Principles of ICT system and data security

    CITY & GUILDS LIMITED
    Vocational

    This topic covers principles of ICT system and data security, including common threats, protection methods, and cryptography applications. It provides a foundation for securing systems and data.

    8
    Learning Outcomes
    24
    Assessment Guidance
    24
    Key Skills
    8
    Key Terms
    33
    Assessment Criteria

    Assessment criteria

    City & Guilds Level 4 Diploma For ICT Professionals (Systems and Principles)
    City & Guilds Level 2 Award in ICT Systems and Principles
    City & Guilds Level 2 Diploma in ICT Systems and Principles for IT Professionals
    City & Guilds Level 3 Diploma in ICT Systems Support
    City & Guilds Level 3 Diploma in ICT Systems and Principles for IT Professionals
    City & Guilds Level 2 Certificate in ICT Systems Support
    City & Guilds Level 3 Certificate in ICT Systems and Principles
    City & Guilds Level 2 Diploma in ICT Systems Support

    Topic Overview

    The City & Guilds Level 2 Diploma in ICT Systems Support provides a comprehensive foundation for students aspiring to work in IT support roles. This qualification covers essential skills such as installing and configuring hardware and software, maintaining computer networks, and providing user support. It is designed to equip learners with the practical knowledge needed to troubleshoot common IT issues and understand the principles of system security.

    Throughout the course, students engage with real-world scenarios that mirror the challenges faced by IT support technicians. Topics include understanding computer components, operating systems, networking fundamentals, and customer service skills. The diploma also emphasizes health and safety practices and the importance of data protection, preparing students for entry-level positions in IT support or further study in more advanced qualifications.

    This qualification is part of the wider ICT professional pathway and is recognized by employers across various industries. By completing this diploma, students demonstrate their ability to work effectively in a technical support environment, making them valuable assets to any organization's IT department.

    Key Concepts

    Core ideas you must understand for this topic

    • Hardware and software installation: Understanding how to install, configure, and troubleshoot computer components and operating systems.
    • Networking fundamentals: Knowledge of network topologies, protocols (e.g., TCP/IP), and how to set up and maintain local area networks (LANs).
    • User support and communication: Developing effective communication skills to assist users with technical issues, including remote support techniques.
    • System security: Implementing basic security measures such as antivirus software, firewalls, and password policies to protect data and systems.
    • Health and safety: Applying health and safety regulations when working with ICT equipment, including proper cable management and workstation ergonomics.

    Learning Objectives

    What you need to know and understand

    • Understand the common types of threat to ICT systems and data, Understand how to protect ICT systems, Understand the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data

    Assessment Criteria

    Key criteria assessors look for in your portfolio

    • Identify common threats such as malware, phishing, and DDoS attacks.
    • Explain methods to protect ICT systems (firewalls, antivirus, access controls).
    • Describe the principles of cryptography (encryption, hashing, digital signatures).
    • Apply cryptographic techniques to secure data in transit and at rest.
    • Award credit for demonstrating the ability to accurately classify and describe at least three distinct types of threat (e.g., phishing, ransomware, Trojan horse) with real-world examples.
    • Look for evidence of matching specific protection methods to identified threats—for instance, explaining how firewalls mitigate unauthorised access or how regular patching reduces vulnerability exploitation.
    • Expect learners to explain the basic principles of encryption (plaintext to ciphertext) and differentiate between symmetric and asymmetric encryption in a practical context, such as secure online transactions.
    • Identify common threats such as malware, phishing, and unauthorised access.
    • Describe methods to protect ICT systems, including firewalls and antivirus.
    • Explain the applications of cryptography, such as encryption and digital signatures.
    • Implement basic security practices like password policies.
    • Identify common threats to ICT systems and data (e.g., malware, phishing).
    • Describe methods to protect ICT systems (e.g., firewalls, antivirus, access controls).
    • Explain the principles of cryptography (encryption, decryption, hashing).
    • Describe applications of cryptography (e.g., secure communications, digital signatures).
    • Discuss the importance of data security policies.
    • Identifies common threats to ICT systems and data.
    • Describes methods to protect ICT systems.
    • Explains applications of cryptography.
    • Evaluates the effectiveness of security measures.
    • Identifies common threats to ICT systems and data.
    • Describes methods to protect ICT systems.
    • Explains applications of cryptography.
    • Recognises the importance of security policies.
    • Identify common threats to ICT systems and data.
    • Describe protection methods such as antivirus, firewalls, and backups.
    • Explain the role of cryptography in securing data.
    • Distinguish between symmetric and asymmetric encryption.
    • Apply appropriate security measures to given scenarios.
    • Identify common threats such as malware, phishing, and social engineering.
    • Describe methods to protect ICT systems including firewalls and antivirus.
    • Explain the principles of symmetric and asymmetric cryptography.
    • Apply basic cryptographic techniques to secure data.

    Assessment Guidance

    Guidance for achieving higher grades

    • 💡Learn the differences between types of malware and attack vectors.
    • 💡Understand how encryption keys are managed.
    • 💡Study real-world security breaches and their causes.
    • 💡When answering scenario-based questions, explicitly connect each control measure (e.g., backup strategy) to the impact it reduces (e.g., data loss from ransomware).
    • 💡Use appropriate technical vocabulary—terms like 'authentication', 'authorisation', and 'non-repudiation' demonstrate deeper understanding and gain marks.
    • 💡In cryptography questions, reference typical key lengths (e.g., AES-256) and mention real-world use cases like TLS for secure web browsing to show applied knowledge.
    • 💡Learn the CIA triad (Confidentiality, Integrity, Availability).
    • 💡Understand symmetric vs asymmetric encryption.
    • 💡Know common security tools and their purposes.
    • 💡Use real-world examples of security breaches.
    • 💡Understand the CIA triad: Confidentiality, Integrity, Availability.
    • 💡Be able to explain how cryptography protects data at rest and in transit.
    • 💡Stay updated on current cyber threats.
    • 💡Understand basic cryptographic concepts.
    • 💡Use real-world examples of security breaches.
    • 💡Use examples like phishing or ransomware.
    • 💡Explain cryptography in simple terms.
    • 💡Mention best practices like regular updates.
    • 💡Use real-world examples to illustrate threats and protections.
    • 💡Remember that cryptography ensures confidentiality, integrity, and authenticity.
    • 💡Practice matching security measures to specific threats.
    • 💡Learn the difference between threats, vulnerabilities, and risks.
    • 💡Understand the CIA triad (Confidentiality, Integrity, Availability).
    • 💡Practice identifying phishing emails.
    • 💡When answering questions about troubleshooting, always follow a logical step-by-step process: identify the problem, establish a theory of probable cause, test the theory, implement a solution, verify functionality, and document findings. This structured approach demonstrates methodical thinking.
    • 💡For networking questions, ensure you can explain the difference between a hub, switch, and router, and know when each is used. Practical examples, such as setting up a small office network, can help illustrate your understanding.
    • 💡In user support scenarios, emphasize the importance of active listening and clear communication. Examiners look for evidence that you can adapt your language to the user's technical level and provide instructions that are easy to follow.

    Common Mistakes

    Common errors to avoid in your coursework

    • Confusing symmetric and asymmetric encryption.
    • Underestimating the importance of physical security.
    • Failing to keep software and systems up to date.
    • Confusing viruses with worms—viruses require a host program to spread, while worms self-replicate independently across networks.
    • Assuming that data encryption alone protects against all threats, neglecting the need for physical security or user access controls.
    • Misunderstanding that a strong password policy is sufficient without multi-factor authentication, ignoring additional layers of defence against credential theft.
    • Confusing encryption with hashing.
    • Underestimating social engineering threats.
    • Neglecting physical security measures.
    • Confusing encryption with hashing.
    • Overlooking human factors in security (e.g., social engineering).
    • Failing to differentiate between symmetric and asymmetric encryption.
    • Confusing threats with vulnerabilities.
    • Overlooking social engineering attacks.
    • Misunderstanding encryption vs hashing.
    • Confusing encryption with hashing.
    • Underestimating social engineering threats.
    • Thinking antivirus alone is sufficient protection.
    • Confusing threats with vulnerabilities.
    • Overlooking social engineering as a threat.
    • Misunderstanding the difference between encryption and hashing.
    • Confusing encryption with hashing.
    • Underestimating the importance of physical security.
    • Failing to keep software updated against vulnerabilities.
    • Misconception: IT support only involves fixing hardware issues. Correction: IT support also includes software troubleshooting, network configuration, user training, and maintaining security protocols.
    • Misconception: All network problems are caused by hardware failures. Correction: Many network issues stem from software misconfigurations, IP address conflicts, or incorrect DNS settings, which require systematic troubleshooting.
    • Misconception: Data backup is optional for small businesses. Correction: Data loss can occur due to hardware failure, malware, or human error; regular backups are essential for all organizations to ensure business continuity.

    Frequently Asked Questions

    Common questions students ask about this topic

    Pass / Merit / Distinction Evidence Checklist

    How your portfolio evidence is graded for CITY & GUILDS LIMITED Principles of ICT system and data security

    Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.

    Pass (P)

    Demonstrate baseline knowledge, accurate terminology, and core practical application.

    Merit (M)

    Provide detailed analysis, structured explanations, and clear workplace reasoning.

    Distinction (D)

    Deliver thorough evaluation, original problem solving, and fully justified recommendations.

    Before You Start

    Prior knowledge that will help with this topic

    • Basic understanding of computer hardware components (e.g., CPU, RAM, hard drive) and their functions.
    • Familiarity with common operating systems like Windows or macOS, including basic file management and system settings.
    • Elementary knowledge of networking concepts such as IP addresses and internet connectivity.

    Coursework AI Review

    Paste your assignment brief and check your draft against its P/M/D criteria

    Key Terminology

    Essential terms to know

    • Understand the common types of threat to ICT systems and data, Understand how to protect ICT systems, Understand the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data
    • Know the common types of threat to ICT systems and data, Know how to protect ICT systems, Be aware of the applications of cryptography to ICT systems and data

    Ready to learn?

    AI-powered learning tailored to this unit