Skip to content

Latest commit

 

History

History
135 lines (92 loc) · 13.3 KB

File metadata and controls

135 lines (92 loc) · 13.3 KB

CCC Program Grading Rubric

Overview

This document provides the grading rubrics for all assignments and the capstone project in the Certified Cybersecurity Consultant (CCC) program. These rubrics are designed to provide clear, objective criteria for evaluating student work.


General Assignment Rubric

This rubric applies to all monthly assignments (Modules 1-3).

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%) Weight
Technical Accuracy All technical content is accurate, well-researched, and demonstrates deep understanding. Recommendations are based on current industry best practices. Technical content is mostly accurate with minor errors. Recommendations are sound and appropriate. Technical content is generally accurate but may contain some errors or oversimplifications. Recommendations are adequate. Technical content contains significant errors or demonstrates lack of understanding. Recommendations are inappropriate or missing. 30%
Completeness All required sections are included and thoroughly addressed. Goes beyond minimum requirements. All required sections are included and adequately addressed. Most required sections are included. Some sections may lack detail. Missing required sections or significant gaps in content. 20%
Analysis and Critical Thinking Demonstrates exceptional analytical skills and strategic thinking. Provides insightful observations and well-reasoned conclusions. Demonstrates good analytical skills. Provides sound analysis and logical conclusions. Demonstrates basic analytical skills. Analysis is adequate but may lack depth. Lacks analytical depth. Conclusions are unsupported or illogical. 25%
Professional Presentation Exceptionally well-written and formatted. Free of errors. Uses professional language and appropriate tone. Includes effective visualizations. Well-written and formatted. Minor errors. Professional language and tone. Good use of visualizations. Adequately written and formatted. Some errors. Generally professional. Basic visualizations. Poorly written or formatted. Multiple errors. Unprofessional language or tone. Missing or poor visualizations. 15%
Actionability Recommendations are highly specific, practical, and immediately actionable. Clear implementation guidance provided. Recommendations are specific and actionable. Implementation guidance is adequate. Recommendations are somewhat general but still actionable. Limited implementation guidance. Recommendations are vague, impractical, or not actionable. 10%

Module-Specific Rubrics

Module 1: Strategic Security Consulting & Business Alignment

Assignment 1.1: Statement of Work (SOW)

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Scope Definition Scope is crystal clear, comprehensive, and includes appropriate exclusions. Demonstrates understanding of client needs. Scope is clear and comprehensive. Minor ambiguities. Scope is defined but may be vague in some areas. Scope is unclear, incomplete, or inappropriate.
Deliverables Deliverables are specific, measurable, and aligned with client needs. Timeline is realistic. Deliverables are clear and appropriate. Timeline is reasonable. Deliverables are defined but may lack specificity. Timeline may be unrealistic. Deliverables are vague or missing. Timeline is unrealistic.
Pricing Pricing is detailed, transparent, and realistic. Includes appropriate breakdown and payment terms. Pricing is clear and reasonable. Adequate breakdown provided. Pricing is provided but may lack detail or justification. Pricing is missing, unrealistic, or poorly justified.

Assignment 1.2: Qualitative Risk Assessment

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Risk Identification Comprehensive list of risks covering all relevant categories. Demonstrates deep understanding of the scenario. Good list of risks covering most relevant categories. Adequate list of risks but may miss some important categories. Incomplete or superficial risk identification.
Risk Analysis Risk likelihood and impact assessments are well-reasoned and justified. Uses appropriate methodology. Risk assessments are reasonable and adequately justified. Risk assessments are provided but may lack justification. Risk assessments are arbitrary or unjustified.
Prioritization Risk prioritization is logical, well-justified, and uses an appropriate risk matrix. Risk prioritization is reasonable and adequately justified. Risk prioritization is provided but may lack clear rationale. Risk prioritization is unclear or illogical.

Module 2: GRC Deep Dive

Assignment 2.1: Statement of Applicability (SoA)

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Control Assessment All controls are assessed with clear, well-justified decisions on applicability. Demonstrates deep understanding of ISO 27001. Most controls are assessed with adequate justification. Controls are assessed but justification may be weak or missing for some. Control assessment is incomplete or poorly justified.
Documentation References to documentation are specific and appropriate. Implementation status is clearly indicated. References are adequate. Implementation status is indicated. References may be vague. Implementation status may be unclear. References are missing or inappropriate. Implementation status is not indicated.

Assignment 2.2: GDPR Gap Analysis

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Data Mapping Comprehensive data mapping covering all relevant data types and processes. Good data mapping covering most relevant data types. Adequate data mapping but may miss some data types. Incomplete or inaccurate data mapping.
Gap Identification All significant gaps are identified with clear explanations. Demonstrates deep understanding of GDPR. Most significant gaps are identified with adequate explanations. Some gaps are identified but analysis may be superficial. Gap identification is incomplete or inaccurate.
Remediation Plan Remediation steps are specific, prioritized, and follow SMART criteria. Remediation steps are clear and actionable. Remediation steps are provided but may lack specificity. Remediation steps are vague or impractical.

Module 3: Advanced Security Architecture

Assignment 3.1: Zero Trust Architecture Design

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Architecture Design Comprehensive ZTA design addressing all key principles. Includes detailed diagrams and explanations. Good ZTA design addressing most key principles. Adequate diagrams. Basic ZTA design addressing some key principles. Limited diagrams. Incomplete or flawed ZTA design. Missing or poor diagrams.
Feasibility Design is highly feasible for the given environment. Demonstrates understanding of implementation challenges. Design is feasible with minor concerns. Design may have feasibility issues. Design is impractical or demonstrates lack of understanding.
Innovation Demonstrates innovative thinking and incorporates cutting-edge concepts. Demonstrates good understanding of modern ZTA concepts. Demonstrates basic understanding of ZTA. Lacks understanding of ZTA principles.

Assignment 3.2: Cloud Security Strategy

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Comprehensiveness Strategy addresses all key aspects of cloud security. Demonstrates deep understanding of cloud security models. Strategy addresses most key aspects of cloud security. Strategy addresses some key aspects but may have gaps. Strategy is incomplete or demonstrates lack of understanding.
Shared Responsibility Clear explanation of shared responsibility model and how it applies to the client. Adequate explanation of shared responsibility model. Basic explanation of shared responsibility model. Missing or incorrect explanation of shared responsibility model.

Module 4: Professional Consulting Skills

Assignment 4.1: Board Presentation

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%)
Executive Communication Presentation is exceptionally clear, concise, and persuasive. Perfect for a board audience. No technical jargon. Presentation is clear and appropriate for a board audience. Minimal technical jargon. Presentation is adequate but may include some technical jargon or lack clarity. Presentation is unclear, too technical, or inappropriate for the audience.
Visual Design Slide deck is professionally designed with effective use of visuals and data visualizations. Slide deck is well-designed with good use of visuals. Slide deck is adequately designed but may lack polish. Slide deck is poorly designed or unprofessional.
Call to Action Call to action is clear, compelling, and actionable. Call to action is clear and actionable. Call to action is present but may lack clarity. Call to action is missing or unclear.

Capstone Project Rubric

The capstone project is worth 40% of the final grade and is evaluated using the following rubric:

Criteria Excellent (90-100%) Good (80-89%) Satisfactory (75-79%) Unsatisfactory (<75%) Weight
Technical Accuracy All technical content across all deliverables is accurate and demonstrates mastery. Findings are realistic and well-researched. Recommendations are based on current best practices. Technical content is mostly accurate with minor errors. Findings are reasonable. Recommendations are sound. Technical content is generally accurate but may contain some errors. Findings are adequate. Recommendations are appropriate. Technical content contains significant errors. Findings are unrealistic. Recommendations are inappropriate. 30%
Strategic Relevance Roadmap is exceptionally well-aligned with business objectives. Clear ROI demonstrated. Priorities are perfectly justified. Roadmap is well-aligned with business objectives. Good business justification. Priorities are justified. Roadmap is aligned with business objectives. Basic business justification. Priorities are reasonable. Roadmap is poorly aligned with business objectives. Weak business justification. Priorities are unclear. 30%
Professional Presentation All deliverables are exceptionally well-written, formatted, and free of errors. Executive presentation is outstanding. Visualizations are highly effective. All deliverables are well-written and formatted with minor errors. Executive presentation is good. Visualizations are effective. All deliverables are adequately written and formatted with some errors. Executive presentation is adequate. Visualizations are basic. Deliverables are poorly written or formatted with multiple errors. Executive presentation is weak. Visualizations are poor or missing. 20%
Completeness All deliverables are complete and exceed requirements. All sections are thoroughly addressed. Deliverables are cohesive and consistent. All deliverables are complete and meet requirements. All sections are adequately addressed. Deliverables are consistent. Most deliverables are complete. Some sections may lack detail. Deliverables are generally consistent. Deliverables are incomplete. Missing required sections. Deliverables are inconsistent. 20%

Final Grade Calculation

Assessment Weights

  • Module 1 Assignments: 15%
  • Module 2 Assignments: 15%
  • Module 3 Assignments: 15%
  • Module 4 Assignments: 15%
  • Capstone Project: 40%

Certification Requirements

To earn the CCC certification:

  • Minimum Final Grade: 75%
  • All Assignments Completed: Students must complete all assignments and the capstone project
  • No Individual Assignment Below 60%: Students must achieve at least 60% on each individual assignment

Grade Scale

Grade Percentage Designation
A 90-100% Excellent
B 80-89% Good
C 75-79% Satisfactory
F Below 75% Unsatisfactory (No Certification)

Last Updated: December 2025

Version: 1.0