Project assessment: Cyber security service proposal
Unit code, name and release number
VU21990 Recognise the need for cyber security in an organisation
Qualification/Course code, name and release number
901-00011V01 State of Attainment in Digital Security Basics
Specific task instructions
You are required to write a cyber security service proposal based on this scenario.
Part 1: Service proposal report
Using the DataTrust report template, write a cyber security service proposal based on the scenario (less than 50 words).
Your report must address the following headings and content:
1. Introduction
Outline the concept of information security and why it’s important to care about it, by addressing the following:
1. Definition: Write a definition of information security.
2. Protecting identity and data: Explain the importance of protecting your personal online identity and data.
3. Protecting organisational data: Explain the importance of protecting the organisation's data.
4. Cyber security professionals: Explain why cyber security professionals are necessary.
2. Threats
Explain what cyber threats are and list potential threat sources, as follows:
1. Cyber threats: Define the concept of cyber threat.
2. Organisational threats: List and describe at least three potential threat sources for an organisation.
3. Risks
Explain the concept of risk, as follows:
1. Relationships, risks, and strategies: Identify and discuss:
o the relationship between data, networks, users and applications within an organisation.
o meaning of risk and risk mitigation
2. Physical security: Describe the security of physical infrastructure, such as computers in an office building or at your workplace if any: (if you can’t get information about any office building or workplace then consider general physical security)
o the threats and risks to these resources
o the mitigation strategies that could be implemented

3. Identity and access management: Describe:
o identity and access management (IAM) systems
o how these systems work, for example, lock and key analogy
o why it's important to have these in place

Part 2: Assessment checklist
The following checklist will be used by an assessor to mark your performance against the assessment criteria of your submitted project. Use this checklist to understand what skills and/or knowledge you need to demonstrate in your submission. All the criteria described in the Assessment Checklist must be met. The assessor may ask questions if appropriate directly after the task/activity has been submitted/completed.
TASK/STEP # Instructions S U/S Assessor Comments
Part 1.1 Report is submitted as a typed document in the supplied DataTrust report template.
Writes a definition of information security.
Gives appropriate reasons to protect personal online identity and data.
Gives appropriate reasons to protect an organisation’s data.
Gives appropriate reasons for the need of cyber security professionals.
Part 1.2 Writes a definition of the concept of cyber threat.
Describes three potential threat sources for an organisation.
Part 1.3 Describes the risks and relationship between data, networks, users and applications within an organisation.
Identifies and evaluates the security of an organisation’s physical infrastructure.
Writes an overview of identity and access management (IAM) systems, including their importance and how they work.

