Security of Connected Systems
4,500 words
CW: Security Evaluation
This assignment is an individual technical report focused on the security evaluation and strategic development of a rapidly expanding Internet of Things (IoT) systems developer based in Coventry. The client specialises in innovative IoT devices and systems for residential and commercial applications, particularly smart energy monitoring, and is planning to scale its operations and expand into new markets. The report is designed to provide practical and strategic guidance on how the organisation can achieve this growth while maintaining strong cybersecurity. The assignment requires students to act as an external IoT Security and Scaling Strategist and critically evaluate the organisation’s current and future security needs. The report covers four principal areas: organisational change strategy, secure design and development strategy, security audit strategy, and security recommendations. The organisational change section considers internal and external factors influencing growth, the development and implementation of an organisational strategy, monitoring against objectives, and approaches to leading and managing strategic change using relevant change management theories and models. The secure design and development section requires an overview and evaluation of possible secure design processes for IoT systems, including their strengths and weaknesses, followed by a recommendation for an appropriate process. The security audit section examines methods such as PTES and OWASP and develops a guide for conducting a security audit, including the testing methodology, rationale for each stage, and evaluation of different approaches. The security recommendations section requires a case study of an IoT security vulnerability, examination of where the security flaw was introduced, assessment of weaknesses in the secure design or audit process, consideration of the resulting security impact, and recommendations for improvement. The report should be written for a technical audience, particularly the client’s software development team, and should use appropriate structure, technical language, diagrams where useful, and APA referencing. The organisational strategy and strategic change proposal should be included in appendices and referenced within the main report. The assessment is worth 30 credits and has a maximum word count of 4,500 words, with the main sections weighted across organisational change, secure design, security auditing, security recommendations, and report structure.
Read Model Answer →
Security of Emerging Connected Systems
1,500 words
CW1: Policy and Legal Aspects Report – IoT System
This 1,500-word report for the Security of Emerging Connected Systems module examines the legal and security implications of a proposed Internet of Things (IoT) system designed for consumers to monitor food intake and bodyweight. The coursework requires students to provide an initial investigation of the potential legal pitfalls associated with the proposed product and identify appropriate solutions or mitigation measures. The report is worth 5 credits and is assessed as an individual written report. The proposed IoT system consists of several connected components. A smartphone application allows users to scan barcodes of processed food to record calorie and nutritional information against their health record. A kitchen scale communicates with the phone application to record the weight of ingredients used in home-cooked meals. A bathroom scale records the user's weight and provides light and sound reminders to encourage regular measurements. A UK-based server stores the collected information and generates individual user reports. The main purpose of the report is to ensure that the company understands the UK and international laws that may apply to the proposed system. Students must identify potential legal issues and recommend appropriate mitigation through technology, organisational policy, licensing arrangements or user agreements. The system definition is deliberately broad, so students should not make unsupported assumptions about its design. Where several options have different legal implications, the report should compare the relevant alternatives and explain their implications rather than presenting only one solution. The initial product is intended for UK residents, while the company is considering future expansion into the United States. Consequently, the report should focus primarily on UK law but also include a short section discussing legal aspects that may need to be reconsidered when entering the US market. The report is intended for company executives and may subsequently be provided to the R&D department. Therefore, high-level outcomes should be communicated early, while useful links to technical information such as encryption schemes, protocols and frameworks may be provided without extensive technical explanations in the main report. The assessment places 50% of the marks on understanding and coverage of UK and US law, 40% on technical recommendations and 10% on report presentation. Strong submissions are expected to provide comprehensive coverage of relevant legislation, connect legal issues with the wider security context, analyse technical recommendations for both regions, identify differences between UK and US requirements and support arguments with appropriate citations and a wide range of sources. The assignment learning outcomes focus on critically evaluating the role of security policy in protecting information assets and proposing appropriate policies for internet-based technologies. They also require students to demonstrate an understanding of key legislation relating to information security and how legislation influences organisational security policy. The final report should therefore combine legal analysis with practical security recommendations, addressing the proposed IoT system from both UK and US perspectives while remaining suitable for both technical staff and non-technical management.
Read Model Answer →