IT Security for Users

    CITY & GUILDS LIMITED
    Vocational

    This unit focuses on minimising security risks to IT systems and data. Learners must use appropriate methods to protect against threats such as malware, phishing, and unauthorised access.

    13
    Learning Outcomes
    26
    Assessment Guidance
    32
    Key Skills
    13
    Key Terms
    33
    Assessment Criteria

    Assessment criteria

    City & Guilds Level 2 Diploma in IT User Skills
    City & Guilds Level 3 Award for IT Users (ITQ)
    City & Guilds Level 2 Award for IT Users (ITQ)
    City & Guilds Level 2 Certificate for IT Users (ITQ)
    City & Guilds Level 3 Certificate for IT Users (ITQ)
    City & Guilds Level 2 Diploma for IT Users (ITQ)
    City & Guilds Level 3 Diploma in IT User Skills
    City & Guilds Level 3 Diploma for IT Users (ITQ)

    Quick Revision Summary (Key Takeaway)

    The City & Guilds Level 3 Diploma in IT User Skills (VRQ) is a vocational qualification that develops advanced digital literacy and practical IT competencies for the modern workplace. It covers topics such as advanced word processing, spreadsheet modelling, database design, presentation software, and safe, secure IT use, preparing learners for employment or further study.

    Topic Overview

    The City & Guilds Level 3 Diploma in IT User Skills (VRQ) is designed to equip learners with advanced practical skills in using IT applications effectively and efficiently. It is a vocational qualification that focuses on real-world application, covering areas such as word processing, spreadsheets, databases, presentations, and using email and the internet. The diploma is recognised by employers and universities, demonstrating a high level of digital competence.

    This qualification is structured around mandatory and optional units, allowing learners to tailor their studies to their career aspirations. Core units include 'Word Processing Software', 'Spreadsheet Software', 'Database Software', and 'Presentation Software', while optional units may cover topics like 'IT Security', 'Website Software', or 'Project Management'. Assessment is typically through a portfolio of evidence, where learners complete practical tasks that are internally assessed and externally moderated.

    Mastering these skills is essential in today's digital workplace, as employers increasingly require staff who can manipulate data, produce professional documents, and manage information securely. The diploma not only teaches technical skills but also develops problem-solving, planning, and communication abilities, making it a valuable addition to any CV.

    Key Concepts

    Core ideas you must understand for this topic

    • Advanced formatting and mail merge in word processing
    • Use of complex formulas, functions, and what-if analysis in spreadsheets
    • Database design, relationships, and structured queries (SQL)
    • Creating dynamic and interactive presentations with multimedia elements
    • IT security best practices, including data protection and safe internet use

    Learning Objectives

    What you need to know and understand

    • Use appropriate methods to minimise security risks to IT systems and data
    • Select and use appropriate methods to minimise security risk to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Select and use appropriate methods to minimise security risk to IT systems and data
    • Identify common security threats to IT systems and confidential data
    • Explain the principles of effective password management and multi-factor authentication
    • Demonstrate the use of antivirus software and firewalls to prevent malware infections
    • Evaluate the risks associated with email attachments and web browsing and apply appropriate safeguards
    • Implement a regular data backup routine and describe recovery procedures
    • Apply encryption techniques to protect sensitive information during storage and transmission

    Assessment Criteria

    Key criteria assessors look for in your portfolio

    • Identify common security threats to IT systems.
    • Use strong passwords and authentication methods.
    • Apply software updates and antivirus protection.
    • Recognise and avoid phishing attempts.
    • Award credit for demonstrating the ability to conduct a risk assessment and justify the selection of security controls based on identified threats.
    • Award credit for accurately configuring and applying at least three distinct security methods (e.g., firewall settings, encryption, multi-factor authentication) to protect systems and data.
    • Award credit for providing clear, contextualised evidence of secure data handling, including backup procedures and compliant disposal of confidential information.
    • Award credit for demonstrating the creation of strong, unique passwords and explaining the risks of password reuse.
    • Credit given for correctly identifying phishing attempts and outlining appropriate response actions (e.g., not clicking links, reporting to IT).
    • Evidence should show understanding of keeping software updated and using antivirus/antimalware tools, including scheduled scans.
    • Learner must explain the importance of locking devices when unattended and using encryption for sensitive data.
    • Award credit for demonstrating the use of strong passwords and effective authentication procedures in a real or simulated scenario.
    • Look for evidence of identifying and responding to phishing attempts or other social engineering threats, with appropriate actions taken.
    • Credit should be given for explaining and applying safe internet practices, including secure browsing, recognising secure websites, and being cautious with downloads.
    • Assess the ability to maintain up-to-date anti-malware software and perform regular system scans, documenting the process or results.
    • Evidence of data backup procedures and an understanding of recovery methods must be present to confirm competence.
    • Award credit for demonstrating the configuration and use of appropriate access controls, such as implementing strong password policies and enabling multi-factor authentication.
    • Look for evidence of securely managing sensitive data, including regular backups, encryption of portable media, and secure deletion techniques appropriate to the storage type.
    • Credit responses that identify a range of common cyber threats (e.g., phishing, ransomware, shoulder surfing) and apply suitable preventative measures, such as email filtering and screen privacy filters.
    • Assessors should reward learners who show adherence to relevant legislation and organisational policies, particularly in areas like data protection (GDPR) and acceptable use of IT resources.
    • Award credit for demonstrating the ability to create and manage complex passwords using a combination of upper and lower case letters, numbers and symbols, and explaining the rationale.
    • Award credit for correctly identifying and describing at least three types of malware (e.g., virus, trojan, ransomware) and the corresponding preventive measures (e.g., antivirus, firewall, user awareness).
    • Provide evidence of configuring automatic updates for operating systems and applications, with a clear explanation of why this minimises vulnerabilities.
    • Demonstrate secure handling of portable storage devices by showing a process of scanning for viruses before transferring data and explaining the dangers of untrusted media.
    • Award credit for demonstrating a systematic risk assessment, identifying specific threats and vulnerabilities relevant to a given IT system or data environment.
    • Credit given for selecting and correctly implementing layered security measures, such as user access controls, anti-malware software, and firewalls, with clear justification for each choice.
    • Award credit for showing practical application of data protection techniques (e.g., encryption, secure backup, proper disposal) in line with relevant legislation like GDPR and organisational policies.
    • Credit for evidence of proactive security maintenance, such as applying updates and patches, monitoring for threats, and educating users on security best practice.
    • Award credit for correctly configuring a firewall to block unauthorised access
    • Expect evidence of scheduled backups with verification of data integrity
    • Credit demonstration of strong password creation (e.g., length, complexity, uniqueness)
    • Look for appropriate use of encryption tools, such as encrypting a file or email
    • Assess ability to identify phishing attempts in a simulated scenario

    Assessment Guidance

    Guidance for achieving higher grades

    • 💡Remember the principle of least privilege.
    • 💡Always lock your screen when away.
    • 💡Back up important data regularly.
    • 💡In practical assessments, always relate your chosen security methods to a realistic scenario, explaining why each is appropriate for the given risk rather than just listing features.
    • 💡For written assignments, structure your evidence around the Plan-Do-Review cycle: show how you identified risks, implemented measures, and then evaluated their effectiveness.
    • 💡Pay close attention to command verbs in assessment criteria—‘select and use’ means you must demonstrate both decision-making and hands-on application, not just describe theory.
    • 💡In assignments, always explain both the method and the security risk it minimises – don't just list actions.
    • 💡For practical tasks, demonstrate following organisational policies even if you know a quicker way – it shows compliance awareness.
    • 💡When describing security measures, reference real-world consequences of failures (e.g., data breach fines, identity theft) to show deeper understanding.
    • 💡Use technical terms accurately (e.g., 'two-factor authentication' rather than 'double password') to demonstrate professional competency.
    • 💡When providing evidence for assignments, use annotated screenshots or recordings to clearly show each step of the security method applied.
    • 💡Always relate your actions to the specific risk being mitigated, demonstrating understanding of the underlying threat and the chosen control.
    • 💡When answering scenario-based questions, explicitly link each security measure to the risk it mitigates and the potential impact of not implementing it.
    • 💡In practical assessments, document your actions step-by-step, explaining the rationale behind each decision to demonstrate underpinning knowledge.
    • 💡Reference real-world examples of security breaches to illustrate consequences and strengthen your analysis of why specific methods are essential.
    • 💡Ensure you cover all three pillars of security—confidentiality, integrity, and availability—when evaluating the effectiveness of a security method.
    • 💡In practical assessments, annotate screenshots to clearly highlight security settings, such as firewall status, update schedules, or antivirus scan results.
    • 💡When answering written questions, reference real-world security breach examples to illustrate the consequences of poor practices and the value of the methods being described.
    • 💡For portfolio evidence, include a risk assessment table that lists identified threats, their potential impact, and the specific security controls applied to mitigate them.
    • 💡Tailor your security selections to the exact scenario in the assignment; generic lists of measures without context will not achieve high marks.
    • 💡Include annotated screenshots or logs as practical evidence to demonstrate that you have applied the methods correctly.
    • 💡Reference current legislation, standards, and company policies to validate your choices and show professional awareness.
    • 💡Explain your decision-making process: compare alternative methods and justify your final selection based on criteria such as cost, user impact, and effectiveness.
    • 💡Provide specific, real-world examples of security breaches to strengthen scenario-based answers
    • 💡Differentiate clearly between types of malware (virus, worm, trojan, ransomware) in written responses
    • 💡Include a documented security policy as part of your portfolio to demonstrate comprehensive understanding
    • 💡Always read the question carefully to identify the exact software (e.g., Microsoft Word, Excel, Access) and the version, as features may vary.
    • 💡When asked to 'explain', provide a reason or justification, not just a description. Use 'because' to link your explanation to the outcome.
    • 💡In practical assessments, save your work regularly and name files as instructed. Check that your final output meets all the criteria in the marking checklist.

    Common Mistakes

    Common errors to avoid in your coursework

    • Using weak or reused passwords.
    • Clicking on suspicious links or attachments.
    • Ignoring software update notifications.
    • Learners often confuse logical security controls with physical security measures, or apply generic solutions without tailoring them to specific threats.
    • A frequent error is relying solely on antivirus software without implementing complementary measures like access controls or user education.
    • Many learners fail to address the human element, overlooking social engineering risks or neglecting to document procedures for reporting security incidents.
    • Confusing encryption with password protection or thinking that antivirus alone guarantees full security.
    • Using the same password across multiple accounts and believing that simple variations (e.g., Password1, Password2) are secure.
    • Clicking on links in unsolicited emails to verify legitimacy rather than independently navigating to the official website.
    • Assuming that a secure Wi-Fi network means all data transmitted is automatically safe without using HTTPS or VPNs.
    • Learners often believe that installing anti-virus software is sufficient for complete protection, neglecting other layers like firewalls or user awareness.
    • Many fail to appreciate the importance of regular software updates, leaving systems vulnerable to known exploits.
    • Using simple or repeated passwords across multiple accounts is a frequent error, undermining security despite other measures.
    • Confusing data backup with synchronization, leading to data loss when one copy is corrupted or deleted.
    • Over-reliance on passwords alone, neglecting supplementary controls like biometrics or one-time codes, which leaves accounts vulnerable to credential theft.
    • Failing to distinguish between authentication and authorisation, leading to incomplete access management solutions.
    • Ignoring physical security aspects such as leaving devices unattended, not using cable locks, or discarding hardware without data sanitisation.
    • Assuming that antivirus software alone is sufficient without updating signatures regularly or applying operating system patches promptly.
    • Assuming that antivirus software alone is sufficient for complete protection, neglecting other layers like firewalls and user education.
    • Using the same password across multiple accounts or writing down passwords in accessible locations.
    • Clicking on links or opening attachments in emails without verifying the sender's identity or checking for signs of phishing.
    • Failing to regularly back up data or test restoration procedures, leading to permanent data loss in case of ransomware or hardware failure.
    • Failing to match security measures to specific threat types, for example using a firewall to block phishing emails.
    • Overlooking physical security aspects, such as securing hardware, using privacy screens, or shredding sensitive documents.
    • Relying on a single security method (e.g., password only) without implementing a defence-in-depth strategy.
    • Not considering the importance of regular software updates and patch management as a fundamental security practice.
    • Confusing data backups with data security, neglecting that backups must also be secured to prevent unauthorised access.
    • Using the same password across multiple accounts
    • Neglecting to update antivirus definitions and operating system patches
    • Assuming encrypted data is automatically safe from all threats without considering key management
    • Failing to test backups, leading to unrecoverable data
    • Clicking on links or downloading attachments from unverified sources
    • Misconception: 'Validation and verification are the same thing.' Correction: Validation checks data against rules (e.g., range), verification checks data against the original source (e.g., double entry).
    • Misconception: 'Absolute cell references are always needed in formulas.' Correction: Only use absolute references when you want a cell reference to stay fixed; otherwise, relative references are appropriate.
    • Misconception: 'A primary key is just a unique identifier; it doesn't matter what field you choose.' Correction: The primary key must be unique and not null; choosing an inappropriate field (e.g., name) can cause issues.

    Revision Plan

    How to revise this topic in 1–2 weeks

    1. 1Week 1: Focus on word processing and presentation units. Practise advanced features like mail merge, macros, and slide transitions. Create a portfolio of sample documents.
    2. 2Week 2: Move to spreadsheets. Learn advanced formulas (IF, VLOOKUP, SUMIF), data validation, and chart creation. Complete practice exercises from past papers.
    3. 3Week 3: Study databases. Design tables, set relationships, and write queries. Use sample data to practise creating forms and reports.
    4. 4Week 4: Review all units, focusing on weak areas. Take timed mock assessments and check your answers against mark schemes. Revise IT security and legal issues.

    Exam Question Types

    How this topic typically appears in the exam

    • 📋Multiple-choice questions: Test knowledge of definitions, shortcuts, and best practices. Read each option carefully; eliminate obviously wrong answers first.
    • 📋Practical tasks: You will be given a scenario and asked to produce a document, spreadsheet, or database. Follow the instructions exactly, and save your work in the correct format.
    • 📋Short-answer questions: Require you to explain a concept or describe a process. Use bullet points if helpful, and include technical terms accurately.
    • 📋Extended writing: May ask you to evaluate the use of a particular software feature or discuss security implications. Structure your answer with an introduction, points for and against, and a conclusion.

    Command Word Expectations (CITY & GUILDS LIMITED)

    What examiners look for when using specific command words in this specification

    Evaluate

    In City & Guilds exams, 'evaluate' requires you to consider the strengths and weaknesses of a solution or approach, and make a judgement. You must provide evidence and reasoning for your conclusion. For example, evaluate the use of a relational database over a flat file database.

    Explain

    You must give a clear account of how or why something happens, including reasons and causes. For example, explain the purpose of a primary key in a database. Simply stating a fact is not enough; you must show understanding of the underlying principles.

    Describe

    You need to give a detailed account of the features or characteristics of something. For example, describe the features of a mail merge. You should list and elaborate on each feature, but you do not need to justify why they are used.

    How Students Lose Marks (Examiner Pitfalls)

    Common mark loss traps and how to write 100% full-mark answers

    Pitfall: Students often confuse the terms 'validation' and 'verification' in database contexts, leading to incorrect answers in exam questions.
    ❌ Weak Answer (Loses Marks):Validation is checking data is correct, verification is checking data is accurate.
    ✅ 100% Model Answer (Full Marks):Validation is a process that automatically checks data against predefined rules (e.g., range checks, type checks) to ensure it is plausible and within acceptable limits, whereas verification is a manual or automated check to ensure data has been entered correctly and matches the original source (e.g., double entry or visual check).
    Examiner Tip: Always use the exact definitions from the City & Guilds specification and provide a clear example for each term to demonstrate understanding.
    Pitfall: In spreadsheet tasks, students often lose marks by not using absolute cell references when copying formulas, resulting in incorrect calculations.
    ❌ Weak Answer (Loses Marks):I used the formula =B2*C2 and copied it down, but it gave wrong answers.
    ✅ 100% Model Answer (Full Marks):When creating a formula that must reference a fixed cell (e.g., a tax rate in cell $B$1), use absolute referencing like =$B$1*C2. This ensures that when the formula is copied to other cells, the reference to $B$1 remains constant, while C2 adjusts relatively.
    Examiner Tip: Practise identifying when a cell reference should be absolute, relative, or mixed. In exams, explicitly state why you used $ signs in your formula.

    Step-by-Step Worked Solutions

    Detailed solution breakdown for typical exam problems

    Question: A company records its monthly sales in a spreadsheet. In cell B2, the sales for January are 5000. The sales increase by 5% each month. Write a formula for cell C2 (February) that can be copied down to calculate sales for the rest of the year. Explain how the formula works.

    1. 1.Step 1: Identify the initial value and the percentage increase. Initial sales = 5000, increase = 5%.
    2. 2.Step 2: The formula for February should be =B2*(1+5%) or =B2*1.05. This adds 5% to the previous month's sales.
    3. 3.Step 3: To copy down, ensure the reference to B2 is relative (no $ signs) so it updates to B3, B4, etc. The 1.05 is a constant, so it can be typed directly or referenced absolutely if placed in a cell.
    4. 4.Step 4: State that the formula uses relative referencing to calculate each month based on the previous month's value.
    Final Answer: Formula: =B2*1.05. This multiplies the previous month's sales by 1.05 (100% + 5%) to give the new sales figure. When copied down, B2 becomes B3, B4, etc., so each month's sales are 5% more than the previous month.

    Question: A database table 'Students' has fields: StudentID (Primary Key), FirstName, LastName, DateOfBirth, CourseCode. Write a query to show the full names of all students enrolled on course 'IT3' born after 1st January 2000. Explain the criteria and output.

    1. 1.Step 1: Identify the tables and fields needed: Students table, fields FirstName, LastName, DateOfBirth, CourseCode.
    2. 2.Step 2: Use a SELECT statement to choose the fields: SELECT FirstName, LastName FROM Students.
    3. 3.Step 3: Add a WHERE clause to filter: WHERE CourseCode = 'IT3' AND DateOfBirth > #01/01/2000#.
    4. 4.Step 4: Explain that the AND operator ensures both conditions must be true, and the date is enclosed in # symbols in Access.
    Final Answer: SELECT FirstName, LastName FROM Students WHERE CourseCode = 'IT3' AND DateOfBirth > #01/01/2000#; This query returns the first and last names of students on the IT3 course who were born after 1st January 2000.

    Active Recall Memory Test

    Test your memory before revealing the key facts

    Frequently Asked Questions

    Common questions students ask about this topic

    Pass / Merit / Distinction Evidence Checklist

    How your portfolio evidence is graded for CITY & GUILDS LIMITED IT Security for Users

    Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.

    Pass (P)

    Demonstrate baseline knowledge, accurate terminology, and core practical application.

    Merit (M)

    Provide detailed analysis, structured explanations, and clear workplace reasoning.

    Distinction (D)

    Deliver thorough evaluation, original problem solving, and fully justified recommendations.

    Before You Start

    Prior knowledge that will help with this topic

    • Basic computer literacy, including file management and using a keyboard and mouse.
    • Foundational knowledge of Microsoft Office or similar software (e.g., creating simple documents, spreadsheets, and presentations).
    • Understanding of simple data types (text, number, date) and basic mathematical operations.

    Coursework AI Review

    Paste your assignment brief and check your draft against its P/M/D criteria

    Key Terminology

    Essential terms to know

    • Use appropriate methods to minimise security risks to IT systems and data
    • Select and use appropriate methods to minimise security risk to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Use appropriate methods to minimise security risks to IT systems and data
    • Select and use appropriate methods to minimise security risk to IT systems and data
    • Password and authentication management
    • Malware and virus protection
    • Safe email and internet practices
    • Data backup and recovery
    • Access control and user permissions
    • Social engineering awareness

    Ready to learn?

    AI-powered learning tailored to this unit