Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Cybersecurity / Information Security Auditing
3,000 words
Physical Security Audit of University Computing Facilities Using ISO/IEC 27002:2022
This postgraduate information-security coursework requires students to act as an IT Security Auditor working for CyberSAFE Auditors and conduct a professional physical-security audit of computing resources used by students at the University of Greenwich. The audit focuses on public student-study and open computing areas within the Dreadnought and Stephen Lawrence Buildings, with findings evaluated against relevant physical-security controls from ISO/IEC 27002:2022 Section 7. 202526 SL-COMP1431 CWK 2026-am … The project begins with planning and project-control activities. Students must define their audit tasks, plan the work independently and document progress through two Work-in-Progress reports, one produced near the beginning of the project and another approximately halfway through. Each WIP report is limited to 250 words and records completed activities, encountered or anticipated problems, planned next steps and potential risk areas. 202526 SL-COMP1431 CWK 2026-am … The second phase involves practical fieldwork. Students must visit the specified university buildings and decide on suitable audit methods, timetable and evidence-gathering procedures. The audit is restricted to public student areas and must not include staff rooms, seminar rooms or utility areas. Students must also comply with client-imposed constraints, including not communicating with university staff and approaching the audit from the perspective of an ordinary student rather than conducting highly technical operating-system or server-level investigation. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … The final professional audit report evaluates secure areas and equipment security, including physical security perimeters, entry controls, protection of rooms and facilities, working in secure areas, equipment siting, supporting utilities and cabling security. Findings should distinguish between expected controls and observed controls, identify gaps and provide justified recommendations for immediate and future management action. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … Assessment places particular emphasis on practical audit methodology, secure-area analysis, equipment security, audit conclusions, gap analysis, professional reporting and the two WIP reports. 202526 SL-COMP1431 CWK 2026-am … Overview word count: approximately 355 words. AI-use note: the brief states that this coursework does not lend itself to reliance on AI-based applications such as ChatGPT and emphasises original analysis, fieldwork and proper attribution of sources. 202526 SL-COMP1431 CWK 2026-am …
Read Model Answer →
Cyber Security
Contextual Risk Assessment and Policy to Address Information Security within Supplier Agreements
This assignment focuses on the development of a contextual risk assessment and an information security policy addressing security requirements within supplier agreements for Heathrow Airport Holdings (LHR). The assessment is an individual postgraduate task worth 60% of the module and requires students to apply information security risk assessment methods, security standards and policy development techniques to a realistic organisational scenario. The assignment is based on a cyber-attack affecting Heathrow and other European airports in September 2025, where disruption to a third-party cloud-based check-in and baggage system affected airport and airline operations. The scenario highlights the security risks associated with interconnected systems, third-party suppliers and dependence on critical digital services. Students are required to assume the role of a new Chief Information Security Officer (CISO) at Heathrow Airport Holdings and investigate the organisation, its environment and the relevant threat landscape. The task requires the development of a clear organisational context, including appropriate assumptions, followed by an asset-based information security risk assessment. The risk assessment should identify and prioritise relevant risks and support the selection of controls needed to manage residual information security risks. The main policy component requires students to develop an “Information Security within Supplier Agreements” policy aligned with the ISO 27000 family. The policy should establish clear security responsibilities between LHR and its suppliers and address the protection of information assets, legal and regulatory requirements, and supplier-related security obligations. Particular attention is required for confidentiality, integrity and availability, together with ISO 27002 controls relating to information security policies and supplier agreements. The assignment also requires consideration of acceptable use of information and other assets, information classification and information labelling. The final submission consists of a cover page, context establishment, an asset-based risk assessment, the supplier information security policy, references and supporting appendices. The context establishment is limited to a maximum of two pages or 1,000 words, while the policy is limited to three pages or 1,500 words. The risk assessment is completed using the supplied template. Students are also required to provide evidence and commentary concerning the development and tailoring of the policy when using an approved AI tool, together with a self-written evaluation addressing strengths, weaknesses, privacy, GDPR and ethical considerations. The assessment is marked across context establishment, asset-based risk assessment, the information security within supplier agreements policy, and presentation, design and references. At least 20 authentic references, including standards and papers accessed through the University library, are required.
Read Model Answer →
Security of Emerging Connected Systems
1,500 words
CW1: Policy and Legal Aspects Report – IoT System
This 1,500-word report for the Security of Emerging Connected Systems module examines the legal and security implications of a proposed Internet of Things (IoT) system designed for consumers to monitor food intake and bodyweight. The coursework requires students to provide an initial investigation of the potential legal pitfalls associated with the proposed product and identify appropriate solutions or mitigation measures. The report is worth 5 credits and is assessed as an individual written report. The proposed IoT system consists of several connected components. A smartphone application allows users to scan barcodes of processed food to record calorie and nutritional information against their health record. A kitchen scale communicates with the phone application to record the weight of ingredients used in home-cooked meals. A bathroom scale records the user's weight and provides light and sound reminders to encourage regular measurements. A UK-based server stores the collected information and generates individual user reports. The main purpose of the report is to ensure that the company understands the UK and international laws that may apply to the proposed system. Students must identify potential legal issues and recommend appropriate mitigation through technology, organisational policy, licensing arrangements or user agreements. The system definition is deliberately broad, so students should not make unsupported assumptions about its design. Where several options have different legal implications, the report should compare the relevant alternatives and explain their implications rather than presenting only one solution. The initial product is intended for UK residents, while the company is considering future expansion into the United States. Consequently, the report should focus primarily on UK law but also include a short section discussing legal aspects that may need to be reconsidered when entering the US market. The report is intended for company executives and may subsequently be provided to the R&D department. Therefore, high-level outcomes should be communicated early, while useful links to technical information such as encryption schemes, protocols and frameworks may be provided without extensive technical explanations in the main report. The assessment places 50% of the marks on understanding and coverage of UK and US law, 40% on technical recommendations and 10% on report presentation. Strong submissions are expected to provide comprehensive coverage of relevant legislation, connect legal issues with the wider security context, analyse technical recommendations for both regions, identify differences between UK and US requirements and support arguments with appropriate citations and a wide range of sources. The assignment learning outcomes focus on critically evaluating the role of security policy in protecting information assets and proposing appropriate policies for internet-based technologies. They also require students to demonstrate an understanding of key legislation relating to information security and how legislation influences organisational security policy. The final report should therefore combine legal analysis with practical security recommendations, addressing the proposed IoT system from both UK and US perspectives while remaining suitable for both technical staff and non-technical management.
Read Model Answer →
Digital Security Risk and Audit
2,000 words
Digital Security Risk and Audit – Information Security Audit of ABC Air
This individual coursework for the Digital Security Risk and Audit module requires students to prepare a 2,000-word information security audit report based on a case study involving ABC Air, a small aircraft service company responsible for aircraft maintenance for civil operators. The company records information including aircraft flying hours, servicing time, engineers' man-hours and related maintenance activities. An external contractor has also provided a report outlining a possible solution for ABC Air. Students are required to assess the information security risks associated with the scenario, complete an information security audit and produce a professional report, clearly identifying any assumptions made during the analysis. The assessment requires students to examine risk assessment, identification and analysis as part of the audit process. A suitable auditing approach must be selected and justified, with students considering either a general risk-based approach or a specific control-based approach. The report should explain why the selected approach is appropriate for the ABC Air scenario and demonstrate how it can be applied to the organisation's information security environment. The coursework also requires consideration of potential cyber attacks and their use within an integrated fault event analysis. Students must identify relevant information security threats and examine how an attack could affect the organisation and its information assets. The report should further identify appropriate standards, best practices or guidelines that could be used to mitigate information security breaches. These should be critically evaluated, including discussion of their advantages and disadvantages rather than simply being listed. The assessment develops students' ability to apply information security governance and audit practices within legal, ethical and professional contexts. It also requires consideration of recognised industry frameworks such as COBIT and international standards including the ISO 27000 series. Students are expected to perform systematic risk assessment and analysis, critically evaluate information assurance reference models, and select appropriate information security audit strategies for complex real-world scenarios. The marking criteria place particular emphasis on the quality of the information security audit, identification and adoption of appropriate international standards and frameworks, and critical evaluation of the benefits and limitations of security audit frameworks. The assessment allocates 20% to identifying and applying an appropriate audit approach, 50% to completing the conceptual information security audit and assurance, and 30% to interpreting and critically evaluating information assurance reference models. The report is an individual assessment and must be submitted as a PDF through Aula/Turnitin. The brief states that APA referencing should be used for the work and that all sources and any AI tools used must be acknowledged.
Read Model Answer →