How to write IT-FPX4073 Assessment 2

The short answer

This manual is for IT-FPX4073 Assessment 2, start to submission. The middle deliverable in this course usually covers the parts of a security program that have nothing to do with software: people through the length of their employment, buildings and who gets into them, and suppliers who inherit your data and export their weaknesses. IT students underweight this work, and the criteria reward candidates who write about all three without embarrassment. Ahead: the method, a structure that follows the criteria row by row, and one annotated model excerpt. Want it handled? Send the case and a premium original sample lands within 24 to 48 hours, revised at no charge until the guide is satisfied. Your courseroom may print this as IT FPX 4073 Assessment 2 or IT4073 Assessment 2; it is the same deliverable, and IT-FPX4073 Assessment 2 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

IT-FPX4073 Assessment 2 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades IT-FPX4073 Assessment 2, visualized by Capella Tutors.

How IT-FPX4073 Assessment 2 is scored

Four levels sit behind every criterion, with no percentage anywhere. What the level says is what the section has to do:

LevelWhat it means on a personnel, premises and third-party submission
DistinguishedControls attach to the employment lifecycle and to the building the case actually describes, suppliers are tiered by what they hold, and obligations appear as contract language with a notification window and an audit right. Reassessment has a cadence.
ProficientScreening, access, facilities, and vendor review are all present and sensible. Complete, with the controls written as intentions.
BasicA policy summary covering hiring and a note that vendors complete a questionnaire. Where the deliverable lands when the sections were written from a template.
Non-performanceA required area is absent, most often physical security or the contract obligations, so the criterion resting on it cannot be marked.

Vendor risk is where most drafts stop one step early. A returned questionnaire with no evidence behind it and no clause in the contract changes nothing about the risk, and an evaluator who has managed suppliers knows it. Evidence proportionate to the tier, and an obligation somebody could enforce, are what the criterion is asking for.

The IT-FPX4073 Assessment 2 method, step by step

  1. Map the criteria, then split the work three ways

    Divide the document into people, premises, and third parties before drafting, and check that each has its own criteria answered inside it. Sections that bleed into one another are how the physical security row ends up with two sentences in an appendix.

  2. Run personnel controls along the whole employment lifecycle

    Screening proportionate to the role, an acceptable use agreement signed before access exists, permissions granted from the job rather than copied from a colleague, recertification of what people can reach, and a departure process that closes accounts on the last day. A hotel group hiring seasonal front-desk staff every spring needs the joining and leaving ends of that chain to work automatically, because they run four times a year.

  3. Address the trusted insider with the two controls that fit

    Separation of duties and rotation of duties belong in any paper that mentions fraud, so apply them to something concrete: the night manager who can both void a charge and adjust the till reconciliation is one person holding both halves of a transaction, and rotating who performs the weekly reconciliation costs nothing and closes the gap.

  4. Write physical security against the building in the case

    Six properties with public lobbies, back-of-house corridors, and a small server cupboard behind reception is a specific problem. Say how the cupboard is locked, who holds the key, how the key is logged, how a contractor is escorted, how a delivery is received, and what happens to the propped fire door in July. Logical controls assume the premises are controlled, and this section is where that assumption gets tested.

  5. Tier the suppliers and write obligations somebody could enforce

    Sort suppliers by the sensitivity of what they hold, take evidence proportionate to the tier rather than the same form from everybody, and put security obligations into the contract with a breach notification window measured in hours, a right to audit, and a reassessment cadence. The booking platform holding guest payment details and the company that services the lifts are not the same risk and should not receive the same questionnaire.

  6. Give every control an owner and a cadence, then self-score

    Attach a position and a frequency to each recommendation, since a control with no cadence happens once. Then mark your own draft against each row and submit early, because an evaluated attempt can take two business days and one revision is cheaper than one resubmission.

A structure that maps to the criteria

Planning targets our tutors use for a deliverable of this scope, not Capella rules; let your own scoring guide decide the real proportions.

SectionWhat it must doGuide
Context recapThe organization, its sites, its staffing pattern, and the data each site handles.~150 words
Employment lifecycleScreening, agreements, provisioning, recertification, and departure, each with an owner and a trigger.~300 words
Insider controlsSeparation and rotation of duties applied to a named process where one person holds both halves.~200 words
PremisesServer room access, key custody, visitor and contractor handling, deliveries, and the failure the case already contains.~300 words
Third partiesSupplier tiers, evidence expected per tier, contract clauses, notification window, and reassessment cadence.~300 words
SourcesManagement standards and supply chain guidance cited by revision, sector figures dated, current APA.as needed

Annotated sample excerpt

One recommendation from a model our team produced, written so a general manager could act on it without a security background.

Sample excerpt: a supplier obligation Original model · Capella Tutors

The booking platform holds guest names, stay dates, and card references for all six properties, which places it in the top supplier tier and means a questionnaire is not sufficient evidence on its own.1 The contract at renewal carries three clauses: notification to the group's operations director within twenty-four hours of any suspected compromise of guest data, a right to receive the platform's current independent assurance report annually rather than on request, and a requirement that subcontractors handling the same data be disclosed in writing before they are engaged.2 The linen supplier and the lift maintenance company sit in the lowest tier, hold no guest data, and are reassessed on a three-year cycle with a single-page confirmation, because spending equal effort on every supplier means spending too little on this one.3

  • 1Sets the tier from what the supplier holds rather than from how much it is paid, which is the reasoning a third-party criterion looks for.
  • 2Turns intentions into contract language with a number in it. A notification window measured in hours is enforceable; a promise to notify promptly is not.
  • 3Justifies spending less on the low tier, which shows prioritization rather than thoroughness for its own sake.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • Vendor risk that stops at a questionnaire. A returned form with no evidence and no contract clause leaves the risk exactly where it was.
  • Physical and personnel controls left out. A program paper covering only technology has answered a different question than the one asked.
  • Departure handling with no trigger. An offboarding process that starts when somebody remembers is not a control, and the case usually proves it.
  • Every supplier treated identically. Equal effort across all tiers means too little effort on the one holding your guests' card data.
  • Controls with no cadence. Recertification that happens once is provisioning, and the criterion asks how often it recurs.

Pre-submission checklist

  • People, premises, and third parties each answered in their own section
  • Every lifecycle control given an owner and an automatic trigger
  • Separation or rotation of duties applied to a named process, not defined in the abstract
  • Physical controls written against the building the case describes, including its existing failure
  • Suppliers tiered by what they hold, with evidence and clauses proportionate to tier
  • A cadence attached to every recurring control, then self-scored per row

Program sections due and the physical part is empty?

Send the organization, the sites, and the criteria. You get controls attached to the employment lifecycle, premises written against the building in the case, and supplier obligations drafted as contract language with a notification window, inside 24 to 48 hours. Free revision until the guide is met, and the first premium sample carries no fee.

Keep going

Online now