Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Cyber Security
Contextual Risk Assessment and Policy to Address Information Security within Supplier Agreements
This assignment focuses on the development of a contextual risk assessment and an information security policy addressing security requirements within supplier agreements for Heathrow Airport Holdings (LHR). The assessment is an individual postgraduate task worth 60% of the module and requires students to apply information security risk assessment methods, security standards and policy development techniques to a realistic organisational scenario. The assignment is based on a cyber-attack affecting Heathrow and other European airports in September 2025, where disruption to a third-party cloud-based check-in and baggage system affected airport and airline operations. The scenario highlights the security risks associated with interconnected systems, third-party suppliers and dependence on critical digital services. Students are required to assume the role of a new Chief Information Security Officer (CISO) at Heathrow Airport Holdings and investigate the organisation, its environment and the relevant threat landscape. The task requires the development of a clear organisational context, including appropriate assumptions, followed by an asset-based information security risk assessment. The risk assessment should identify and prioritise relevant risks and support the selection of controls needed to manage residual information security risks. The main policy component requires students to develop an “Information Security within Supplier Agreements” policy aligned with the ISO 27000 family. The policy should establish clear security responsibilities between LHR and its suppliers and address the protection of information assets, legal and regulatory requirements, and supplier-related security obligations. Particular attention is required for confidentiality, integrity and availability, together with ISO 27002 controls relating to information security policies and supplier agreements. The assignment also requires consideration of acceptable use of information and other assets, information classification and information labelling. The final submission consists of a cover page, context establishment, an asset-based risk assessment, the supplier information security policy, references and supporting appendices. The context establishment is limited to a maximum of two pages or 1,000 words, while the policy is limited to three pages or 1,500 words. The risk assessment is completed using the supplied template. Students are also required to provide evidence and commentary concerning the development and tailoring of the policy when using an approved AI tool, together with a self-written evaluation addressing strengths, weaknesses, privacy, GDPR and ethical considerations. The assessment is marked across context establishment, asset-based risk assessment, the information security within supplier agreements policy, and presentation, design and references. At least 20 authentic references, including standards and papers accessed through the University library, are required.
Read Model Answer →
Security of Emerging Connected Systems
1,500 words
CW1: Policy and Legal Aspects Report – IoT System
This 1,500-word report for the Security of Emerging Connected Systems module examines the legal and security implications of a proposed Internet of Things (IoT) system designed for consumers to monitor food intake and bodyweight. The coursework requires students to provide an initial investigation of the potential legal pitfalls associated with the proposed product and identify appropriate solutions or mitigation measures. The report is worth 5 credits and is assessed as an individual written report. The proposed IoT system consists of several connected components. A smartphone application allows users to scan barcodes of processed food to record calorie and nutritional information against their health record. A kitchen scale communicates with the phone application to record the weight of ingredients used in home-cooked meals. A bathroom scale records the user's weight and provides light and sound reminders to encourage regular measurements. A UK-based server stores the collected information and generates individual user reports. The main purpose of the report is to ensure that the company understands the UK and international laws that may apply to the proposed system. Students must identify potential legal issues and recommend appropriate mitigation through technology, organisational policy, licensing arrangements or user agreements. The system definition is deliberately broad, so students should not make unsupported assumptions about its design. Where several options have different legal implications, the report should compare the relevant alternatives and explain their implications rather than presenting only one solution. The initial product is intended for UK residents, while the company is considering future expansion into the United States. Consequently, the report should focus primarily on UK law but also include a short section discussing legal aspects that may need to be reconsidered when entering the US market. The report is intended for company executives and may subsequently be provided to the R&D department. Therefore, high-level outcomes should be communicated early, while useful links to technical information such as encryption schemes, protocols and frameworks may be provided without extensive technical explanations in the main report. The assessment places 50% of the marks on understanding and coverage of UK and US law, 40% on technical recommendations and 10% on report presentation. Strong submissions are expected to provide comprehensive coverage of relevant legislation, connect legal issues with the wider security context, analyse technical recommendations for both regions, identify differences between UK and US requirements and support arguments with appropriate citations and a wide range of sources. The assignment learning outcomes focus on critically evaluating the role of security policy in protecting information assets and proposing appropriate policies for internet-based technologies. They also require students to demonstrate an understanding of key legislation relating to information security and how legislation influences organisational security policy. The final report should therefore combine legal analysis with practical security recommendations, addressing the proposed IoT system from both UK and US perspectives while remaining suitable for both technical staff and non-technical management.
Read Model Answer →
Network Security
1,500 words
The Case Study – Network Security Planning and Upgrade
This individual assessment for the Network Security module requires students to work as network consultants and carry out network and security planning and an upgrade for an imaginary company. The assignment is titled “The Case study” and requires students to produce a written report presenting solutions to the problems identified within the case study. The assessment is worth 15 credits and requires approximately 1,500 words, with a permitted variation of ±10%. The coursework focuses on applying network security concepts and protocols to contemporary Internet and mobile-based solutions and technologies. Students are expected to analyse the requirements of the imaginary organisation, identify relevant network and security issues and propose appropriate planning and upgrade solutions. The report should demonstrate an understanding of network security technologies while considering the organisation's information assets and operational requirements. A significant part of the assessment concerns network performance. Students must provide recommendations and suggestions for addressing network performance issues identified in the case study. Where the proposed solution changes the existing network design, an appropriate network diagram should be included. The brief allows students to use tools such as Packet Tracer or other suitable applications to represent the proposed network design. The assignment also requires students to consider security policy and network protection. The existing security policy should be reviewed and recommendations should be made for improving it. Students are specifically instructed not to create a completely new security policy because the organisation already has one. In addition, the report should discuss how appropriate security measures could be implemented across the network. Detailed device configurations are not required, although relevant examples or configuration snippets are encouraged. Because the information provided in the case study is incomplete, students must identify and document their assumptions and requirements. This includes defining unspecified parameters such as network speeds, device features and existing policy details. The assumptions and requirements section is therefore an important part of the investigation and contributes to the assessment mark. The final report should summarise the key findings of the investigation and may recommend how any remaining IT support budget could be used. References must be included and used effectively to support the discussion. The marking criteria allocate 10% to the introduction, 10% to assumptions and requirements, 20% to improving performance, 20% to policy amendments, 20% to securing the network, 10% to the conclusion/summary and 10% to references. The assessed learning outcomes cover the application of network security concepts and protocols, critical evaluation and design of security policies, understanding of IT governance and its influence on organisational security policy, and critical review of current research and technological advances in network security. The brief also permits AI assistance, but any AI tools used must be referenced and their use summarised at the end of the report before the reference list.
Read Model Answer →
Network Security and Incident Report
1,500 words
Network Security and Incident Report – Megadodo Publications
This 1,500-word individual coursework for the Network Security and Incident Report module examines the network infrastructure and security challenges of Megadodo Publications, a company located near Warwick that has expanded into two buildings, Ursa Major Alpha and Ursa Minor Beta. Despite investment in new networking equipment, the organisation is experiencing poor network performance and repeated security incidents involving the leakage of sensitive information into the public domain. The situation is particularly urgent because the company is negotiating an important government contract. The student is placed in the role of a network security professional asked to investigate the existing environment and provide recommendations for improving its infrastructure and security. The case study provides a network topology, addressing scheme, equipment information and an existing security policy. The network connects departments across the two buildings and includes servers, management systems, sales, marketing, legal, finance, software development, product testing, administration, IT support, Wi-Fi and a rented floor occupied by a separate start-up company. The addressing scheme identifies separate subnets for several organisational functions, while the topology includes multiple switches, routers, servers and wireless access points. The report requires students to make reasonable assumptions where information is incomplete and document those assumptions at the beginning of the report. The first substantive task evaluates how the organisation's network performance could be improved. Recommendations should address the existing infrastructure and, where the design is changed, include an appropriate network diagram using tools such as Packet Tracer or other suitable applications. The second major area addresses amendments to the existing security policy. Students should recommend improvements to the current policy rather than create a completely new policy. The report must also discuss how appropriate security measures could be implemented across the network and its devices. Detailed device configurations are not required, although relevant examples or configuration snippets are encouraged. The final section requires a summary of the key findings and recommendations, together with a proposal for how the organisation could use its remaining IT support budget of approximately £8,000 and identify areas for future investment. The assessment is divided into introduction, assumptions and requirements, improving performance, policy amendments, security and devices, summary and budget, and references. The marking scheme allocates 50% of the module mark to this coursework, with the individual report submitted as a single DOC, DOCX or PDF document.
Read Model Answer →
Cloud Computing / Big Data Technologies / Cyber Security
2,500 words
Cloud and Big Data Security Application: Design, Implementation and Evaluation
This assessment for the Cloud and Big Data Technologies module requires students to design, implement and evaluate an individual cloud-based or distributed data application. The project focuses on practical solutions involving the complex transformation, processing, storage and security of big data within cloud environments. Students are expected to demonstrate how distributed data can be organised in the cloud, how data pipelines can be used to access or process distributed databases, and how appropriate security controls can be incorporated into the resulting architecture. Students have considerable freedom when selecting their application. Suggested project directions include developing a data-science solution using SQL or MongoDB with cloud storage and an appropriate security policy; implementing privacy-preserving distributed processing using techniques such as Differential Privacy; creating multi-party authentication and group-based access-control mechanisms; or designing Multi-Level Security, Attribute-Based Encryption or Role-Based Access Control solutions. Projects may also examine distributed or cloud applications using security protocols such as SSH, SSL or IPsec. Creativity and originality are explicitly encouraged. The written component is a Design and Implementation Document of no more than approximately 2,500 words. It should present the project aims and objectives, application concept, cloud and security technologies, functional and security requirements, architecture and design decisions, protocols, access-control mechanisms, implementation process, achievements, problems encountered and overall evaluation. Relevant diagrams, such as interaction or sequence diagrams, may be used to explain system behaviour and architecture. The assessment also requires submission of the functioning Cloud and Big Data Security application and a 7-minute highlight demonstration video. The video should demonstrate the application's major features, implementation details, security functionality and, where appropriate, attack scenarios. Assessment places strong emphasis on the quality of the design and implementation documentation, originality, use of advanced features, and the overall effort and technical quality of the completed application. Students are therefore expected to demonstrate independent development rather than simply reproduce an existing tutorial.
Read Model Answer →