How to write IT-FPX4076 Assessment 1

The short answer

This manual is for IT-FPX4076 Assessment 1, start to submission. The first deliverable in Security Management and Policies is normally a governing document you write for a named organization, and the test it has to pass is whether that organization could actually be run by it. Nothing rewards elegant prose about intentions here. The marks sit in the front matter that says who is bound and who approved it, in obligations phrased so an auditor can test them, and in an enforcement section that exists. Below is the method our tutors use for it, a structure that maps to the criteria, and an annotated sample excerpt. Prefer to hand it off? A premium original sample for this exact assessment comes back in 24 to 48 hours, revised free until it meets the guide. Your courseroom may print this as IT FPX 4076 Assessment 1 or IT4076 Assessment 1; it is the same deliverable, and IT-FPX4076 Assessment 1 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

IT-FPX4076 Assessment 1 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades IT-FPX4076 Assessment 1, visualized by Capella Tutors.

How IT-FPX4076 Assessment 1 is scored

FlexPath does not average anything into a letter. Each criterion on your scoring guide is placed at one of four levels, and those level descriptions are the brief you write toward:

LevelWhat it means on a policy document
DistinguishedObligations are testable as written, settings are delegated to a named standard, and the review and enforcement clauses would still work three years from now. Each criterion has one extra move in it; find that move and make it.
ProficientA complete, correct document with every required clause present. Professional work, one step short of a document an auditor could pick up cold.
BasicA policy that pauses to explain why security matters, with requirements buried in paragraphs of reasoning. The commonest first submission in this course.
Non-performanceA required clause is not there at all, most often the review interval or the consequence of non-compliance. Omission puts a row on the floor by itself.

The register is the thing to get right early. A policy speaks in obligations and never argues with itself in the middle of one, so any sentence that begins to persuade belongs in a rationale section or in the memo to the approving committee instead.

The IT-FPX4076 Assessment 1 method, step by step

  1. Sort the criteria into documents, processes, and assessments

    Read each row and decide which of the three it wants, because they are written differently. A document states obligations, a process states steps with roles attached, and an assessment states findings with evidence behind them. Submissions lose the top column by mixing the registers, so decide this before drafting and label your sections accordingly.

  2. Write the organization profile before the first requirement

    Take an engineering consultancy of 240 staff working across client sites on their own laptops, and write that down: sector, headcount, structure, what data it holds, what obligations follow. Scope decisions come out of that profile, and rewriting scope late means rewriting every requirement under it. Say in the introduction whether the organization is real or constructed, because a reader cannot judge whether your scope is right without knowing what it covers.

  3. Fill in all six front-matter fields

    Who it applies to, who approved it, when it takes effect, who owns it, when it will be reviewed, and what happens if somebody ignores it. Documents missing the last two are the ones auditors find years out of date with nobody willing to touch them. Make applicability precise enough to settle an argument, so contractors and personal devices are either in or out in writing.

  4. Use one modal verb per meaning and never mix them

    Must for a requirement, should for a recommendation, may for a permission. A document that drifts between them cannot be audited because nobody can tell which lines are obligations, and an acceptable-use policy is read most closely by people looking for the gap. Number your obligations so a manager can cite one by reference in a conversation.

  5. Push every technical setting down a level

    The moment a specific configuration value appears in a document an executive committee approved, that value is frozen until the committee meets again. Require authentication that meets the current organizational standard, then let the standard move at the speed of the advice. Say in one line where the standard lives and who owns it, since a delegation with no destination is just a gap.

  6. Read it as the person being governed, then self-score

    Take the role of a consultant who wants to use a personal tablet on a client site and see whether your document answers that in under a minute. If the answer takes three sections and an inference, rewrite. Then mark each criterion D, P, B, or N yourself and fix any row you cannot defend, and upload early because an evaluation can take two business days.

A structure that maps to the criteria

Word counts are the shape our tutors plan a governing document around rather than a Capella requirement; a criterion that asks for more in a clause gets more there.

SectionWhat it must doGuide
Purpose and scopeWhy the document exists, who and what it binds, and any person, system, or location deliberately excluded.~200 words
DefinitionsOnly the terms whose meaning changes an obligation, defined once so the requirements can stay short.~150 words
RequirementsNumbered obligations in consistent modal language, each one testable as written and free of settings.~450 words
Roles and responsibilitiesWho decides, who implements, who verifies, and who must be told, assigned to positions rather than to people.~200 words
Compliance and enforcementHow adherence is checked, what happens when it is not met, and how exceptions are requested.~200 words
Governance and sourcesOwner, approver, effective date, review interval, version history, and standards references in current APA.~150 words

Annotated sample excerpt

A short passage of original model text from our team, in the register a governing document is supposed to carry. Read it for the mechanics, then draft your own clauses.

Sample excerpt: requirements clause Original model · Capella Tutors

4.2 Personnel must not connect a device to a client network or client system unless that device is enrolled in the firm's management service and appears on the current asset register.1 4.3 Personally owned devices may be used for electronic mail and calendar access only, and must not hold client drawings, models, or correspondence in local storage; personnel who require local access must request an exception under section 7.2 4.4 Authentication to firm systems must meet the requirements of the Access Control Standard, which is owned by the Information Security Manager and reviewed at least annually.3

  • 1Numbered, one obligation, one modal verb, and a condition somebody can go and check against a register. An auditor can test this clause without asking the author what it meant.
  • 2Draws the personal-device line in the clause itself and routes the predictable objection to the exception process rather than leaving a reader to argue about it.
  • 3Delegates the technical detail to a named standard with a named owner and a review cycle, so the policy survives the next change of advice without going back to an approving committee.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • Requirements written in the future tense. A document saying the firm intends to do something has committed nobody to anything.
  • Modal verbs used interchangeably. When must and should mean the same thing in one document, none of the obligations can be enforced.
  • Configuration values written into policy. A password length approved by a committee stays wrong until that committee meets again.
  • No consequence for non-compliance. A rule with nothing behind it is guidance, and the criterion asking about enforcement can see the difference.
  • Scope that never mentions contractors or personal devices. The population your document forgot is the population that will test it first.

Pre-submission checklist

  • Purpose, scope, owner, approver, effective date, and review interval are all populated
  • Every obligation is numbered and uses a single modal verb with one meaning
  • No technical setting appears in the governing text, and each delegation names a standard
  • Roles are assigned to positions, with verification separated from implementation
  • Enforcement and the route to request an exception both appear in the document
  • Read once from the position of a person trying to find the gap, then self-scored row by row

Policy document due and the wording will not hold?

Send the organization, the criteria, and any document your scenario supplied. A premium original returns inside 24 to 48 hours with front matter complete, obligations numbered and testable, and settings delegated where they belong. The first sample costs nothing.

Keep going

Online now