Corporate Profile: Part 2
|
|
|
|
|
|
|
|
|
Criteria |
Excellent |
Outstanding |
Acceptable |
Needs Improvement |
Needs Significant Improvement |
Missing or Unacceptable |
|
Executive Summary: Introduction to the Company |
20 points Provided an excellent introduction which identified the company being profiled and included a brief overview of the company (may reuse narrative from Part 1 of this assignment). Appropriately used information from 3 or more authoritative sources. |
18 points Provided an outstanding introduction which identified the company being profiled and included a brief overview of the company (may reuse narrative from Part 1 of this assignment). Appropriately used information from 2 or more authoritative sources. |
16 points Provided an introduction which identified the company being profiled and included a brief overview of the company (may reuse narrative from Part 1 of this assignment). Appropriately used information from authoritative sources. |
14 points Provided an introduction to the company but the section lacked some required details. Information from authoritative sources was cited and used in the overview. |
9 points Attempted to provide an introduction to the company but this section lacked detail and/or was not well supported by information drawn from authoritative sources. |
0 points The introduction section was missing or did not clearly identify the company. |
|
Executive Summary: Sources of Cybersecurity Risk |
20 points Provided an excellent summary of the sources, potential impacts, and planned mitigation approach/strategy for cyberspace and/or cybersecurity related risks as identified in the Risk Section of the company’s annual report. |
18 points Provided an outstanding summary of the sources, potential impacts, and planned mitigation approach/strategy for cyberspace and/or cybersecurity related risks as identified in the Risk Section of the company’s annual report. Appropriately used and cited information from 3 or more authoritative sources. |
16 points Provided a summary of the sources, potential impacts, and planned mitigation approach/strategy for cyberspace and/or cybersecurity related risks as identified in the Risk Section of the company’s annual report. Appropriately used and cited information from 2 or more authoritative sources. |
14 points Provided a summary of the sources, potential impacts, and planned mitigation approach/strategy for cyberspace and/or cybersecurity related risks as identified in the Risk Section of the company’s annual report. Appropriately used and cited information from authoritative sources. |
9 points Provided a discussion of the cybersecurity risks that the company faces. The discussion lacked detail and/or was not well supported by information drawn from authoritative sources. |
0 points Risk discussion was missing or off topic. |
|
Table: Risk Register |
15 points Provided a complete, concise, and thorough Risk Register (columns 1 and 2 of table) for 10 or more cyberspace or cybersecurity related risks as identified in the company's annual report. (Risk ID was numeric sequence # or short title suitable for cross-referencing.) |
14 points Provided a complete, concise, and thorough Risk Register (columns 1 and 2 of table) for 8 or more cyberspace or cybersecurity related risks as identified in the company's annual report. (Risk ID was numeric sequence # or short title suitable for cross-referencing.) |
13 points Provided a completed Risk Register (columns 1 and 2 of table) for 5 or more cyberspace or cybersecurity related risks as identified in the company's annual report. (Risk ID was numeric sequence # or short title suitable for cross-referencing.) |
11 points Provided a completed Risk Register (columns 1 and 2 of table) for at least three cyberspace or cybersecurity related risks which the company faces. |
9 points Attempted to complete the Risk Register (columns 1 and 2 of table) for 3 or more entries but information about the risks was lacking details. |
0 points Did not complete 3 or more entries in the Risk Register. |
|
Table: Risk Mitigation Approach |
15 points Provided a complete, concise, and thorough Risk Mitigation Approach with Recommendation Security Controls by family (column 3 of table) for 10 or more cyberspace or cybersecurity related risks as identified in the company's annual report. |
14 points Provided a complete, concise, and thoroughRisk Mitigation Approach with Recommendation Security Controls by family (column 3 of table) for 8 or more cyberspace or cybersecurity related risks as identified in the company's annual report. |
13 points Provided a completed Risk Mitigation Approach with Recommendation Security Controls by family (column 3 of table) for 5 or more cyberspace or cybersecurity related risks as identified in the company's annual report. |
11 points Provided a completed Risk Mitigation Approach with Recommendation Security Controls by family (column 3 of table) for at least three cyberspace or cybersecurity related risks which the company faces. |
9 points Attempted to complete the Risk Mitigation Approach with Recommendation Security Controls by family (column 3 of table) for 3 or more entries but information about risk mitigation was lacking details. |
0 points Did not complete 3 or more entries in the Risk Mitigation Approach column of the table. |
|
Addressed security issues using standard cybersecurity terminology |
5 points Demonstrated excellence in the integration of standard cybersecurity terminology into the case study. |
4 points Provided an outstanding integration of standard cybersecurity terminology into the case study. |
3 points Integrated standard cybersecurity terminology into the into the case study |
2 points Used standard cybersecurity terminology but this usage was not well integrated with the discussion. |
1 point Misused standard cybersecurity terminology. |
0 points Did not integrate standard cybersecurity terminology into the discussion. |
|
APA Formatting for Citations and Reference List |
5 points Work contains a reference list containing entries for all cited resources. Reference list entries and in-text citations are correctly formatted using the appropriate APA style for each type of resource. |
4 points Work contains a reference list containing entries for all cited resources. One or two minor errors in APA format for in-text citations and/or reference list entries. |
3 points Work contains a reference list containing entries for all cited resources. No more than 3 minor errors in APA format for in-text citations and/or reference list entries. |
2 points Work has no more than three paragraphs with omissions of citations crediting sources for facts and information. Work contains a reference list containing entries for cited resources. Work contains no more than 5 minor errors in APA format for in-text citations and/or reference list entries. |
1 point Work attempts to credit sources but demonstrates a fundamental failure to understand and apply the APA formatting standard as defined in the Publication Manual of the American Psychological Association (6th ed.). |
0 points Reference list is missing. Work demonstrates an overall failure to incorporate and/or credit authoritative sources for information used in the paper. |
|
Professionalism Part I: Organization & Appearance |
5 points Submitted work shows outstanding organization and the use of color, fonts, titles, headings and sub-headings, etc. is appropriate to the assignment type. |
4 points Submitted work has minor style or formatting flaws but still presents a professional appearance. Submitted work is well organized and appropriately uses color, fonts, and section headings (per the assignment’s directions). |
3 points Organization and/or appearance of submitted work could be improved through better use of fonts, color, titles, headings, etc. OR Submitted work has multiple style or formatting errors. Professional appearance could be improved. |
2 points Submitted work has multiple style or formatting errors. Organization and professional appearance need substantial improvement. |
1 point Submitted work meets minimum requirements but has major style and formatting errors. Work is disorganized and needs to be rewritten for readability and professional appearance. |
0 points Submitted work is poorly organized and formatted. Writing and presentation are lacking in professional style and appearance. Work does not reflect college level writing skills. |
|
Professionalism Part II: Execution |
15 points No formatting, grammar, spelling, or punctuation errors. |
14 points Work contains minor errors in formatting, grammar, spelling or punctuation which do not significantly impact professional appearance. |
13 points Errors in formatting, spelling, grammar, or punctuation which detract from professional appearance of the submitted work. |
11 points Submitted work has numerous errors in formatting, spelling, grammar, or punctuation. Work is unprofessional in appearance. |
4 points Submitted work is difficult to read / understand and has significant errors in formatting, spelling, grammar, punctuation, or word usage. |
0 points Submitted work is poorly executed OR does not reflect college level work. |
|
Overall Score |
Excellent 90 or more |
Outstanding 80 or more |
Acceptable 70 or more |
Needs Improvement 56 or more |
Needs Significant Improvement 36 or more |
Missing or Unacceptable 0 or more |
|
|
|
|
|
|
|
|