Securing ICT systems and networks
This unit covers securing ICT systems and networks, including network security, operational security, threat discovery, data host security, access control, and cryptography.
Assessment criteria
Topic Overview
The City & Guilds Level 3 Certificate in ICT Systems and Principles provides a comprehensive foundation in information and communication technology, covering both theoretical concepts and practical skills. This qualification is designed for students who wish to develop a deep understanding of how ICT systems operate, including hardware, software, networking, and security. It is ideal for those pursuing careers in IT support, systems administration, or further study in computer science.
The course is structured around key areas such as computer architecture, operating systems, data communications, and the principles of programming. Students learn to analyse system requirements, troubleshoot issues, and implement solutions in real-world contexts. The qualification emphasises both technical competence and the ability to communicate effectively about ICT systems, preparing students for the demands of the modern digital workplace.
This certificate is part of the wider City & Guilds ICT suite and is recognised by employers and higher education institutions. It bridges the gap between foundational ICT skills and advanced technical qualifications, making it a valuable stepping stone for progression to higher-level study or apprenticeships in the IT sector.
Key Concepts
Core ideas you must understand for this topic
- →Computer architecture: Understanding the components of a computer system, including the CPU, memory, storage, and input/output devices, and how they interact.
- →Operating systems: The role of operating systems in managing hardware resources, providing user interfaces, and supporting application software.
- →Networking fundamentals: Concepts such as IP addressing, protocols (TCP/IP), network topologies, and the OSI model.
- →Data security: Principles of protecting data integrity, confidentiality, and availability, including encryption, authentication, and backup strategies.
- →Programming principles: Basic programming constructs (sequence, selection, iteration), data types, and the software development lifecycle.
Learning Objectives
What you need to know and understand
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Implement network security measures to protect against unauthorized access
- Apply operational security procedures in an ICT environment
- Discover threats and vulnerabilities in ICT systems
- Implement data host security controls
- Configure access control mechanisms
- Apply cryptographic techniques to secure data
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
Assessment Criteria
Key criteria assessors look for in your portfolio
- Implement network security measures (firewalls, VLANs).
- Configure access control lists and permissions.
- Identify and mitigate common threats.
- Apply cryptographic techniques (encryption, hashing).
- Implement network security measures (firewalls, VPNs).
- Implement operational security in an ICT environment.
- Discover threats and vulnerabilities using tools.
- Implement data host security (antivirus, patching).
- Configure access control (user accounts, permissions).
- Implement cryptography (encryption, hashing).
- Implement network security measures such as firewalls and VPNs.
- Apply operational security procedures in an ICT environment.
- Identify and assess threats and vulnerabilities.
- Configure access control mechanisms (e.g., permissions, authentication).
- Implement cryptography to protect data.
- Implement network security using firewalls and VLANs.
- Configure access control lists and user permissions.
- Identify common threats and vulnerabilities.
- Apply cryptography for data protection.
- Implement data host security measures.
- Correctly implements firewalls, IDS/IPS, and VPNs.
- Applies access control principles such as least privilege.
- Uses cryptographic methods appropriately for data protection.
- Conducts vulnerability assessments and threat analysis.
- Documents security measures and incident response procedures.
- Implements network security measures such as firewalls and VPNs.
- Configures access control lists and user permissions.
- Identifies and mitigates common threats and vulnerabilities.
- Applies cryptographic techniques to protect data.
- Monitors and maintains operational security procedures.
- Implements network security measures such as firewalls and VLANs.
- Applies operational security procedures like user training and policies.
- Identifies threats and vulnerabilities using appropriate tools.
- Configures access control based on the principle of least privilege.
- Award credit for demonstrating correct configuration of firewall rules and network segmentation.
- Award credit for showing evidence of applying security policies and procedures in operational tasks.
- Award credit for using appropriate tools to identify and document vulnerabilities.
- Award credit for implementing host-based security measures such as antivirus and patch management.
- Award credit for setting up user accounts with appropriate permissions and authentication methods.
- Award credit for correctly applying encryption methods to protect data at rest and in transit.
- Implements network security measures such as firewalls and VPNs.
- Configures access control lists and user permissions.
- Identifies and mitigates common threats and vulnerabilities.
- Applies cryptographic techniques to protect data.
- Implement network security measures such as firewalls and VLANs.
- Apply operational security practices like patch management and user training.
- Discover threats and vulnerabilities using scanning tools.
- Configure access control lists and authentication methods.
- Implement cryptography for data protection.
Assessment Guidance
Guidance for achieving higher grades
- 💡Understand the CIA triad (confidentiality, integrity, availability).
- 💡Practice setting up basic firewall rules.
- 💡Know common attack types (phishing, DDoS).
- 💡Understand the CIA triad (Confidentiality, Integrity, Availability).
- 💡Practice using vulnerability scanning tools.
- 💡Know common encryption algorithms and their uses.
- 💡Use practical examples of security implementations.
- 💡Explain the principle of least privilege in access control.
- 💡Discuss the importance of defence in depth.
- 💡Understand the CIA triad (Confidentiality, Integrity, Availability).
- 💡Practice configuring a basic firewall.
- 💡Know the difference between symmetric and asymmetric encryption.
- 💡Practice configuring a small network with security features.
- 💡Understand common attack vectors and how to mitigate them.
- 💡Be prepared to explain the rationale behind security choices.
- 💡Understand the CIA triad (Confidentiality, Integrity, Availability).
- 💡Practise using security tools like Wireshark or Nmap.
- 💡Keep up to date with current cyber threats.
- 💡Know the difference between symmetric and asymmetric encryption.
- 💡Understand common attack types like phishing and DDoS.
- 💡Always consider the CIA triad (Confidentiality, Integrity, Availability).
- 💡Understand the difference between symmetric and asymmetric encryption and when to use each.
- 💡Practice configuring access control lists (ACLs) and user permissions in a simulated environment.
- 💡Learn common vulnerability scanning tools and how to interpret their reports.
- 💡Memorize key security principles like least privilege and defense in depth.
- 💡Review case studies of security breaches to understand real-world application of concepts.
- 💡Stay updated on common cyber threats.
- 💡Practice configuring security settings in a lab environment.
- 💡Understand the principle of least privilege.
- 💡Practice configuring firewalls and access controls in a lab.
- 💡Stay updated on common vulnerabilities and exploits.
- 💡Understand the principle of least privilege.
- 💡When answering questions about system components, always use specific technical terms (e.g., 'clock speed' instead of 'speed') and explain how they contribute to performance. This demonstrates depth of knowledge.
- 💡For networking questions, draw diagrams to illustrate topologies or data flow. Even rough sketches can help clarify your answer and show the examiner you understand the concepts.
- 💡In programming questions, show your working and comment on your code. Explain why you chose a particular approach, as this can earn marks even if the code has minor errors.
Common Mistakes
Common errors to avoid in your coursework
- Confusing authentication with authorisation.
- Overlooking physical security.
- Misconfiguring firewall rules.
- Weak password policies or default credentials.
- Failing to patch systems regularly.
- Misconfiguring firewall rules.
- Confusing encryption with hashing or encoding.
- Neglecting physical security measures.
- Failing to update security patches regularly.
- Leaving default passwords unchanged.
- Not updating security patches regularly.
- Misconfiguring firewall rules.
- Confusing symmetric and asymmetric encryption.
- Neglecting to update security patches regularly.
- Overlooking physical security aspects of network devices.
- Weak password policies or default configurations.
- Failing to update software and patch vulnerabilities.
- Misconfiguring firewall rules, leaving gaps in security.
- Using weak passwords or default credentials.
- Failing to encrypt sensitive data in transit and at rest.
- Overlooking physical security measures for ICT equipment.
- Confusing authentication with authorization.
- Neglecting to update security patches regularly.
- Overlooking physical security measures as part of operational security.
- Using weak encryption algorithms or misconfiguring encryption settings.
- Failing to document security configurations and procedures.
- Using weak passwords or default configurations.
- Neglecting to patch software regularly.
- Failing to encrypt sensitive data in transit or at rest.
- Leaving default passwords or configurations unchanged.
- Failing to segment networks properly.
- Overlooking physical security measures.
- Misconception: 'The CPU is the only component that affects computer speed.' Correction: While the CPU is crucial, factors like RAM speed, storage type (SSD vs HDD), and graphics card also significantly impact overall system performance.
- Misconception: 'Networking and the internet are the same thing.' Correction: Networking refers to connecting multiple devices locally (LAN), while the internet is a global network of networks. Understanding the distinction is key for troubleshooting and design.
- Misconception: 'Encryption makes data completely secure.' Correction: Encryption protects data from unauthorised access, but it does not prevent data loss or destruction. Backup and access controls are also essential for comprehensive security.
Frequently Asked Questions
Common questions students ask about this topic
Pass / Merit / Distinction Evidence Checklist
How your portfolio evidence is graded for CITY & GUILDS LIMITED Securing ICT systems and networks
Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.
Demonstrate baseline knowledge, accurate terminology, and core practical application.
Provide detailed analysis, structured explanations, and clear workplace reasoning.
Deliver thorough evaluation, original problem solving, and fully justified recommendations.
Before You Start
Prior knowledge that will help with this topic
- •Basic understanding of computer hardware and software, typically from a Level 2 ICT qualification or GCSE Computer Science.
- •Familiarity with common operating systems (Windows, Linux) and basic file management.
- •Elementary mathematics, including binary and hexadecimal number systems, as these are used in addressing and data representation.
Coursework AI Review
Paste your assignment brief and check your draft against its P/M/D criteria
Key Terminology
Essential terms to know
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Network security implementation
- Operational security procedures
- Threat and vulnerability discovery
- Data host security
- Access control configuration
- Cryptography fundamentals
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
- Be able to implement network security, Be able to implement operational security in an ICT environment, Be able to dicover threats and vulnerabilities, Be able to implement data host security, Be able to configure access control, Be able to implement cryptography
Ready to learn?
AI-powered learning tailored to this unit