Information Governance and Security

Job ID: 30667585

Budget: £10 – £20 GBP

Introduction
The assignment for this module is the creation of an information governance policy for a chosen organisation, accompanied by a report justifying the policy and recommending an implementation strategy.
Assignment Tasks:
You are required to create an information governance policy for an organisation and write an accompanying report in which you justify the approach and content of the policy, and propose an implementation strategy. Choose an organisation you know sufficiently well to be able to complete the assignment and address the assessment criteria. It may or may not be an organisation you currently or have previously worked for and you may wish to anonymise it.
Policy
This component addresses module learning outcomes 1 and 3. The policy should be overarching i.e. a statement of intent that provides the organisation with an holistic approach to information governance. It should therefore reference other relevant policies that are either already in place or in need of development; for example an information security policy, email policy, data privacy policy. The policy should be fit-for purpose were it to be implemented in practice. As a minimum it should contain:
• Aim or purpose
• Scope (e.g. all of or selected functions or operating jurisdictions)
• Objectives
• Roles and responsibilities
• Related policies and/or procedures
• Monitoring, measurement and review mechanisms
• Approval
You may include other sections as appropriate for the organisational context. You are also free to determine the length of the policy – its word length is not part of the word limit for the assignment.


Report
This component addresses module learning outcomes 1, 2, 3 and 4. The accompanying report should provide relevant information about the chosen organisation as context, including the nature of its business and the jurisdiction(s) in which it is situated. It should also establish the importance of information governance within the organisational context.
You should justify the form and content of the policy based on principles and best practice, and set out an implementation strategy which should include details relating to any high level resource investment involved (e.g. people, system investment etc) and a timescale.
Your report may include appendices which you may use, for example, to provide additional detail in regard to the nature of the organisation or any analysis you have undertaken. These are outside the word limit.
The audience for the report is the module tutor, not a member of the organisation, therefore it should include citations where relevant, formatted in accordance with academic standards. The word length is 3500-4000 words.

The policy (50%)

• Within the context of the selected organisation – possible mark 15%
• Appropriateness and completeness of content – possible mark 15%
• Evidence of application of principles and best practice – possible mark 10%
• Fitness-for-purpose – 5%
• Presentation including appropriate language, clarity of expression and style; appropriate structure and format and length – possible mark 5%

Accompanying report (50%)
• Appropriateness of organisational context detail – possible mark 10%
• Justification of the importance of information governance to the selected organisation based on a critical evaluation of the organisational context – possible mark 10%
• Justification of the approach taken and rationale for the form and content of the information governance policy based on a critical evaluation and understanding of the organisation, and reference to principles and best practice - possible mark 15%
• Critical analysis and evaluation of the resource requirements and recommendations for the implementation strategy, including timescale - possible mark 10%
Related categories: Security