How to write IT-FPX4993 Assessment 1

The short answer

This manual is for IT-FPX4993 Assessment 1, start to submission. The opening deliverable in IT-FPX4993, Cybersecurity Capstone, generally asks you to fix the project in place: an organization defined tightly enough to analyze, a security problem stated in one sentence with four boundaries in it, an asset inventory and architecture view, the controls that already exist, and a risk register whose ratings a reader could reproduce. A capstone collects verdicts criterion by criterion like everything else, against the guide your courseroom attached. Our tutors' working order appears below, next to an outline taken from the criteria and a worked passage with notes. Prefer to hand it off? A premium original sample for this exact assessment returns in 24 to 48 hours with findings sourced to observation or declared assumption, revised free until the guide is met. Your courseroom may print this as IT FPX 4993 Assessment 1 or IT4993 Assessment 1; it is the same deliverable, and IT-FPX4993 Assessment 1 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

IT-FPX4993 Assessment 1 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades IT-FPX4993 Assessment 1, visualized by Capella Tutors.

How IT-FPX4993 Assessment 1 is scored

Capstone work is still assessed one criterion at a time at one of four levels, which means an opening deliverable can be excellent in three places and floored in a fourth:

LevelWhat it means on a scope and current-state deliverable
DistinguishedThe boundary is tight enough to finish inside a session, every finding is traceable to an observation or a declared assumption, and the risk ratings carry the method that produced them so somebody else could arrive at the same numbers. The criterion asks for one move past a description, and it names it.
ProficientThe organization, the assets and the risks are all documented and consistent. Complete work one column below the top because the ratings are asserted rather than derived.
BasicA generic company profile with a risk table of high, medium and low. Plausible material with nothing behind it lands here more often than a messy honest assessment does.
Non-performanceA required element is not present, most often the asset inventory or a stated scope exclusion. Absence outranks weakness as a way to lose a criterion.

Scope is the exposure that ends capstones. A project that gains a section every week arrives broad, thin and unfinished, so the boundary you write here should be one you can defend against your own enthusiasm in week seven.

The IT-FPX4993 Assessment 1 method, step by step

  1. Write the problem statement with four boundaries in it

    This organization, this system or population, this category of data, and this timeframe. Then test it by asking what evidence would show the problem solved, and if you cannot answer in a sentence the statement is still too large to finish.

  2. Handle the case organization properly before you write about it

    If it is a real employer, ask permission first rather than after a draft exists, then replace the name, generalize the location, change host names and addresses, and keep configuration and credentials out entirely. If permission does not come, build a composite openly and say that you did.

  3. Inventory the assets you will actually be assessing

    Systems, data stores, network segments, identity infrastructure and the people who administer them, each with an owner and a sensitivity. Use one name per asset and use it everywhere, because a server called two things across two documents is what tells a reader the artifacts were never reconciled.

  4. Describe the current controls without flattering them

    What exists, how it is configured, when it was last verified, and which of those answers you obtained by observation rather than by asking. A control somebody says is in place and nobody has checked is a finding in its own right and should be recorded as one.

  5. Build the risk register so the ratings can be reproduced

    Each entry carries the threat, the asset, the existing control, a likelihood and an impact with the scale defined at the top, the resulting rating, and the evidence behind it. Publish the scale before the table so the numbers stop being opinions.

  6. Start the traceability spine now

    One table, one row per risk, and three columns: which artifact deals with it, what proves the artifact did, and which criterion in the guide that satisfies. Blank cells are the schedule for the weeks ahead, and they also mark the claims that will have to become recommendations instead.

A structure that maps to the criteria

Internal planning lengths for an opening capstone document rather than Capella rules; give the extra words to whichever criterion your guide weights most.

SectionWhat it must doGuide
Problem statement and scopeThe one-sentence problem with its four boundaries, what is in scope, what is excluded, and why each exclusion is defensible.~250 words
Organization and constraintsThe case organization described at the level the analysis needs, its constraints, and the redaction statement if it is real.~200 words
Asset inventory and architectureSystems, data, segments and identity infrastructure with owners and sensitivity, named consistently throughout.~300 words
Existing controlsWhat is already in place, how it is configured, when it was last verified, and which answers came from observation.~250 words
Risk registerThe scale defined first, then entries with threat, asset, control, likelihood, impact, rating and the evidence behind each.~350 words
Traceability, assumptions and sourcesThe spine table, the assumptions the analysis rests on, and standards and reporting cited by revision and year in current APA.~200 words

Annotated sample excerpt

One paragraph our team wrote as a model for a deliverable of this kind. Read it for the moves rather than the particulars, then write it for the organization you chose.

Sample excerpt: problem statement and scope Original model · Capella Tutors

The problem is that the brokerage's 260 workstations across five branch offices authenticate to a single directory with password-only access for staff and no separate credential for administration, and this assessment covers those workstations, that directory, and the client records held on the two file servers between now and the end of the current fiscal year.1 Evidence that the problem is solved would be specific rather than atmospheric: administrative actions requiring a second factor, no shared administrative account in use, and a measured reduction in the number of staff accounts holding rights they do not need, which is currently 41 of 260 by the directory's own group membership.2 Excluded deliberately are the agency management platform, which is a hosted service the brokerage cannot configure, and the branch telephony system, because neither can be changed by anyone inside the organization and a recommendation nobody can execute is not a finding.3

  • 1Puts all four boundaries in one sentence: the organization, the systems, the data and the timeframe. A reader knows immediately what will and will not be assessed.
  • 2Answers the solved test with observable conditions and one real count. A number pulled from the environment converts a scope statement into an evidence plan.
  • 3Excludes on the grounds of what the organization can actually change. Exclusions with reasons read as judgment; exclusions by omission read as gaps.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • A scope that grows every week. Adding a section each time something interesting appears produces a project that is wide, shallow and unfinished at the deadline.
  • Risk ratings with no scale published. High and medium mean nothing until the document says what likelihood and impact values produce them.
  • Assets named differently in different artifacts. One server called two things across two documents tells a reader the pieces were written separately and never reconciled.
  • Existing controls taken on trust. A control nobody has verified is an assumption, and recording it as a fact contaminates every rating that depends on it.
  • Real employer detail left in the file. One live hostname, one screenshot carrying a logo, or one named colleague is enough to make the document unshowable.

Pre-submission checklist

  • Each criterion in your guide addressed under its own heading
  • Problem statement carrying organization, system, data and timeframe
  • Exclusions stated with a defensible reason for each
  • Asset inventory with one consistent name per asset and an owner
  • Risk scale published before the register, ratings reproducible from it
  • Traceability table started, redaction statement present, current APA both ways

Scope and current state due this week?

Send the organization, whatever scope you have sketched and the criteria attached to this stage. The problem statement comes back with four boundaries in one sentence, the register comes back with a published scale, and every finding comes back sourced to an observation or a declared assumption. Your opening premium sample is free.

Keep going

Online now