IT security fundamentals
IT security fundamentals cover security layers, operating system and network security, system protection options, and configuring security for IT systems. Understanding these helps protect data and systems from threats.
Assessment criteria
Topic Overview
The City & Guilds Level 3 Diploma in ICT Systems and Principles for IT Professionals is a comprehensive vocational qualification designed to equip students with the practical skills and theoretical knowledge required for a career in IT. This diploma covers a wide range of topics including computer systems, networking, database design, programming, and cybersecurity. It is structured to provide a solid foundation in both hardware and software aspects of ICT, preparing students for roles such as IT support technician, network administrator, or systems analyst.
This qualification is particularly valuable because it balances hands-on technical skills with an understanding of how ICT systems are designed, implemented, and maintained in real-world business environments. Students learn to troubleshoot hardware issues, configure networks, develop software applications, and ensure data security. The diploma is recognised by employers and can lead to further study at university level or direct entry into the IT industry. By the end of the course, students will have developed problem-solving abilities, project management skills, and a professional approach to ICT work.
The diploma is divided into mandatory and optional units, allowing students to specialise in areas such as programming, networking, or IT security. Assessment methods include practical assignments, written exams, and project work, ensuring that students can demonstrate both their knowledge and their ability to apply it. This qualification aligns with the UK's National Occupational Standards for IT, making it directly relevant to the skills demanded by employers in the sector.
Key Concepts
Core ideas you must understand for this topic
- →Computer Systems Architecture: Understanding the components of a computer system (CPU, memory, storage, I/O devices) and how they interact, including the fetch-execute cycle and different types of memory (RAM, ROM, cache).
- →Networking Fundamentals: Knowledge of network topologies, protocols (TCP/IP, HTTP, FTP), OSI model, IP addressing, subnetting, and the difference between LAN, WAN, and VPN.
- →Database Design and SQL: Ability to design relational databases using normalisation, create tables, and write SQL queries for data manipulation (SELECT, INSERT, UPDATE, DELETE) and data definition (CREATE, ALTER, DROP).
- →Programming Principles: Understanding of programming paradigms (procedural, object-oriented), data types, control structures (selection, iteration), and debugging techniques, typically using languages like Python, Java, or C#.
- →Cybersecurity Basics: Principles of confidentiality, integrity, and availability (CIA triad), common threats (malware, phishing, DoS attacks), and security measures such as encryption, firewalls, and access controls.
Learning Objectives
What you need to know and understand
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Describe the layers of security in an IT system
- Explain the security requirements and issues of operating systems
- Identify the requirements for establishing network security
- Compare different system security protection options
- Configure security settings for an IT system
- Describe the key aspects of security layers in an IT environment
- Explain the requirements and issues associated with operating system security
- Identify the requirements for establishing a secure network
- Evaluate system security protection options to mitigate risks
- Configure security settings for IT systems according to given specifications
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Describe the layers of security and their roles in protecting IT systems
- Explain the requirements and issues associated with operating system security
- Identify the requirements for establishing network security
- Compare different system protection options
- Configure security settings for an IT system to meet given requirements
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
Assessment Criteria
Key criteria assessors look for in your portfolio
- Describe the key aspects of security layers (physical, network, etc.).
- Explain requirements for operating system security (e.g., updates, user accounts).
- Identify network security measures (firewalls, encryption).
- Configure security settings on an IT system (e.g., antivirus, permissions).
- Award credit for correctly identifying the layers of security (e.g., physical, network, host, application, data)
- Award credit for explaining OS security issues such as vulnerabilities, patches, and user access controls
- Award credit for listing network security requirements like firewalls, encryption, and access control lists
- Award credit for comparing protection options such as antivirus, anti-malware, and intrusion detection systems
- Award credit for demonstrating practical configuration of security settings (e.g., setting up a firewall, enabling encryption)
- Award credit for accurately identifying and explaining the different security layers (e.g., physical, network, application)
- Marks should be given for demonstrating understanding of OS security features such as user account control, file permissions, and update management
- Credit should be awarded for correctly setting up a basic firewall rule or configuring wireless network security in a practical task
- Look for evidence of selecting and justifying appropriate system protection tools like antivirus, encryption, or backup solutions
- Ensure practical configuration tasks include steps such as creating secure user accounts, applying security policies, and testing configurations
- Identify the key layers of IT security (physical, network, application, etc.).
- Describe operating system security requirements and issues.
- Explain network security requirements and common threats.
- Configure security settings for an IT system.
- Identifies key aspects of security layers (physical, network, application).
- Explains requirements and issues of operating system security.
- Describes requirements to establish network security.
- Identifies protection options for system security.
- Configures security settings for IT systems appropriately.
- Explain security layers (physical, network, application).
- Describe operating system security features (user accounts, updates).
- Identify network security measures (firewalls, encryption).
- Configure security settings such as antivirus and permissions.
- Understand the importance of security policies.
- Award credit for accurately describing each security layer and its purpose
- Award credit for identifying specific OS security features such as user authentication, patch management, and file permissions
- Award credit for explaining network security measures like firewalls, encryption, and access controls
- Award credit for comparing protection options such as antivirus, anti-malware, and encryption tools
- Award credit for demonstrating correct configuration of security settings in a practical context
- Identifies key aspects of security layers (physical, network, etc.).
- Explains requirements and issues of OS security.
- Describes requirements for network security.
- Lists protection options for system security.
- Configures security settings correctly on IT systems.
Assessment Guidance
Guidance for achieving higher grades
- 💡Remember the CIA triad: Confidentiality, Integrity, Availability.
- 💡Use the principle of least privilege when setting permissions.
- 💡Keep software updated to patch vulnerabilities.
- 💡Use real-world examples to illustrate security layers and their interactions
- 💡When configuring security, always document the steps and justify each configuration choice
- 💡Remember to consider both technical and procedural security measures
- 💡Practice configuring security settings in a virtual environment to gain confidence
- 💡For practical assessments, always document each configuration step with screenshots and explanations to demonstrate competence
- 💡When discussing security layers, use real-world analogies to show depth of understanding
- 💡In theory questions, always relate security measures to the CIA triad (Confidentiality, Integrity, Availability) to gain higher marks
- 💡Practice configuring security settings on various operating systems (Windows, Linux) and network devices to be versatile
- 💡When asked to evaluate protection options, compare at least two methods and justify your choice based on cost, effectiveness, and ease of use
- 💡Know the CIA triad: Confidentiality, Integrity, Availability.
- 💡Understand common attack types (e.g., phishing, malware).
- 💡Practice configuring firewalls and user permissions.
- 💡Use real-world examples of security breaches.
- 💡Understand the principle of defence in depth.
- 💡Practice configuring security settings in a lab environment.
- 💡Learn the CIA triad (Confidentiality, Integrity, Availability).
- 💡Practice configuring Windows security settings.
- 💡Understand common threats like malware and phishing.
- 💡Use real-world examples to illustrate security concepts
- 💡Practice configuring security settings in a virtual environment
- 💡Understand the 'defense in depth' approach and be able to explain its benefits
- 💡Review common security threats and how each layer mitigates them
- 💡Ensure you can justify your security configuration choices in assessments
- 💡Learn common security threats and their mitigations.
- 💡Practice configuring security settings in a lab environment.
- 💡Understand the principle of defence in depth.
- 💡When answering questions about networking, always refer to the OSI model layers and give specific examples of protocols at each layer. This demonstrates depth of understanding and can earn you higher marks.
- 💡In programming tasks, show your working by including comments in your code and explaining your logic. Examiners look for clear, well-structured code that is easy to follow, not just correct output.
- 💡For database questions, always normalise your tables to at least third normal form (3NF) unless the question specifies otherwise. This shows you understand how to eliminate redundancy and maintain data integrity.
Common Mistakes
Common errors to avoid in your coursework
- Confusing authentication with authorisation.
- Neglecting physical security measures like locked server rooms.
- Using weak passwords or default settings.
- Confusing the layers of security with types of security controls
- Overlooking the importance of physical security as part of the security layers
- Assuming that antivirus software alone is sufficient for system protection
- Misconfiguring firewall rules, leading to either overly permissive or overly restrictive access
- Confusing authentication (verifying identity) with authorization (granting access)
- Overlooking the importance of physical security as part of the security layers
- Assuming that a firewall alone is sufficient for network security without considering additional measures like intrusion detection
- Failing to keep operating systems and security software updated, leaving vulnerabilities unpatched
- Misconfiguring permissions by granting excessive privileges to users or applications
- Neglecting physical security measures.
- Using weak passwords or default configurations.
- Failing to keep software updated.
- Confusing different security layers and their purposes.
- Neglecting physical security in favour of technical controls.
- Misconfiguring firewall or antivirus settings.
- Thinking antivirus alone is sufficient.
- Using weak passwords or default settings.
- Neglecting to apply updates regularly.
- Confusing security layers with security types (e.g., physical vs. network)
- Overlooking the importance of user education as a security layer
- Assuming that a single security measure is sufficient for complete protection
- Misconfiguring firewall rules, leading to either excessive blocking or vulnerabilities
- Neglecting to document security configurations for future reference
- Confusing different security layers.
- Overlooking the importance of physical security.
- Misconfiguring firewall or antivirus settings.
- Misconception: 'Networking is just about connecting computers.' Correction: Networking involves complex protocols, addressing schemes, and security considerations. Understanding the OSI model and how data is encapsulated at each layer is crucial for troubleshooting and design.
- Misconception: 'SQL is only about SELECT queries.' Correction: SQL includes DDL (Data Definition Language) for creating and modifying database structures, DML (Data Manipulation Language) for data operations, and DCL (Data Control Language) for permissions. A full understanding requires knowledge of all these aspects.
- Misconception: 'Programming is just writing code.' Correction: Programming involves problem-solving, algorithm design, testing, and debugging. Writing code is only one part; understanding logic, data structures, and efficient algorithms is equally important.
Frequently Asked Questions
Common questions students ask about this topic
Pass / Merit / Distinction Evidence Checklist
How your portfolio evidence is graded for CITY & GUILDS LIMITED IT security fundamentals
Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.
Demonstrate baseline knowledge, accurate terminology, and core practical application.
Provide detailed analysis, structured explanations, and clear workplace reasoning.
Deliver thorough evaluation, original problem solving, and fully justified recommendations.
Before You Start
Prior knowledge that will help with this topic
- •Basic understanding of computer hardware and software components, such as being able to identify parts of a computer and explain their functions.
- •Familiarity with mathematical concepts like binary, hexadecimal, and basic algebra, as these are used in networking (IP addressing) and programming (logic and calculations).
- •Some experience with using a computer for everyday tasks (file management, internet browsing) is assumed, but no prior programming or networking knowledge is required.
Coursework AI Review
Paste your assignment brief and check your draft against its P/M/D criteria
Key Terminology
Essential terms to know
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Layered security architecture
- Operating system hardening
- Network security fundamentals
- System protection mechanisms
- Security configuration best practices
- Security layering models
- Operating system security requirements
- Network security establishment
- System protection mechanisms
- Practical security configuration
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
- Security layers and defense in depth
- Operating system security requirements
- Network security fundamentals
- System protection options
- Configuration of security settings
- Know key aspect of security layers, Know requirements and issues of operating systems security, Know requirements to establish network security, Know protection options of system security, Be able to configure security for IT systems
Ready to learn?
AI-powered learning tailored to this unit