INF20031: Cybersecurity for Business Report Assessment

Download Solution Order New Solution

Assessment

You are a Melbourne based Information Systems Security Auditor who has been assigned to Zenith logistics to carry out a Cybersecurity status report for the company. Your task is to produce a 2800-word (max.) auditors report (in business report format) identifying and assessing information security risks and proposing a preliminary mitigation strategy. Your report should address the following specified components:

Undertake an information security risk assessment and produce the status report. To do so, you must:

1. Briefly explain your approach to Information Security risk management and information risk assessment to Zenith Logistics so that they understand the work you are doing, i.e., in an approximately 150- 200-word introduction let your clients know what your Cybersecurity status report is and how you will approach the task.

2. Clearly and concisely assess and describe, Zenith Logistics’s strategic environment, their value creating activities and their current risk posture; and prepare a Cybersecurity mission statement (of no more than 250 words, that may also include a supporting diagram) for Zenith that includes an appropriate expression of their high-level target risk appetite and risk tolerance parameters.

3. Identify and table the key roles and responsibilities of individuals and business functions at Zenith describing who is responsible for overseeing specific functions and information assets and assess any associated information risks in terms of responsibilities and gaps in responsibility,

4. Carefully audit the case study to identify and prepare a full inventory (descriptive list) of all information assets, including Zenith Logistics’ most significant, physical &/or logical information resources, the information of most value, and the information systems/process required to work with information at the logistics company. Include your full list as an appendix item.

5. Include an ATV table in your report identify risks (threats and vulnerabilities) for the top 7 operationally critical information assets that you have identified. Provide a supporting explanation for your analysis of the threats and vulnerabilities for Zenith Logistics’ most important information assets (both information and information systems and processes),

6. Present a likelihood and impact analysis for your seven (7) most significant information (assets) that you have identified above, alongside of your tables, consider using diagram and graphical representations such as matrices, and in doing so,

7. Evaluate and prioritise the most significant associated information risks for Zenith Logistics to manage. Ensure you justify your assessed order of priority in your risk assessment tables and prepare a mitigation plan, incorporating (1) a named mitigation strategy and recommended internal controls for all 7 identified concerns.

Brief Summary of the Assessment Requirements

You must produce a 2800-word (max.) auditor’s business report for Zenith Logistics that assesses information security risks and proposes a preliminary mitigation strategy. The report must be practical, evidence-based and client-facing. Key requirements to cover:

  • A 150–200 word introduction explaining the auditor’s approach to information-risk management and how the status report will be produced.
  • A concise assessment of Zenith’s strategic environment, value-creating activities and current risk posture, plus a Cybersecurity mission statement (≤250 words) that states high-level risk appetite and risk tolerance (diagram optional).
  • A roles & responsibilities table mapping people/functions to security oversight responsibilities and identifying gaps.
  • A full inventory (appendix) of information assets (physical & logical), the highest-value information, and supporting systems/processes.
  • An ATV table (Asset: Threat: Vulnerability) for the top 7 operationally critical information assets, with supporting analysis of threats and vulnerabilities.
  • A likelihood × impact analysis for those seven assets (matrices/diagrams recommended).
  • A risk prioritisation (with justification) and a mitigation plan: for each of the 7 items name a mitigation strategy and recommend internal controls.

Deliver the report in a clear business-report format (headings, tables, diagrams, appendix) and ensure each judgement is justified.

How the Academic Mentor guided the student: step-by-step

Below is the stepwise mentoring approach the academic mentor used to guide the student through producing a high-quality submission.

Step 1: Clarify scope, constraints and format (before writing)

  • What the mentor did: Explained the 2800-word cap, business-report conventions (executive tone, headings, tables, appendix) and assessment marking priorities (clarity of risk reasoning, quality of evidence, feasibility of controls).
  • Student action: Agreed a project plan and word allocation per section.

Step 2: Draft the 150–200 word introduction

  • Mentor guidance: Keep it client-facing and concrete: say what the report will do, why a risk assessment is needed, and how the analysis will be conducted (inventory → ATV → L×I → prioritisation → mitigation).
  • Outcome: A compact introduction that sets expectations and links to the methodology used.

Step 3: Assess strategic environment, value activities and current risk posture

  • Mentor guidance: Map Zenith’s business model (logistics nodes, partners, customer data flows) and identify where information value is created (scheduling, tracking, customer PII, financial systems). Use a one-page SWOT/risk-map to show exposure.
  • Student action: Produce a short summary of strategy, list critical business processes, and assess maturity level (e.g., ad-hoc, defined, managed).
  • Deliverable: Text plus a one-paragraph strategic assessment and a draft Cybersecurity mission statement (≤250 words) that includes target risk appetite/tolerance language (e.g., “Zenith maintains a low tolerance for data confidentiality breaches affecting customers; moderate tolerance for short operational interruptions”).

Step 4: Roles & responsibilities table

  • Mentor guidance: Use RACI-style clarity who is Responsible, Accountable, Consulted, Informed for key security functions (CIO/IT Manager, Operations Manager, HR, Third-party vendors). Ask the student to identify gaps (e.g., no named incident owner).
  • Outcome: A table that links assets/functions to owners and lists gaps as identified risks.

Step 5: Build the full asset inventory (appendix)

  • Mentor guidance: Instruct student to compile an exhaustive list (servers, cloud services, databases, mobile devices, telematics, paper records). Mark each asset with owner, location, business value, and confidentiality/integrity/availability classification. Put the long list in the appendix to preserve word count.
  • Student action: Gather asset details from the case study and present the top 7 assets in the main body.

Step 6: Prepare ATV tables for the top 7 assets

  • Mentor guidance: For each critical asset write: Asset → plausible Threats → existing Vulnerabilities → short rationale (2–3 sentences). Ensure threats are realistic for logistics (ransomware, insider misuse, supply-chain compromise, physical theft).
  • Outcome: Clear ATV tables that feed into likelihood and impact assessment.

Step 7: Likelihood × Impact analysis and prioritisation

  • Mentor guidance: Use a 3×3 or 5×5 matrix. Define likelihood and impact scales explicitly (e.g., likelihood: rare–possible–likely; impact: minor–major–catastrophic). Require justification for each asset’s cell don’t just label colors.
  • Student action: Populate matrices and rank risks by residual concern if current controls remain, or by inherent risk if controls are ineffective. Provide rationale for ordering.

Step 8: Mitigation plan and recommended controls

  • Mentor guidance: For each top risk, propose a named mitigation strategy (e.g., “Implement network segmentation”, “Deploy endpoint detection and response”, “Strengthen vendor access governance”). For each strategy give 2-4 recommended internal controls, responsible role, and a short note on cost/feasibility and expected risk reduction. Emphasise layered controls (technical + process + people).
  • Outcome: A concise mitigation table tied directly to the prioritised risks.

Step 9: Final polish, diagrams and appendix

  • Mentor guidance: Add visuals (mission-statement diagram, ATV summary, L×I matrix), ensure appendices include full asset inventory and any assumptions. Tighten language to meet the word limit and check that every claim has supporting logic.
  • Student action: Final editing, word-count trim, and produce the business report.

Final outcome & learning objectives achieved

Final outcome: A client-ready, 2800-word business report that: introduces the audit approach; maps Zenith’s strategic context and risk posture; defines mission, appetite and tolerance; documents roles & responsibilities; provides an appendix inventory; contains ATV tables and L×I matrices for the top 7 assets; ranks risks with justifications; and proposes named mitigation strategies and internal controls for each prioritized risk.

Learning objectives covered:

  • Apply information-risk management concepts to a real organisational context.
  • Translate business strategy into an information-security posture and mission.
  • Create a complete asset inventory and identify high-value information resources.
  • Perform ATV analysis and likelihood×impact assessment with clear, justified prioritisation.
  • Design practical mitigation strategies and map controls to responsibilities.
  • Communicate technical findings in a concise, business-report format suitable for stakeholders.

Boost Your Grades the Smart Way Use Reference Samples and Get Custom Help

Need clarity on how to structure and present your assignment? Our sample solutions are designed to give you a strong understanding of academic formatting, research depth, and the expected writing style for high-scoring submissions.
However, please note that these samples are strictly for reference and learning purposes only. Submitting them as your own work may result in plagiarism issues with your university. Use the sample to learn, not to submit.

If you want a fully original, customised, plagiarism-free assignment written specifically for your topic and requirements, our expert academic writers are here to help. Every fresh assignment is crafted from scratch, well-researched, properly referenced, and tailored to your guidelines for maximum scoring potential.

Why Order a Fresh, Custom-Written Assignment?

  • 100% original and plagiarism-free content
  • Tailored to your instructions, topic, and marking rubric
  • Written by qualified academic specialists
  • Proper citations and referencing in your required style
  • High-quality writing delivered on time

Learn confidently and submit with assurance by choosing professional academic support that meets your academic goals.

Download Sample Solution         Order Fresh Assignment

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.