Security of ICT Systems
This topic covers security of ICT systems, including common threats, protection methods, and monitoring procedures. Learners apply security measures to protect organisational data and systems.
Assessment criteria
Topic Overview
The City & Guilds Level 2 Diploma in ICT Professional Competence is a vocational qualification designed to equip students with the practical skills and theoretical knowledge needed for a career in ICT. This diploma covers a broad range of topics, including computer hardware, software applications, networking, database management, and web development. It emphasises hands-on experience, preparing students for roles such as IT support technician, network administrator, or web developer. The qualification is recognised by employers and can lead to further study, such as a Level 3 diploma or an apprenticeship.
This diploma is structured around core units that build a solid foundation in ICT. Students learn to install and configure hardware and software, set up and maintain networks, create and manage databases, and develop websites using HTML and CSS. The course also covers essential professional skills like problem-solving, communication, and teamwork. By the end of the diploma, students will have a portfolio of practical projects demonstrating their competence, which is invaluable for job applications and interviews.
In the wider context of computer science, this diploma provides a practical counterpart to more theoretical qualifications. While A-level Computer Science focuses on algorithms and programming theory, the City & Guilds diploma emphasises real-world application. It is ideal for students who prefer a hands-on approach and want to enter the workforce quickly. The skills gained are directly transferable to many ICT roles, making it a popular choice for those aiming for immediate employment or further vocational training.
Key Concepts
Core ideas you must understand for this topic
- →Hardware and Software Installation: Understanding how to install, configure, and troubleshoot operating systems (e.g., Windows, Linux) and application software, as well as hardware components like RAM, hard drives, and peripherals.
- →Networking Fundamentals: Knowledge of network topologies (star, bus, ring), protocols (TCP/IP, DHCP, DNS), and devices (routers, switches, hubs). Students learn to set up a small local area network (LAN) and configure IP addresses.
- →Database Design and Management: Creating relational databases using SQL, normalising data to reduce redundancy, and performing queries to retrieve and manipulate data. Understanding primary keys, foreign keys, and relationships.
- →Web Development: Building static websites using HTML5 and CSS3, including structuring content with semantic elements, styling with CSS, and ensuring basic accessibility and responsiveness.
- →Health and Safety in ICT: Applying ergonomic principles to prevent repetitive strain injury (RSI) and eye strain, understanding electrical safety when handling hardware, and following data protection regulations (GDPR).
Learning Objectives
What you need to know and understand
- Know the common types of security threat to an organisation, its IT system and its data, with relevant methods and procedures for protecting it., Apply security measures, Monitor security procedures
- Know the common types of security threat to an organisation, its IT system and its data, with relevant methods and procedures for protecting it., Apply security measures, Monitor security procedures
Assessment Criteria
Key criteria assessors look for in your portfolio
- Identify common types of security threats to ICT systems.
- Describe methods and procedures for protecting systems and data.
- Apply security measures such as access controls and encryption.
- Monitor security procedures and respond to incidents.
- Explain the importance of security policies and user training.
- Identify common security threats and their impacts.
- Describe methods to protect ICT systems and data.
- Apply security measures like password policies and access controls.
- Monitor security procedures and respond to incidents.
Assessment Guidance
Guidance for achieving higher grades
- 💡Use the CIA triad (Confidentiality, Integrity, Availability) as a framework.
- 💡Give examples of security measures for different threat types.
- 💡Show understanding of the incident response process.
- 💡Learn the CIA triad (Confidentiality, Integrity, Availability).
- 💡Practise configuring basic firewall rules.
- 💡Understand the importance of regular backups.
- 💡When answering questions about hardware installation, always mention safety precautions (e.g., anti-static wrist strap) and verification steps (e.g., checking device manager). This shows you understand professional practice.
- 💡For networking questions, draw diagrams to illustrate topologies or data flow. Labelling components and protocols (e.g., 'router using NAT') can earn you marks for clarity and technical accuracy.
- 💡In database tasks, normalise your tables to at least third normal form (3NF) and explain why you chose certain primary keys. Examiners look for logical design that minimises redundancy and ensures data consistency.
Common Mistakes
Common errors to avoid in your coursework
- Underestimating social engineering threats like phishing.
- Neglecting physical security of servers and devices.
- Failing to keep software and patches up to date.
- Confusing threats like viruses with phishing.
- Overlooking physical security measures.
- Failing to document security incidents properly.
- Misconception: 'Installing software is just clicking Next.' Correction: Proper installation involves checking system requirements, managing licences, configuring settings for user needs, and testing functionality. Skipping steps can lead to security vulnerabilities or software conflicts.
- Misconception: 'All networks are the same.' Correction: Networks vary in scale (LAN, WAN), topology (star vs. mesh), and security requirements. A home network is simpler than a corporate one with VLANs and firewalls. Understanding these differences is crucial for troubleshooting.
- Misconception: 'Databases are just spreadsheets.' Correction: Databases use structured query language (SQL) for efficient data retrieval and maintain data integrity through relationships and constraints. Unlike spreadsheets, they support concurrent multi-user access and complex queries.
Frequently Asked Questions
Common questions students ask about this topic
Pass / Merit / Distinction Evidence Checklist
How your portfolio evidence is graded for CITY & GUILDS LIMITED Security of ICT Systems
Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.
Demonstrate baseline knowledge, accurate terminology, and core practical application.
Provide detailed analysis, structured explanations, and clear workplace reasoning.
Deliver thorough evaluation, original problem solving, and fully justified recommendations.
Before You Start
Prior knowledge that will help with this topic
- •Basic computer literacy: familiarity with using a computer, managing files, and browsing the internet.
- •Foundational maths skills: understanding of binary, hexadecimal, and basic arithmetic for IP addressing and data storage calculations.
- •Communication skills: ability to write clear instructions and document technical processes, as the diploma includes report writing and presentations.
Coursework AI Review
Paste your assignment brief and check your draft against its P/M/D criteria
Key Terminology
Essential terms to know
- Know the common types of security threat to an organisation, its IT system and its data, with relevant methods and procedures for protecting it., Apply security measures, Monitor security procedures
- Know the common types of security threat to an organisation, its IT system and its data, with relevant methods and procedures for protecting it., Apply security measures, Monitor security procedures
Ready to learn?
AI-powered learning tailored to this unit