Assignment title: Information
BIT309: Security Management
Assignment (40%)
Total: 40 Marks
Due Date: Week 8, Week 12.
Assignment Overview
Research you're a company Security Management policies and procedures. Write a report analysing the security management strategies employed, investigate the company with background research and questionnaires, conduct a risk assessment (including a risk matrix) and Human Resource polices. Evaluate the security management implemented. Provide all references (PDFs, links, etc) include evidence of attempts to contact the company.
Your final report must include the following:
• Assignment Cover Page: (Use the cover sheet provided. Include the Title,
• Assignment number, Student Names and IDs, Subject)
• Title page (Name of report who it is prepared for, and authors)
• Executive summary (1 paragraph)
• Table of contents
• Body (Numerous headings and text at the write choice)
• References/ Bibliography
Submission:
Week 2: Chosen Company (No two students do the same topic)
Week 2-4: Send emails to Company/Interview Company
Week 5: Progress Report (MOODLE) (Background checks)- 0%.
Week 8: Draft Report (MOODLE) – 10%
Week 12: Final Report (TurnItIn) – 30%
See MOODLE for the exact dates and times.
Plagiarism
All used sources must be properly acknowledged with references and citations, if you did not create it. Quotations and paraphrasing are allowed but the sources must be acknowledged. Failure to do so is regarded as plagiarism and the minimum penalty for plagiarism is failure for the assignment. The act of given your assignment to another student is classified as a plagiarism offence. Copying large chucks and supplying a reference will result in zero marks as you have not contributed to the report. Copying from Youtube or other videos is also plagiarism (including transcripts). Citation in a video can be included as credits at the end.
Due Date & Submission
By the due date, you must submit:
1. Name your file with your student number and name.
2. Upload Report to TurnITIn and References to MOODLE.
To upload on TurnItIn, go to http://turnitin.com/
Late submission of assignments will be penalised as follows:
• For assignments 1 to 5 days late, a penalty of 10% (of total available marks) per day.
• For assignments more than 5 days late, a penalty of 100% will apply.
Your submission must be compatible with the software (PDF/Word/Video) in Melbourne Polytechnic, Computer Laboratories/Classrooms.
Extensions: Under normal circumstances extensions will not be granted. In case of extenuating circumstances—such as illness—a Special Consideration form, accompanied by supporting documentation, must be received before 3 working days from the due date. If granted, an extension will be only granted only by the time period stated on the documentation; that is, if the illness medical certificate was for one day, an extension will be granted for one day only. Accordingly the student must submit within that time limit.
Penalties may apply for late submission without an approved extension.
Penalties: Academic misconduct such as cheating and plagiarism incur penalties ranging from a zero result to program exclusion.
Questionnaire Example:
Dear Sir/Madam,
I am a student at Melbourne Polytechnic and I am Security Management. My assignment is to research a company security management of a company. Please complete the following survey.
Thank you for your time.
Regards,
Questions:
1. Which country is your data stored? __________________________________
(Delete: This indicates which laws the data provider needs to obey)
2. Which country is the business registered? ____________________________
(Delete: This indicates which laws the business obeys by)
3. Does the company uses cloud services? ______________________________
If yes, please specify (AWS, GoogleApp, etc and the costs) ______________________________
_______________________________________________________________________________
4. Does the company uses a supercomputer? Yes/No
5. Does the company enforce any of the following Human Resources practices?
a. Job Rotation Yes/No
b. Background Checks Yes/No
c. Mandaotry Vacancy Yes/No
d. Separation of Duties Yes/No
6. Does the company uses any specialize software? Yes/No
If yes, please specify the software detail (software name(s)).
_________________________________________________________________________
7. Does the company uses any specialize hardware? Yes/No.
If yes, please specify the software detail (software name(s)).
_________________________________________________________________________
(Delete: You are required to add at least three more questions.)
Research the Company
You should be able to find the following details:
- ABN
- Small/Medium/Enterprise Business (indicates the number of employees)
- Company Structure
- Mission Statement/Value Statement/Vision Statement
From the details you should be able to estimate the following:
Assess (Typical)
- Microsoft Office x volume license => deduce costs
- PCs x number of employees => deduce costs
- Premises => deduce rent/cost
- Servers/Routers
- Others (You should add 3-5 of your own)
Perform a Risk Assessment of all assess, include threats identification, vulnerability appraisal, the risk of likelihood (MTBF), Single Expectancy, Calculate Annual Loss Expectancy, etc.
Make your own recommendations on how to mitigate the risks.
Marking criteria:
Marks are allocated as indicated on each question, taking the following aspects into account:
Aspects Description
Analysis (if appropriate) Investigation, comparison, discussion
Explanation/justification Description/answer to the question
Presentation Inadequate structure, careless presentation, poor writing
Reference style Proper referencing if required
Plagiarism Copy from another student, copy from internet source/textbook, copy from other sources without proper acknowledgement
Marking Rubric for Exercise Answers
Grade
Mark HD
80%+ D
70%-79% CR
60%-69% P
50%-59% Fail
< 50%
Excellent Very Good Good Satisfactory Unsatisfactory
Analysis
Logic is clear and easy to follow with strong arguments Consistency logical and convincing Mostly consistent and convincing Adequate cohesion and conviction Argument is confused and disjointed
Effort/Difficulties/
Challenges The presented solution demonstrated an extreme degree of difficulty that would require an expert to implement. The presented solution demonstrated a high degree of difficulty that would be an advance professional to implement. The presented solution demonstrated an average degree of difficulty that would be an average professional to implement. The presented solution demonstrated a low degree of difficulty that would be easy to implement. The presented solution demonstrated a poor degree of difficulty that would be too easy to implement.
Explanation/
justification All elements are present and well integrated. Components present with good cohesion Components present and mostly well integrated Most components present Lacks structure.
Reference style Clear styles with excellent source of references. Clear referencing/ style Generally good referencing/style Unclear referencing/style Lacks consistency with many errors
Presentation Proper writing. Professionally presented Properly spoken, with some minor deficiencies Mostly good, but some structure or presentation problems Acceptable presentation Poor structure, careless presentation
Assignments Topics:
Students Topic
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-