regulatory requirements, and supplier-related security obligations. Particular attention is required for confidentiality, integrity and availability, together with ISO 27002 controls relating to information security policies and supplier agreements. The assignment also requires consideration of acceptable use of information and other assets, information classification and information labelling. The final submission consists of a cover page, context establishment, an asset-based risk assessment, the supplier information security policy, references and supporting appendices. The context establishment is limited to a maximum of two pages or 1,000 words, while the policy is limited to three pages or 1,500 words. The risk assessment is completed using the supplied template. Students are also required to provide evidence and commentary concerning the development and tailoring of the policy when using an approved AI tool, together with a self-written evaluation addressing strengths, weaknesses, privacy, GDPR and ethical considerations. The assessment is marked across context establishment, asset-based risk assessment, the information security within supplier agreements policy, and presentation, design and references. At least 20 authentic references, including standards and papers accessed through the University library, are required.
Read Model Answer →