You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This document provides the grading rubrics for all assignments and the capstone project in the Certified Cybersecurity Consultant (CCC) program. These rubrics are designed to provide clear, objective criteria for evaluating student work.
General Assignment Rubric
This rubric applies to all monthly assignments (Modules 1-3).
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Weight
Technical Accuracy
All technical content is accurate, well-researched, and demonstrates deep understanding. Recommendations are based on current industry best practices.
Technical content is mostly accurate with minor errors. Recommendations are sound and appropriate.
Technical content is generally accurate but may contain some errors or oversimplifications. Recommendations are adequate.
Technical content contains significant errors or demonstrates lack of understanding. Recommendations are inappropriate or missing.
30%
Completeness
All required sections are included and thoroughly addressed. Goes beyond minimum requirements.
All required sections are included and adequately addressed.
Most required sections are included. Some sections may lack detail.
Missing required sections or significant gaps in content.
20%
Analysis and Critical Thinking
Demonstrates exceptional analytical skills and strategic thinking. Provides insightful observations and well-reasoned conclusions.
Demonstrates good analytical skills. Provides sound analysis and logical conclusions.
Demonstrates basic analytical skills. Analysis is adequate but may lack depth.
Lacks analytical depth. Conclusions are unsupported or illogical.
25%
Professional Presentation
Exceptionally well-written and formatted. Free of errors. Uses professional language and appropriate tone. Includes effective visualizations.
Well-written and formatted. Minor errors. Professional language and tone. Good use of visualizations.
Adequately written and formatted. Some errors. Generally professional. Basic visualizations.
Poorly written or formatted. Multiple errors. Unprofessional language or tone. Missing or poor visualizations.
15%
Actionability
Recommendations are highly specific, practical, and immediately actionable. Clear implementation guidance provided.
Recommendations are specific and actionable. Implementation guidance is adequate.
Recommendations are somewhat general but still actionable. Limited implementation guidance.
Recommendations are vague, impractical, or not actionable.
10%
Module-Specific Rubrics
Module 1: Strategic Security Consulting & Business Alignment
Assignment 1.1: Statement of Work (SOW)
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Scope Definition
Scope is crystal clear, comprehensive, and includes appropriate exclusions. Demonstrates understanding of client needs.
Scope is clear and comprehensive. Minor ambiguities.
Scope is defined but may be vague in some areas.
Scope is unclear, incomplete, or inappropriate.
Deliverables
Deliverables are specific, measurable, and aligned with client needs. Timeline is realistic.
Deliverables are clear and appropriate. Timeline is reasonable.
Deliverables are defined but may lack specificity. Timeline may be unrealistic.
Deliverables are vague or missing. Timeline is unrealistic.
Pricing
Pricing is detailed, transparent, and realistic. Includes appropriate breakdown and payment terms.
Pricing is clear and reasonable. Adequate breakdown provided.
Pricing is provided but may lack detail or justification.
Pricing is missing, unrealistic, or poorly justified.
Assignment 1.2: Qualitative Risk Assessment
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Risk Identification
Comprehensive list of risks covering all relevant categories. Demonstrates deep understanding of the scenario.
Good list of risks covering most relevant categories.
Adequate list of risks but may miss some important categories.
Incomplete or superficial risk identification.
Risk Analysis
Risk likelihood and impact assessments are well-reasoned and justified. Uses appropriate methodology.
Risk assessments are reasonable and adequately justified.
Risk assessments are provided but may lack justification.
Risk assessments are arbitrary or unjustified.
Prioritization
Risk prioritization is logical, well-justified, and uses an appropriate risk matrix.
Risk prioritization is reasonable and adequately justified.
Risk prioritization is provided but may lack clear rationale.
Risk prioritization is unclear or illogical.
Module 2: GRC Deep Dive
Assignment 2.1: Statement of Applicability (SoA)
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Control Assessment
All controls are assessed with clear, well-justified decisions on applicability. Demonstrates deep understanding of ISO 27001.
Most controls are assessed with adequate justification.
Controls are assessed but justification may be weak or missing for some.
Control assessment is incomplete or poorly justified.
Documentation
References to documentation are specific and appropriate. Implementation status is clearly indicated.
References are adequate. Implementation status is indicated.
References may be vague. Implementation status may be unclear.
References are missing or inappropriate. Implementation status is not indicated.
Assignment 2.2: GDPR Gap Analysis
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Data Mapping
Comprehensive data mapping covering all relevant data types and processes.
Good data mapping covering most relevant data types.
Adequate data mapping but may miss some data types.
Incomplete or inaccurate data mapping.
Gap Identification
All significant gaps are identified with clear explanations. Demonstrates deep understanding of GDPR.
Most significant gaps are identified with adequate explanations.
Some gaps are identified but analysis may be superficial.
Gap identification is incomplete or inaccurate.
Remediation Plan
Remediation steps are specific, prioritized, and follow SMART criteria.
Remediation steps are clear and actionable.
Remediation steps are provided but may lack specificity.
Remediation steps are vague or impractical.
Module 3: Advanced Security Architecture
Assignment 3.1: Zero Trust Architecture Design
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Architecture Design
Comprehensive ZTA design addressing all key principles. Includes detailed diagrams and explanations.
Good ZTA design addressing most key principles. Adequate diagrams.
Basic ZTA design addressing some key principles. Limited diagrams.
Incomplete or flawed ZTA design. Missing or poor diagrams.
Feasibility
Design is highly feasible for the given environment. Demonstrates understanding of implementation challenges.
Design is feasible with minor concerns.
Design may have feasibility issues.
Design is impractical or demonstrates lack of understanding.
Innovation
Demonstrates innovative thinking and incorporates cutting-edge concepts.
Demonstrates good understanding of modern ZTA concepts.
Demonstrates basic understanding of ZTA.
Lacks understanding of ZTA principles.
Assignment 3.2: Cloud Security Strategy
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Comprehensiveness
Strategy addresses all key aspects of cloud security. Demonstrates deep understanding of cloud security models.
Strategy addresses most key aspects of cloud security.
Strategy addresses some key aspects but may have gaps.
Strategy is incomplete or demonstrates lack of understanding.
Shared Responsibility
Clear explanation of shared responsibility model and how it applies to the client.
Adequate explanation of shared responsibility model.
Basic explanation of shared responsibility model.
Missing or incorrect explanation of shared responsibility model.
Module 4: Professional Consulting Skills
Assignment 4.1: Board Presentation
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Executive Communication
Presentation is exceptionally clear, concise, and persuasive. Perfect for a board audience. No technical jargon.
Presentation is clear and appropriate for a board audience. Minimal technical jargon.
Presentation is adequate but may include some technical jargon or lack clarity.
Presentation is unclear, too technical, or inappropriate for the audience.
Visual Design
Slide deck is professionally designed with effective use of visuals and data visualizations.
Slide deck is well-designed with good use of visuals.
Slide deck is adequately designed but may lack polish.
Slide deck is poorly designed or unprofessional.
Call to Action
Call to action is clear, compelling, and actionable.
Call to action is clear and actionable.
Call to action is present but may lack clarity.
Call to action is missing or unclear.
Capstone Project Rubric
The capstone project is worth 40% of the final grade and is evaluated using the following rubric:
Criteria
Excellent (90-100%)
Good (80-89%)
Satisfactory (75-79%)
Unsatisfactory (<75%)
Weight
Technical Accuracy
All technical content across all deliverables is accurate and demonstrates mastery. Findings are realistic and well-researched. Recommendations are based on current best practices.
Technical content is mostly accurate with minor errors. Findings are reasonable. Recommendations are sound.
Technical content is generally accurate but may contain some errors. Findings are adequate. Recommendations are appropriate.
Technical content contains significant errors. Findings are unrealistic. Recommendations are inappropriate.
30%
Strategic Relevance
Roadmap is exceptionally well-aligned with business objectives. Clear ROI demonstrated. Priorities are perfectly justified.
Roadmap is well-aligned with business objectives. Good business justification. Priorities are justified.
Roadmap is aligned with business objectives. Basic business justification. Priorities are reasonable.
Roadmap is poorly aligned with business objectives. Weak business justification. Priorities are unclear.
30%
Professional Presentation
All deliverables are exceptionally well-written, formatted, and free of errors. Executive presentation is outstanding. Visualizations are highly effective.
All deliverables are well-written and formatted with minor errors. Executive presentation is good. Visualizations are effective.
All deliverables are adequately written and formatted with some errors. Executive presentation is adequate. Visualizations are basic.
Deliverables are poorly written or formatted with multiple errors. Executive presentation is weak. Visualizations are poor or missing.
20%
Completeness
All deliverables are complete and exceed requirements. All sections are thoroughly addressed. Deliverables are cohesive and consistent.
All deliverables are complete and meet requirements. All sections are adequately addressed. Deliverables are consistent.
Most deliverables are complete. Some sections may lack detail. Deliverables are generally consistent.
Deliverables are incomplete. Missing required sections. Deliverables are inconsistent.
20%
Final Grade Calculation
Assessment Weights
Module 1 Assignments: 15%
Module 2 Assignments: 15%
Module 3 Assignments: 15%
Module 4 Assignments: 15%
Capstone Project: 40%
Certification Requirements
To earn the CCC certification:
Minimum Final Grade: 75%
All Assignments Completed: Students must complete all assignments and the capstone project
No Individual Assignment Below 60%: Students must achieve at least 60% on each individual assignment