Course overview
This qualification develops occupational competence in cyber security, providing employers with evidence of attainment against the knowledge, skills and behaviours required for entry-level roles. Its mandatory units span cyber security concepts, threat assessment, risk evaluation, incident response, legal compliance, security measures and professional development.
It is designed for learners aged 19 and above who are seeking employment in cyber security. The focus on demonstrated competence makes it well suited to those aiming directly at the workplace.
Learners gain a recognised, occupationally-focused qualification that evidences their readiness for entry-level cyber security positions.
What you will study
The units below, their unit reference numbers and their guided learning hours are taken
directly from the NCFE qualification specification.
| Unit |
Title |
Unit reference |
Hours |
| 01 |
Cyber security concepts
3 learning outcomes
-
Understand the key concepts within cyber security The learner will:
- 1.1 The key concepts and importance of cyber security: > CIA triad: >> confidentiality >> integrity >> availability > IAAA: >> identification >> authentication >> authorisation >> accountability
- 1.2 The use of core terminology in cyber security: > assurance > reliability > non-repudiation > access control > threat > vulnerability > risk > security breach > information security > attack vectors > attack surface
- 1.3 The role of information assurance and governance (IAG): > to guide the development and improvement of policies and processes > to support the auditing of policies and processes > to provide confirmation of compliance (for example, with International Organization of Standardization (ISO) standards)
-
Understand effective cyber security culture The learner will: The learner will:
- 2.1 The influence of organisational structures on cyber security culture: > stakeholders (for example, internal or external) > organisational types (for example, public or private)
- 2.2 The importance of maintaining an effective cyber security culture in protecting the confidentiality of an organisations’ information
- 2.3 The components and importance of an effective security culture
- 2.4 The techniques used to build and maintain an effective security culture
- 2.5 The impact of an inadequate cyber security culture on an organisation (for example, unauthorised distribution or loss of data, reputational damage)
-
Understand secure infrastructure and cloud environments
- 3.1 The components of a secure infrastructure within an organisation: > hardware > software > operating systems (OSs) > network resources
- 3.2 The components of cloud environments: > Infrastructure as a Service (IaaS) > Platform as a Service (PaaS) > Software as a Service (SaaS)
|
A/651/1095 |
45 |
| 02 |
Cyber security threats, vulnerabilities and risks
4 learning outcomes
-
Understand cyber security threats and perform intelligence gathering The learner will: The learner will:
- 1.1 The function and features of the threat intelligence lifecycle
- 1.2 How to use reliable sources to contribute to threat intelligence gathering tasks (for example, MITRE ATT&CK®)
- 1.3 The impact of threats on an organisation (for example, financial, data loss)
- 1.4 Types of threats and the methods used to identify them (for example, social engineering, ransomware, zero-day, commodity threat)
- 1.5 The types and motivations of threat actors: > nation state > script kiddies > cyber criminals > terrorist organisations > insiders > hacktivists
- 1.6 The application of network reconnaissance techniques to identify threats: > indicators of compromise (IOCs) from external threat intelligence sources > use of tools to scan and analyse network traffic > monitoring: >> unusual volume of network traffic >> repeated attempts to access systems >> alerts from end points >> abnormal user behaviour >> unexpected system changes
- 1.7 Perform routine threat intelligence gathering tasks using reliable sources
-
Understand suspicious activities and potential breaches The learner will:
- 2.1 The characteristics of unusual security activity: > suspicious user behaviour (for example, brute force attack) > suspicious device behaviour (for example, unusual network activity) > unauthorised system changes (for example, changes to network configuration) > malware activity (for example, IOCs)
- 2.2 Follow information security procedures to maintain cyber security resilience
- 2.3 Develop information security training and awareness resources to support good cyber security practice
- 2.4 Monitor the effectiveness of security awareness and training resources
-
Understand evolving cyber security issues The learner will: The learner will:
- 3.1 The types of cyber security issues and how these are evolving (for example, artificial intelligence (AI), quantum computing)
- 3.2 How evolving cyber security issues can impact critical national infrastructure and control systems: > military and national defence (for example, leaking of classified information) > healthcare (for example, compromised confidentiality, ability to treat patients) > transport (for example, disruption to airlines, rail, smart motorways) > communication (for example, mass loss of service, interruptions to business and society) > utilities (for example, water and sanitation, energy sources) > supply chain (for example, production of food) > finance (for example, disruption or failure of payment transactions) > operational technologies (OT) (for example, disruption to Supervisory Control and Data Acquisition (SCADA))
- 3.3 The importance of the threat landscape and the associated risks to internet of things (IoT) devices (for example, privacy, compromising other devices on network, trustworthy brand)
-
Understand and maintain digital information systems The learner will:
- 4.1 The types of digital information assets and how they are securely stored and accessed in a controlled environment: > systems > services > devices > data storage
- 4.2 How digital information assets are managed across cloud services
- 4.3 The importance and application of maintaining a digital information asset inventory (for example, compliance with ISO/IEC 27001 standard)
- 4.4 The importance and use of secure digital information asset disposal (for example, data sanitisation)
- 4.5 Maintain an inventory of digital information systems, services, devices and data storage
|
D/651/1096 |
54 |
| 03 |
Risk and vulnerability assessment
4 learning outcomes
-
Understand cyber security vulnerabilities The learner will: The learner will:
- 1.1 Common vulnerability exposures and the impact these can have on an organisation: > software misconfiguration (for example, authentication bypass, data loss) > broken access control and authentication (for example, unauthorised access) > sensitive data exposure (for example, reputational damage, fines) > injection vulnerabilities (for example, remote code execution, Denial of Service (DoS)) > using components with known vulnerabilities (for example, software security weakness) > insufficient logging and monitoring (for example, unacknowledged persistent threat) > security misconfiguration (for example, lack of network restrictions or antivirus protection) > incorrect cross-site validation (for example, session hijacking)
-
Understand and categorise cyber security risks for escalation The learner will:
- 2.1 The process of risk management and risk assessment to categorise threats, vulnerabilities and risks: > identification of the scope of the risk assessment > assessment of the risk using a scoring matrix (for example, probability versus impact) > categorisation of the risk rating (for example, apply a red, amber, green (RAG) rating) > recording, responding or escalating as appropriate > completion of a business impact analysis
- 2.2 Categorise threats, vulnerabilities and risks in preparation for response or escalation
- 2.3 Perform digital information risk assessments
- 2.4 Use own initiative to identify when and how to escalate information security events in accordance with relevant procedures and standards
-
Understand and evaluate vulnerability assessments The learner will:
- 3.1 The considerations for a vulnerability assessment scope: > networks > computers > servers > business units > applications
- 3.2 The use of tools and techniques to evaluate vulnerability assessments: > Common Vulnerabilities and Exposures (CVE) > Common Vulnerability Scoring System (CVSS)
- 3.3 The scope and objectives of vulnerability assessment
- 3.4 How to make recommendations based on evidence from vulnerability assessment tools: > severity of the vulnerability > potential impact and risk on business > availability of resources (for example, time, finances) > acceptance of risk > potential mitigations > scope of mitigation projects
- 3.5 How to interpret the results of a cyber security vulnerability assessment
-
Understand computer forensics The learner will:
- 4.1 The concept of computer forensic principles: > identification (for example, the evidence that is presented, where it is stored and how it can be accessed) > preservation (for example, isolating, securing and preserving evidence) > analysis (for example, evidence- based conclusions) > documentation (for example, retained in line with legal retention periods) > presentation (for example, evidence presented to law enforcement for further investigation)
- 4.2 The importance of ensuring evidence is not contaminated or compromised (for example, continuity of evidence to support court cases)
|
F/651/1097 |
54 |
| 04 |
Incident response and disaster recovery
4 learning outcomes
-
Understand and create incident response documentation The learner will:
- 1.1 The phases and application of the incident response lifecycle: > preparation > detection and analysis > containment > eradication and recovery > post-event activity and lessons learned
- 1.2 The application of exception reporting: > reporting of incidents (for example, breaches of information security policy)
- 1.3 The application of management reporting: > regular reporting (for example, recent events, threat landscape)
- 1.4 Create draft information management reports using standard formats to meet requirements
-
Understand and create cyber security incident information documentation
- 2.1 The importance of maintaining an up-to- date cyber security incident log as part of a chain of evidence
- 2.2 Create cyber security event information documents and preserve evidence to meet requirements
-
Understand and monitor systems to identify information security events The learner will:
- 3.1 The application of monitoring systems to identify information security events (for example, monitoring alerts, checking logs)
- 3.2 Monitor and report information security events to meet requirements
-
Understand disaster prevention and recovery
- 4.1 The use of disaster prevention and recovery methods to support continuity of service planning: > disaster recovery plan (DRP) > business continuity plan (BCP)
- 4.2 The purpose and use of secure on-site and off- site backup and recovery techniques (for example, incremental, air-gapped)
|
H/651/1098 |
54 |
| 05 |
Legislation and governance
6 learning outcomes
-
Understand information security governance
- 1.1 The purpose of organisational security governance: > provides a framework for managing compliance with legislation, standards, policies and processes > supports risk management
-
Understand and review cyber security policies The learner will:
- 2.1 The value of an information security management system (ISMS) to support compliance with cyber security standards: > people > processes > technology
- 2.2 How an ISMS system supports compliance with cyber security standards (for example, International Standards Organisation (ISO) standards)
- 2.3 Review and comment upon cyber security policies, procedures, standards and guidelines
-
Understand knowledge of legislation relating to cyber security The learner will:
- 3.1 The use of current legislation and standards to support cyber security: > Data Protection Act 2018 > Regulation of Investigatory Powers Act 2000 > Human Rights Act 1998 > Computer Misuse Act 1990 > Freedom of Information Act 2000 > Official Secrets Act 1989 > Wireless Telegraphy Act 2006 > Payment Card Industry Data Security Standard (PCI DSS)
- 3.2 How to maintain knowledge of legislation and industry standards relating to cyber security
-
Understand ethical considerations and codes of conduct The learner will:
- 4.1 Ethical considerations when processing and storing data: > consent > contract > legal obligations > vital interests > public interest > legitimate interests
- 4.2 The attributes of ethical codes of conduct within cyber security: > UK Cyber Security Council Code of Ethics > British Computer Society (BCS) Code of Conduct > Ethics for Incident Response and Security Teams (EthicsfIRST)
-
Understand cyber security policies and compliance The learner will:
- 5.1 The purpose and application of common information security policies: > acceptable use policy > incident management policy > bring your own device (BYOD) policy > access control policy > social media policy > password policy > patch management policy > antivirus policy > information security policy > data classification and handling policy > IT asset disposal policy
- 5.2 The concept of cyber security compliance (for example, compliance with legal or internal policy requirements)
- 5.3 The use of compliance monitoring techniques (for example, audits)
-
Understand cyber security auditing and perform compliance checks The learner will:
- 6.1 The purpose and application of cyber security audit requirements in line with organisational procedures (for example, scoping, planning)
- 6.2 The importance of obtaining and documenting evidence in an appropriate form for review by an internal or external auditor
- 6.3 Document audit requirements and collate relevant information from log files, incident reports and appropriate data sources
- 6.4 Perform cyber security compliance checks
|
J/651/1099 |
54 |
| 06 |
Cyber security measures
4 learning outcomes
-
Understand service desk delivery
- 1.1 The purpose and use of service desk delivery in resolving security issues
- 1.2 How and when to escalate a security ticket to a higher level
- 1.3 The importance of communicating accurately and appropriately during escalation (for example, technical or non- technical audience)
-
Understand, maintain and install cyber security controls The learner will: The learner will:
- 2.1 The types of cyber security controls: > physical (for example, door access) > procedural (for example, acceptable use policy, vulnerability management policy, security incident response procedure) > technical (for example, firewalls, applications, user access control)
- 2.2 The application of common cyber security measures and tools: > patching > software updates > access control > password management > firewalls > security incident and event management (SIEM) tools > protection tools: >> antivirus >> anti-malware >> anti-spam > technical management and monitoring tools (for example, cloud security posture management (CSPM), cloud- native application protection platform (CNAPP))
- 2.3 Maintain information security controls and measures
- 2.4 Use a structured approach to manage and assess the validity of security requests from a range of stakeholders
- 2.5 Use technical procedures to install and maintain technical security controls
-
Understand cryptography and digital certificates The learner will: The learner will:
- 3.1 The purpose of cryptography in cyber security: > eavesdropping of information > prevention of tampering of information to ensure integrity of data > assurance of authenticity of information > secure storage of sensitive data
- 3.2 Types of cryptographic techniques in cyber security: > hashing > symmetric encryption (for example, Blowfish, Twofish) > asymmetric encryption (for example, Rivest Shamir Adleman (RSA), Diffie- Hellman)
- 3.3 The use of digital certificates: > to verify the identity of users > to verify servers > to sign data to prove authenticity > to secure communications in transit
- 3.4 The purpose of certificate management tools: > generating certificate signing requests > signing new certificates > secure management of keys > tracking expired certificates > revoking compromised certificates
-
Understand and modify access controls The learner will:
- 4.1 The principles of identity and access management: > authentication > authorisation and federation
- 4.2 The types and application of access control: > mandatory access control (MAC) > discretionary access control (DAC) > attribute-based access control (ABAC) > role-based access control (RBAC) > rule-based access control (RuBAC)
- 4.3 The relationship between privacy and access rights and access control
- 4.4 Review and modify access rights to digital information systems, services, devices or data
|
T/651/1100 |
54 |
| 07 |
Professional development in cyber security
5 learning outcomes
-
Understand digital transformation The learner will:
- 1.1 The impact of digital transformation (for example, new IT system) on cyber security occupations and within an overall business context: > customer issues and problems > business value > brand awareness > cultural/diversity awareness > internal and external stakeholders: >> user experience >> accessibility >> level of technical knowledge
-
Understand cyber security occupations and regulatory requirements
- 2.1 The skill requirements for different cyber security occupations and how these fit into the wider digital landscape
- 2.2 The influence of current regulatory requirements on cyber security occupations
- 2.3 How cyber security regulations may evolve in the future
-
Understand learning techniques and sources of knowledge and review own development needs The learner will:
- 3.1 How learning techniques (for example, evaluation and reflection) contribute to continuing professional development (CPD) of cyber security occupations
- 3.2 A range of sources of knowledge and verified information applicable to cyber security occupations (for example, professional networks, academic publications)
- 3.3 Review own development needs to keep up to date with emerging technologies and trends within cyber security
-
Understand multidisciplinary teams and apply communication skills to share information
- 4.1 The purpose of a multidisciplinary team
- 4.2 How the roles within a multidisciplinary team are identified
- 4.3 The value of communication within multidisciplinary teams
- 4.4 Apply communication skills using appropriate technical and non- technical terminology to share information with stakeholders (for example, within a multidisciplinary team)
-
Understand independent working, time management and stakeholder engagement The learner will:
- 5.1 The value of working independently and taking responsibility for own actions
- 5.2 How to manage own time to meet deadlines and manage stakeholder expectations
- 5.3 The importance of treating all stakeholders fairly and with respect without bias or discrimination
|
Y/651/1101 |
45 |
| Total guided learning hours |
360 |
Entry requirements
- Learners must be aged 19 or above.
- No specific prior skills or knowledge required.
- A Level 2 qualification is helpful but not essential.
- A sound standard of English and maths supports learning at this level.
Take it with you
The course guide
Everything on this page as one document you can keep, print, or send to
whoever is deciding with you.
- All 7 units, with the hours behind each one
- How you are assessed, and who checks the marking
- How paying works, and what is due when
- Entry requirements and where the qualification leads
Download the guide (PDF)
Generated from this qualification's
record, so the units and hours in it are the ones on this page. The fee is
here on the page rather than in the guide, so a saved copy cannot quote you
an old one.
NCFE · Level 3
NCFE Level 3 Technical Occupational Entry in Cyber Securi…
A competence-based diploma evidencing the knowledge, skills and behaviours needed for entry-level cyber security …
Study it online.
Finish with a qualification
that is on your record for life.
Level 3Level
360Hours
7Units
100%Online
DeliveredOnline, with tutor support
AssessedOn your own work
Awarded byNCFE, Ofqual recognised
StudiedAt your own pace
Inside
- The units, and the hours behind each
- What the assessment involves
- Entry requirements, and what it leads to
- How paying works, and questions people ask
A4 PDF
How you are assessed
Your work is assessed by our qualified assessors, internally quality assured, and externally
quality assured by NCFE. Assessment is against the criteria published in the qualification
specification, and your assessor tells you what is needed before you start each unit.
For what happens after you submit: who marks it, who checks the marking, how long feedback
takes and what to do if you disagree with a decision, see
how assessment works.
If you need an adjustment to how you are assessed, for a disability or any other reason,
ask us before you begin. We arrange adjustments under our
Reasonable Adjustments policy,
and you can request one online.
How we assess and quality assure is set out in
DAIS-POL-016 Assessment and Internal Quality Assurance.
How you study, and what you need
You study online through our virtual learning environment, which is where the teaching
material, your assessment submissions, your feedback and your progress all live. You work
at your own pace, with tutor support throughout. Everyone completes a short online
induction before starting an assessed unit.
What you need to take part
| Device |
Laptop or desktop computer |
| Operating system |
Windows 10 or macOS 10.15 or later |
| Browser |
Google Chrome or Mozilla Firefox, latest version |
| Internet speed |
10 Mbps download and 5 Mbps upload |
| Webcam |
Required for live sessions and identity verification |
| Microphone |
Required for live sessions |
These are the minimum requirements published in
DAIS-POL-024 Online Learning and Digital Delivery.
Support, and how quickly we reply
These are the response times we commit to in policy, not an aspiration.
| What |
How |
Response |
| General questions |
Message your tutor in the VLE |
Within 2 working days |
| Assessment feedback |
Returned in the VLE or e-portfolio |
Within 10 working days of submission |
| Technical problems |
Technical support email |
Within 1 working day |
| Urgent welfare concerns |
Email to the Designated Safeguarding Lead |
Within 1 working day |
Published in
DAIS-POL-024
and DAIS-POL-009 Learner Support.
Registration and your certificate
We register you with NCFE before you begin any assessed unit, and we collect your Unique
Learner Number as part of that. When your assessment decisions are finalised and quality
assured, we claim your certificate through the NCFE portal and you are notified digitally.
The certificate comes from NCFE, not from us.
Set out in
DAIS-POL-008 Learner Registration and Certification.
Progression
Learners who achieve this qualification could progress to the following:
- employment:
- cyber security administrator
- cyber security technician
- access control administrator
- incident response technician
- junior information security analyst
- junior threat and risk analyst
- junior penetration tester
- higher education
Progression to higher-level studies
Level 3 qualifications can support progression to higher-level study, which requires knowledge and skills
different from those gained at levels 1 and 2. Level 3 qualifications enable learners to:
- apply factual, procedural and theoretical subject knowledge
- use relevant knowledge and methods to address complex, non-routine problems
- interpret and evaluate relevant information and ideas
- understand the nature of the area of study or work
- demonstrate an awareness of different perspectives and approaches
- identify, select and use appropriate cognitive and practical skills
- use appropriate research to inform actions
- review and evaluate the effectiveness of their own methods
At The Data and AI School of London this diploma also prepares you for our Level 4 Diploma: Cyber Security Engineer, an approved Higher Technical Qualification, for which a relevant Level 3 qualification in cyber security, IT or digital is strongly recommended.