7026CEM Security of Emerging Connected Systems
Security of Emerging
Connected Systems
Coursework 1 – Policy and Legal Aspects Report
Word Limit*: 1500, not including
appendices, logs, screenshots, PoC
code, etc.
Module Learning Outcomes Assessed:
1. Critically evaluate the role of a security policy for protecting information
assets and be able to propose appropriate security policies to defend those
assets based on an understanding of security concepts and their
application to internet-based technologies.
2. Demonstrate a sound understanding of the key legislation that relates to
information security and how it influences the security policy of an


You MUST create a folder in the VM desktop, name it exactly “<first_name>
<last_name>-<ID>”, unzip and place the inside the folder you created,
the unzipped folder MUST be the same name,
i.e., domus. In each command line,
you MUST show this folder path in EVERY screenshot
within your report. Screenshots
MUST be clear and easy to read.
For example, if your first name is “Alice” your last name is “Bob”, and your ID is
123456”, then the folder’s name on the desktop is:
Alice Bob-123456
Full path to the given system MUST include:
…/Alice Bob-123456/ domus

You MUST include proper evidence of performing the experiments in CW2 such as
failure to do so will result in failing CW1.
MUST write and ONLY submit MS Word “.docx” file.
Task and Mark distribution:
This coursework consists of two pieces. Students MUST do both pieces.
For this coursework, you should have done CW2; successfully tested all or part of domus
system. Discuss the laws and the legal background related to copyright and the leaked
Personal Identifiable Information (PII) in CW2 domus system.
1. First piece: Copyright laws and legal background of “domus”.
Domus developers are considering distributing or selling for profit domus system in the UK
and US markets.
Discuss the related copyright and copyleft matters related to the system, according to both
UK and US legal systems.
Discuss, with references, both scenarios, either the system will be an open source or not,
discuss the end users’ licence agreement, terms and conditions, contracting, developing
extra features by others, adding libraries, sensors… etc.
Consider all legal aspects (not just copyright), penalties, legal implications, and the legal
consequences on the related parties party that might be related to a system breaching; the
attacker, the system developer or vendor, the distributer (e.g. re-seller) and the end user.
2. Second piece: laws and legal background of the leaked PII.
There is PII leakage in CW2 domus system, discuss the legal background of the PII leakage
in domus in CW2. What laws, regulations, in UK and US that are concerned with such
leakage. Consider legal aspects, penalties, legal implications, and the legal consequences
on the related parties; the attacker, the system developer or vendor, the distributer (e.g. re
seller) and the end user.


Laws and legal background:
For each piece, the report must discuss the UK and US legislation that might be applicable.
Covering the legal aspects, penalties, legal implications, and the legal consequences on the
related parties – the attacker, the system developer, the distributer (e.g. re-seller), and the
end user. Your report must clearly link the issues found in pieces 1 and 2 to the relevant
sections of legislation explaining why the legislation is relevant.
UK Law understanding and coverage (50%, ~800-900 words): coverage of all applicable
legal aspects and a demonstration of a good understanding of the relevant legislation and
the applicable legal consequences or penalties resulting from the legislation.
US Law understanding and coverage for both pieces (40%, ~600-700 words): coverage of
key aspects to be considered and the applicable legal consequences or penalties.
Report (10%): a report suitable for both technical staff and non-technical management; the
style/structure of the report, and the use of language and grammar. Use proper way of citations,
check Coventry University’s guide on writing. Style recommendations:
o Use 3rd person and passive voice rather than 1st and 2nd person.
o Use MS Word with Arial /Sans Serif font or Times New Roman, size 12, and 1.15 line
o Paragraphs are left alignment or justified.
o Acronyms should be capitalised, explained, and added to a table of acronyms at the
beginning of the report.
o Figures, tables, and graphs should be captioned and added to list of figures, tables, and
o Add a table of contents at the beginning of the report.
o Avoid using American English and use British English.
o Wikipedia must not be used as a reference, through it can be used as a key point or a
start for reading and gaining knowledge, with checking the right references.
o All legislation must be properly referenced.
General report structure recommendations, but numbered heading and sections:

Copyright Section
o UK Subsection
o US Subsection
PII leak Section
o UK Subsection
o US Subsection
OR UK Section
o Copyright Subsection
o PII leak Subsection
US Section
o Copyright Subsection
o PII leak Subsection
OR UK Copyright
UK PII leak Subsection
US Copyright Subsection
US PII leak Subsection

Criteria Legal Discussion Sum
Copyright PII leak
UK Law 25% 25% 50%
US Law 20% 20% 40%
No laws were discussed, or no discussion of the impact of the
legislation. No evidence of specific issues relation to the domus
Bare Pass
Barely mentioning the legal issues related to the above matter, very
little discussion, or discussion of one related legal side per issue.
Discussion of the legal implications on the attacker only
Fair discussion of some of the legal sides of each issue. Listing some
of the possible legal consequences against any breach or attack, for
some of the possible related parties; discussion of the legal
implications on two parties only, of which the attacker is one of them.
Good discussion covering most sides of the legal systems for each
issue. Listing some of the possible legal consequences against any
breach or attack, for most of the possible related parties; discussion
of the legal implications on three parties only, of which the attacker is
one of them.
Full analysis of the legal systems that are related to each issue,
Listing all the possible legal consequences against any breach or
attack, for all the possible related parties.
Technical examples of how to protect or avoid any legal
Report Fail marks will be granted for unprofessional poorly written
report, having legal phrases being copied and pasted without
discussion or paraphrasing. poor grammar, poor stye, poor or
INCORRECT citation and referencing… etc. blurred or
unclear screenshots Minor academic misconduct.
Reduced marks if report was way more than the word limit.
See CW2 brief for more details on report marking criteria.
Total 100%

