Information Assurance and Risk Management White Paper Assessment
Assessment Overview
Assessment Overview
For this module, summative assessment will be via this single in-course assignment; to support evidencing achievement of the learning outcomes for the module, a written critical analysis report form the basis of the module assessment.
The assignment ‘Information Assurance and Risk Management White Paper’ is worth 100% of the total mark. It is an individual assessment and should therefore be all your own work. Students should not collude or plagiarise work. Appropriate action will be taken, according to Northumbria University regulations, if collusion or plagiarism is suspected. Please see the section on academic integrity for clarification.
Module Learning Outcomes
The assignment ‘Information Assurance and Risk Management White Paper’ covers Learning Outcomes 1-5 in full. On completion of the module, you should be able to achieve the following.
1.Identify and evaluate the principles and concepts of information assurance and risk management.
2.Critically discuss information assurance from a combined, managerial, organisational and technical perspective.
3.Critically discuss the scope for risk management in an organisational context.
4.Undertake a detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
5.Identify and evaluate fundamental research issues in information assurance and risk management.
Tasks and Criteria
The assessment task requires you to engage with a scenario which sees you commissioned by ‘Cerious Cybernetics Corp.’ a private cybernetics research and development company to identify fit- for-purpose, robust and comprehensive information assurance and risk management policies, procedures and practices which will ensure successful information assurance for their business via cutting edge and relevant risk assessment, treatment and management both in the current climate and also, for future provision.
Cerious Cybernetics Corp. has its headquarters in London, England, employing a total of 60 full time staff and at any given time upwards of 20 agency staff. The headquarters is the location for the core business functions such as Human Resources, Finance, IT, data governance, legal resources and service level agreements (including those for customers and with the agencies supplying staff). Cerious Cybernetics Corp. currently has a number of ongoing research and development contracts, including the UK Ministry of Defence and the United States Department of Defence.
Help and resources
Please note, there are various types of white paper but what is required here is a standard white paper not a technical white paper. If you’re unsure what a white paper is, guidance will be provided in class but you should also see the following (note; please focus on guidance relating to presenting solutions rather than marketing a specific product of service which can often be the purpose of white papers):
Module Learning Outcomes
White Paper Structure
Although the structure can be more comprehensive, for the purposes of this assessment, your white paper should contain as a minimum the following:
- The nature of the brief/commission and the topic should be briefly outlined and defined alongside details of how the paper is organised.
- Main body.
- This section will contain the main body of the white paper. The presentation of topic and the proposals/solutions established from your research and analysis should provide the structure of the main body; sub headings should be used so it is clear to the reader what each section covers. A logical flow and structure appropriate for a white paper should be evident throughout.
- This section will also include the sample Service Improvement Plan (SIP) pertaining to the scenario given.
- Summary/conclusions.
- A brief summary of the key findings established from your research and analysis in the main body should be provided along with any final recommendations.
- Carefully consider what you include in the appendices (if you choose to include them); ensure the contents are relevant and presented as concisely as possible.
Assessment Criteria
It is expected that you will use quality sources to justify and support points being made in addition to evidencing wider reading and understanding. There are marks available specifically for this (see below). The criteria for assessing the quality of the report will focus on:
- Relevance, appropriateness, accuracy, completeness and cohesive presentation of the topic and proposals/solutions: the white paper (including the sample SIP) should present up-to-date and current information which is directly appropriate and relevant to the Cerious Cybernetics Corp. commission/brief described above. All information contained within the paper should be accurate and unambiguous. The scope and proposals/solutions should be entirely relevant to the request (both overall and for the SIP) and shouldn’t contain elements which are either unrelated or only loosely related. Exploration of the area concerned and proposals/solutions are cohesive and the subtopics presented have a logical flow.
- Evidence of information assurance, risk management and professional understanding: the white paper (including the sample SIP) should cover information assurance, risk management and professional factors relevant to the commission/brief. Information assurance, risk management and professional factors have been fully understood, with no evidence of confusion or lack of important detail/depth.
- Use of high-quality information sources: extensive use should be made of information sources which are not-outdated, are reputable and established as being reliable, valid and accurate.
- Effective communication: the paper should be well written, easily understood with good flow and clarity. The content should be explained in a way that can be easily understood by the reader given Cerious Cybernetics Corp. Executives may have limited subject knowledge or professional understanding.
- Report writing style: the paper should be professionally presented with all expected components/formatting specified below and expected from a white paper. It should make good use of English language with an appropriate writing style and formal, professional tone. It should be error free with no grammatical, spelling mistakes or typo mistakes.
Please adhere to the following requirements:
- Submission will be via Turnitin on Blackboard; please see the front cover for the submission date. Please note, you can submit your report formatively to check for originality i.e. to help check for potential academic misconduct in the form of plagiarism. You can do this multiple times. However, you must ensure the last attempt is your final summatively assessed paper and is correctly submitted ahead of the deadline indicated on the cover page.
- The white paper should be written in a formal reporting style and without use of personal pronouns (for example, no use of ‘I, me, my, our, we, they, he, she’). If you find it difficult, you may want to research the use of the passive voice; help is also available via skills resources online (see above).
- The white paper should not exceed 20 pages in length and should be 3800-4200 words excluding title page, table of contents, references and appendices (if used). Any content in the main body of the report which exceeds the upper word limit will be disregarded.
- Only Microsoft Word or PDF file formats will be accepted.
- Layout should make reasonable use of margins, clear headings, single line spacing and font size should be 11pt (i.e. your report should be professionally presented; do not use the page limit as a reason for trying to fit as much as possible on each page).
Marking Scheme
Late Submission Policy:
Excellent work providing evidence to a very high level of the knowledge, understanding and skills appropriate to level 7. The following learning outcomes have been met, many at high level:
- Identification and evaluation of the principles and concepts of information assurance and risk management.
- Critical discussion of information assurance from a combined, managerial, organisational and technical perspective.
- Critical discussion of the scope for risk management in an organisational context.
- Detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
- Identification and evaluation of fundamental research issues in information assurance and risk management.
Marks at the high end of this range indicate outstanding work where all learning outcomes are met at a high level. Excellent in all or most of: use of primary sources of literature from a range of perspectives; development of analysis and structure of argument; critical evaluation and creative use of theory, research methods and findings; presentation of information to the intended audience.
Commendable work providing evidence to a high level of the knowledge, understanding and skills appropriate to level 7. The following learning outcomes have been met, many are more than satisfied:
- Identification and evaluation of the principles and concepts of information assurance and risk management.
- Critical discussion of information assurance from a combined, managerial, organisational and technical perspective.
- Critical discussion of the scope for risk management in an organisational context.
- Detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
- Identification and evaluation of fundamental research issues in information assurance and risk management.
Good in all or most of: use of up-to-date material from a variety of sources; development of analysis and structure of argument; critical evaluation of relevant theory, research methods and findings to the problem in question; presentation of information to the intended audience.
Satisfactory work providing evidence of the knowledge, understanding and skills appropriate to level 7.
- Identification and evaluation of the principles and concepts of information assurance and risk management.
- Critical discussion of information assurance from a combined, managerial, organisational and technical perspective.
- Critical discussion of the scope for risk management in an organisational context.
- Detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
- Identification and evaluation of fundamental research issues in information assurance and risk management.
Satisfactory in all or most of: use of relevant material from a variety of sources; development of analysis and structure of argument; evaluation of theory; application of relevant theory, research methods and findings to the problem in question; presentation of information to the intended audience.
Adequate work providing evidence of the knowledge, understanding and skills appropriate to level 7 but only at a bare pass level. All of the following learning outcomes are met (or nearly met and balanced by strengths elsewhere):
- Identification and evaluation of the principles and concepts of information assurance and risk management.
- Critical discussion of information assurance from a combined, managerial, organisational and technical perspective.
- Critical discussion of the scope for risk management in an organisational context.
- Detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
- Identification and evaluation of fundamental research issues in information assurance and risk management.
Adequate in all of (or most of, with balancing strength elsewhere): use of relevant material; development of analysis and structure of argument; evaluation of theory; application of relevant theory, research methods and findings to the problem in question; presentation of information to the intended audience.
Work is not acceptable in providing evidence of the knowledge, understanding and skills appropriate to level 7. However the majority of the following learning outcomes are met and others are nearly satisfied:
- Identification and evaluation of the principles and concepts of information assurance and risk management.
- Critical discussion of information assurance from a combined, managerial, organisational and technical perspective.
- Critical discussion of the scope for risk management in an organisational context.
- Detailed analysis of relevant information assurance and risk management issues from a theoretical and practice perspective.
- Identification and evaluation of fundamental research issues in information assurance and risk management. Adequate in most but not all of the following aspects : use of relevant material; development of analysis and structure of argument; evaluation of theory; application of relevant theory, research methods and findings to the problem in question; presentation of information to the intended audience.