Cybersecurity / Information Security Auditing
3,000 words
Physical Security Audit of University Computing Facilities Using ISO/IEC 27002:2022
This postgraduate information-security coursework requires students to act as an IT Security Auditor working for CyberSAFE Auditors and conduct a professional physical-security audit of computing resources used by students at the University of Greenwich. The audit focuses on public student-study and open computing areas within the Dreadnought and Stephen Lawrence Buildings, with findings evaluated against relevant physical-security controls from ISO/IEC 27002:2022 Section 7. 202526 SL-COMP1431 CWK 2026-am … The project begins with planning and project-control activities. Students must define their audit tasks, plan the work independently and document progress through two Work-in-Progress reports, one produced near the beginning of the project and another approximately halfway through. Each WIP report is limited to 250 words and records completed activities, encountered or anticipated problems, planned next steps and potential risk areas. 202526 SL-COMP1431 CWK 2026-am … The second phase involves practical fieldwork. Students must visit the specified university buildings and decide on suitable audit methods, timetable and evidence-gathering procedures. The audit is restricted to public student areas and must not include staff rooms, seminar rooms or utility areas. Students must also comply with client-imposed constraints, including not communicating with university staff and approaching the audit from the perspective of an ordinary student rather than conducting highly technical operating-system or server-level investigation. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … The final professional audit report evaluates secure areas and equipment security, including physical security perimeters, entry controls, protection of rooms and facilities, working in secure areas, equipment siting, supporting utilities and cabling security. Findings should distinguish between expected controls and observed controls, identify gaps and provide justified recommendations for immediate and future management action. 202526 SL-COMP1431 CWK 2026-am … 202526 SL-COMP1431 CWK 2026-am … Assessment places particular emphasis on practical audit methodology, secure-area analysis, equipment security, audit conclusions, gap analysis, professional reporting and the two WIP reports. 202526 SL-COMP1431 CWK 2026-am … Overview word count: approximately 355 words. AI-use note: the brief states that this coursework does not lend itself to reliance on AI-based applications such as ChatGPT and emphasises original analysis, fieldwork and proper attribution of sources. 202526 SL-COMP1431 CWK 2026-am …
Read Model Answer →
Cyber Security / Cloud Management
2,500 words
Cyber Security and Cloud Defence Strategy for ShieldSafe Analytics
This Level 7 Cyber Security for Business and Cloud Management portfolio examines the security challenges faced by ShieldSafe Analytics Ltd., a multinational health analytics organisation specialising in AI-enabled diagnostics and telehealth. The organisation processes high volumes of sensitive patient information, including biometric and genomic data, across hybrid-cloud environments and IoT-enabled healthcare infrastructure. Following a suspected data-exfiltration incident involving anomalous traffic from a diagnostic platform connected to third-party cloud APIs, students are required to evaluate the organisation's information environment and develop appropriate cyber-security and cloud-defence strategies. The first task focuses on information environments and the weaponisation of information. Students identify critical elements of ShieldSafe's information environment, evaluate vulnerabilities associated with the data-exfiltration incident and examine how patient data or analytical systems could be manipulated by malicious actors. Relevant real-world healthcare cyber incidents should be used to support the analysis. The second task examines offensive and defensive Information Operations. Students analyse techniques used by nation-state actors and cybercriminal organisations, including healthcare ransomware incidents such as WannaCry, and compare offensive and defensive approaches. The analysis considers how ShieldSafe can balance these approaches while protecting sensitive data and preserving trust in AI-enabled diagnostic systems. The third task applies Information Operations within legal and ethical boundaries and requires development of a secure cloud migration strategy for ShieldSafe's legacy Electronic Health Record system. The supporting student guide specifically permits students to demonstrate an implementation using Amazon AWS, including IAM users and roles, VPC configuration, security groups, web servers, EC2 instances and AWS migration services. The final task requires a comprehensive cyber-defence strategy, including implementation of Zero Trust Architecture across cloud platforms and analysis of vulnerabilities affecting cyber-physical healthcare systems such as wearable medical devices and diagnostic equipment. Students must propose controls against both remote and local attacks. Overall, the portfolio integrates information operations, healthcare cybersecurity, hybrid-cloud protection, secure migration, Zero Trust, cyber-physical security and strategic cyber defence. The work is produced as a portfolio report using PebblePad and must use Harvard referencing throughout, with appropriate citation of academic sources, images, definitions and external arguments.
Read Model Answer →