The Data and AI School of London is an NCFE approved centre for this qualification (NCFE Account No. 11001657). Enrol below to begin your learning journey.
← All courses
Level 3 · NCFE
Enrolling now NCFE Approved Qualification number 610/4004/6

NCFE Level 3 Technical Occupational Entry in Cyber Security - Diploma

A competence-based diploma evidencing the knowledge, skills and behaviours needed for entry-level cyber security employment.

Duration: 360 guided learning hours; self-paced online study, typically one to two years

Level
Level 3
Qualification number
610/4004/6
Awarding organisation
NCFE
Regulated status
On the RQF, regulated by Ofqual
Guided learning hours
360 hours
Delivery
100% online
Study pattern
360 guided learning hours; self-paced online study, typically one to two years
NCFE This qualification is awarded by NCFE and regulated by Ofqual
NCFE Account No. 11001657

Course overview

This qualification develops occupational competence in cyber security, providing employers with evidence of attainment against the knowledge, skills and behaviours required for entry-level roles. Its mandatory units span cyber security concepts, threat assessment, risk evaluation, incident response, legal compliance, security measures and professional development.

It is designed for learners aged 19 and above who are seeking employment in cyber security. The focus on demonstrated competence makes it well suited to those aiming directly at the workplace.

Learners gain a recognised, occupationally-focused qualification that evidences their readiness for entry-level cyber security positions.

What you will study

The units below, their unit reference numbers and their guided learning hours are taken directly from the NCFE qualification specification.

Unit Title Unit reference Hours
01 Cyber security concepts
3 learning outcomes
  1. Understand the key concepts within cyber security The learner will:
    • 1.1 The key concepts and importance of cyber security: > CIA triad: >> confidentiality >> integrity >> availability > IAAA: >> identification >> authentication >> authorisation >> accountability
    • 1.2 The use of core terminology in cyber security: > assurance > reliability > non-repudiation > access control > threat > vulnerability > risk > security breach > information security > attack vectors > attack surface
    • 1.3 The role of information assurance and governance (IAG): > to guide the development and improvement of policies and processes > to support the auditing of policies and processes > to provide confirmation of compliance (for example, with International Organization of Standardization (ISO) standards)
  2. Understand effective cyber security culture The learner will: The learner will:
    • 2.1 The influence of organisational structures on cyber security culture: > stakeholders (for example, internal or external) > organisational types (for example, public or private)
    • 2.2 The importance of maintaining an effective cyber security culture in protecting the confidentiality of an organisations’ information
    • 2.3 The components and importance of an effective security culture
    • 2.4 The techniques used to build and maintain an effective security culture
    • 2.5 The impact of an inadequate cyber security culture on an organisation (for example, unauthorised distribution or loss of data, reputational damage)
  3. Understand secure infrastructure and cloud environments
    • 3.1 The components of a secure infrastructure within an organisation: > hardware > software > operating systems (OSs) > network resources
    • 3.2 The components of cloud environments: > Infrastructure as a Service (IaaS) > Platform as a Service (PaaS) > Software as a Service (SaaS)
A/651/1095 45
02 Cyber security threats, vulnerabilities and risks
4 learning outcomes
  1. Understand cyber security threats and perform intelligence gathering The learner will: The learner will:
    • 1.1 The function and features of the threat intelligence lifecycle
    • 1.2 How to use reliable sources to contribute to threat intelligence gathering tasks (for example, MITRE ATT&CK®)
    • 1.3 The impact of threats on an organisation (for example, financial, data loss)
    • 1.4 Types of threats and the methods used to identify them (for example, social engineering, ransomware, zero-day, commodity threat)
    • 1.5 The types and motivations of threat actors: > nation state > script kiddies > cyber criminals > terrorist organisations > insiders > hacktivists
    • 1.6 The application of network reconnaissance techniques to identify threats: > indicators of compromise (IOCs) from external threat intelligence sources > use of tools to scan and analyse network traffic > monitoring: >> unusual volume of network traffic >> repeated attempts to access systems >> alerts from end points >> abnormal user behaviour >> unexpected system changes
    • 1.7 Perform routine threat intelligence gathering tasks using reliable sources
  2. Understand suspicious activities and potential breaches The learner will:
    • 2.1 The characteristics of unusual security activity: > suspicious user behaviour (for example, brute force attack) > suspicious device behaviour (for example, unusual network activity) > unauthorised system changes (for example, changes to network configuration) > malware activity (for example, IOCs)
    • 2.2 Follow information security procedures to maintain cyber security resilience
    • 2.3 Develop information security training and awareness resources to support good cyber security practice
    • 2.4 Monitor the effectiveness of security awareness and training resources
  3. Understand evolving cyber security issues The learner will: The learner will:
    • 3.1 The types of cyber security issues and how these are evolving (for example, artificial intelligence (AI), quantum computing)
    • 3.2 How evolving cyber security issues can impact critical national infrastructure and control systems: > military and national defence (for example, leaking of classified information) > healthcare (for example, compromised confidentiality, ability to treat patients) > transport (for example, disruption to airlines, rail, smart motorways) > communication (for example, mass loss of service, interruptions to business and society) > utilities (for example, water and sanitation, energy sources) > supply chain (for example, production of food) > finance (for example, disruption or failure of payment transactions) > operational technologies (OT) (for example, disruption to Supervisory Control and Data Acquisition (SCADA))
    • 3.3 The importance of the threat landscape and the associated risks to internet of things (IoT) devices (for example, privacy, compromising other devices on network, trustworthy brand)
  4. Understand and maintain digital information systems The learner will:
    • 4.1 The types of digital information assets and how they are securely stored and accessed in a controlled environment: > systems > services > devices > data storage
    • 4.2 How digital information assets are managed across cloud services
    • 4.3 The importance and application of maintaining a digital information asset inventory (for example, compliance with ISO/IEC 27001 standard)
    • 4.4 The importance and use of secure digital information asset disposal (for example, data sanitisation)
    • 4.5 Maintain an inventory of digital information systems, services, devices and data storage
D/651/1096 54
03 Risk and vulnerability assessment
4 learning outcomes
  1. Understand cyber security vulnerabilities The learner will: The learner will:
    • 1.1 Common vulnerability exposures and the impact these can have on an organisation: > software misconfiguration (for example, authentication bypass, data loss) > broken access control and authentication (for example, unauthorised access) > sensitive data exposure (for example, reputational damage, fines) > injection vulnerabilities (for example, remote code execution, Denial of Service (DoS)) > using components with known vulnerabilities (for example, software security weakness) > insufficient logging and monitoring (for example, unacknowledged persistent threat) > security misconfiguration (for example, lack of network restrictions or antivirus protection) > incorrect cross-site validation (for example, session hijacking)
  2. Understand and categorise cyber security risks for escalation The learner will:
    • 2.1 The process of risk management and risk assessment to categorise threats, vulnerabilities and risks: > identification of the scope of the risk assessment > assessment of the risk using a scoring matrix (for example, probability versus impact) > categorisation of the risk rating (for example, apply a red, amber, green (RAG) rating) > recording, responding or escalating as appropriate > completion of a business impact analysis
    • 2.2 Categorise threats, vulnerabilities and risks in preparation for response or escalation
    • 2.3 Perform digital information risk assessments
    • 2.4 Use own initiative to identify when and how to escalate information security events in accordance with relevant procedures and standards
  3. Understand and evaluate vulnerability assessments The learner will:
    • 3.1 The considerations for a vulnerability assessment scope: > networks > computers > servers > business units > applications
    • 3.2 The use of tools and techniques to evaluate vulnerability assessments: > Common Vulnerabilities and Exposures (CVE) > Common Vulnerability Scoring System (CVSS)
    • 3.3 The scope and objectives of vulnerability assessment
    • 3.4 How to make recommendations based on evidence from vulnerability assessment tools: > severity of the vulnerability > potential impact and risk on business > availability of resources (for example, time, finances) > acceptance of risk > potential mitigations > scope of mitigation projects
    • 3.5 How to interpret the results of a cyber security vulnerability assessment
  4. Understand computer forensics The learner will:
    • 4.1 The concept of computer forensic principles: > identification (for example, the evidence that is presented, where it is stored and how it can be accessed) > preservation (for example, isolating, securing and preserving evidence) > analysis (for example, evidence- based conclusions) > documentation (for example, retained in line with legal retention periods) > presentation (for example, evidence presented to law enforcement for further investigation)
    • 4.2 The importance of ensuring evidence is not contaminated or compromised (for example, continuity of evidence to support court cases)
F/651/1097 54
04 Incident response and disaster recovery
4 learning outcomes
  1. Understand and create incident response documentation The learner will:
    • 1.1 The phases and application of the incident response lifecycle: > preparation > detection and analysis > containment > eradication and recovery > post-event activity and lessons learned
    • 1.2 The application of exception reporting: > reporting of incidents (for example, breaches of information security policy)
    • 1.3 The application of management reporting: > regular reporting (for example, recent events, threat landscape)
    • 1.4 Create draft information management reports using standard formats to meet requirements
  2. Understand and create cyber security incident information documentation
    • 2.1 The importance of maintaining an up-to- date cyber security incident log as part of a chain of evidence
    • 2.2 Create cyber security event information documents and preserve evidence to meet requirements
  3. Understand and monitor systems to identify information security events The learner will:
    • 3.1 The application of monitoring systems to identify information security events (for example, monitoring alerts, checking logs)
    • 3.2 Monitor and report information security events to meet requirements
  4. Understand disaster prevention and recovery
    • 4.1 The use of disaster prevention and recovery methods to support continuity of service planning: > disaster recovery plan (DRP) > business continuity plan (BCP)
    • 4.2 The purpose and use of secure on-site and off- site backup and recovery techniques (for example, incremental, air-gapped)
H/651/1098 54
05 Legislation and governance
6 learning outcomes
  1. Understand information security governance
    • 1.1 The purpose of organisational security governance: > provides a framework for managing compliance with legislation, standards, policies and processes > supports risk management
  2. Understand and review cyber security policies The learner will:
    • 2.1 The value of an information security management system (ISMS) to support compliance with cyber security standards: > people > processes > technology
    • 2.2 How an ISMS system supports compliance with cyber security standards (for example, International Standards Organisation (ISO) standards)
    • 2.3 Review and comment upon cyber security policies, procedures, standards and guidelines
  3. Understand knowledge of legislation relating to cyber security The learner will:
    • 3.1 The use of current legislation and standards to support cyber security: > Data Protection Act 2018 > Regulation of Investigatory Powers Act 2000 > Human Rights Act 1998 > Computer Misuse Act 1990 > Freedom of Information Act 2000 > Official Secrets Act 1989 > Wireless Telegraphy Act 2006 > Payment Card Industry Data Security Standard (PCI DSS)
    • 3.2 How to maintain knowledge of legislation and industry standards relating to cyber security
  4. Understand ethical considerations and codes of conduct The learner will:
    • 4.1 Ethical considerations when processing and storing data: > consent > contract > legal obligations > vital interests > public interest > legitimate interests
    • 4.2 The attributes of ethical codes of conduct within cyber security: > UK Cyber Security Council Code of Ethics > British Computer Society (BCS) Code of Conduct > Ethics for Incident Response and Security Teams (EthicsfIRST)
  5. Understand cyber security policies and compliance The learner will:
    • 5.1 The purpose and application of common information security policies: > acceptable use policy > incident management policy > bring your own device (BYOD) policy > access control policy > social media policy > password policy > patch management policy > antivirus policy > information security policy > data classification and handling policy > IT asset disposal policy
    • 5.2 The concept of cyber security compliance (for example, compliance with legal or internal policy requirements)
    • 5.3 The use of compliance monitoring techniques (for example, audits)
  6. Understand cyber security auditing and perform compliance checks The learner will:
    • 6.1 The purpose and application of cyber security audit requirements in line with organisational procedures (for example, scoping, planning)
    • 6.2 The importance of obtaining and documenting evidence in an appropriate form for review by an internal or external auditor
    • 6.3 Document audit requirements and collate relevant information from log files, incident reports and appropriate data sources
    • 6.4 Perform cyber security compliance checks
J/651/1099 54
06 Cyber security measures
4 learning outcomes
  1. Understand service desk delivery
    • 1.1 The purpose and use of service desk delivery in resolving security issues
    • 1.2 How and when to escalate a security ticket to a higher level
    • 1.3 The importance of communicating accurately and appropriately during escalation (for example, technical or non- technical audience)
  2. Understand, maintain and install cyber security controls The learner will: The learner will:
    • 2.1 The types of cyber security controls: > physical (for example, door access) > procedural (for example, acceptable use policy, vulnerability management policy, security incident response procedure) > technical (for example, firewalls, applications, user access control)
    • 2.2 The application of common cyber security measures and tools: > patching > software updates > access control > password management > firewalls > security incident and event management (SIEM) tools > protection tools: >> antivirus >> anti-malware >> anti-spam > technical management and monitoring tools (for example, cloud security posture management (CSPM), cloud- native application protection platform (CNAPP))
    • 2.3 Maintain information security controls and measures
    • 2.4 Use a structured approach to manage and assess the validity of security requests from a range of stakeholders
    • 2.5 Use technical procedures to install and maintain technical security controls
  3. Understand cryptography and digital certificates The learner will: The learner will:
    • 3.1 The purpose of cryptography in cyber security: > eavesdropping of information > prevention of tampering of information to ensure integrity of data > assurance of authenticity of information > secure storage of sensitive data
    • 3.2 Types of cryptographic techniques in cyber security: > hashing > symmetric encryption (for example, Blowfish, Twofish) > asymmetric encryption (for example, Rivest Shamir Adleman (RSA), Diffie- Hellman)
    • 3.3 The use of digital certificates: > to verify the identity of users > to verify servers > to sign data to prove authenticity > to secure communications in transit
    • 3.4 The purpose of certificate management tools: > generating certificate signing requests > signing new certificates > secure management of keys > tracking expired certificates > revoking compromised certificates
  4. Understand and modify access controls The learner will:
    • 4.1 The principles of identity and access management: > authentication > authorisation and federation
    • 4.2 The types and application of access control: > mandatory access control (MAC) > discretionary access control (DAC) > attribute-based access control (ABAC) > role-based access control (RBAC) > rule-based access control (RuBAC)
    • 4.3 The relationship between privacy and access rights and access control
    • 4.4 Review and modify access rights to digital information systems, services, devices or data
T/651/1100 54
07 Professional development in cyber security
5 learning outcomes
  1. Understand digital transformation The learner will:
    • 1.1 The impact of digital transformation (for example, new IT system) on cyber security occupations and within an overall business context: > customer issues and problems > business value > brand awareness > cultural/diversity awareness > internal and external stakeholders: >> user experience >> accessibility >> level of technical knowledge
  2. Understand cyber security occupations and regulatory requirements
    • 2.1 The skill requirements for different cyber security occupations and how these fit into the wider digital landscape
    • 2.2 The influence of current regulatory requirements on cyber security occupations
    • 2.3 How cyber security regulations may evolve in the future
  3. Understand learning techniques and sources of knowledge and review own development needs The learner will:
    • 3.1 How learning techniques (for example, evaluation and reflection) contribute to continuing professional development (CPD) of cyber security occupations
    • 3.2 A range of sources of knowledge and verified information applicable to cyber security occupations (for example, professional networks, academic publications)
    • 3.3 Review own development needs to keep up to date with emerging technologies and trends within cyber security
  4. Understand multidisciplinary teams and apply communication skills to share information
    • 4.1 The purpose of a multidisciplinary team
    • 4.2 How the roles within a multidisciplinary team are identified
    • 4.3 The value of communication within multidisciplinary teams
    • 4.4 Apply communication skills using appropriate technical and non- technical terminology to share information with stakeholders (for example, within a multidisciplinary team)
  5. Understand independent working, time management and stakeholder engagement The learner will:
    • 5.1 The value of working independently and taking responsibility for own actions
    • 5.2 How to manage own time to meet deadlines and manage stakeholder expectations
    • 5.3 The importance of treating all stakeholders fairly and with respect without bias or discrimination
Y/651/1101 45
Total guided learning hours 360

Entry requirements

  • Learners must be aged 19 or above.
  • No specific prior skills or knowledge required.
  • A Level 2 qualification is helpful but not essential.
  • A sound standard of English and maths supports learning at this level.
Take it with you

The course guide

Everything on this page as one document you can keep, print, or send to whoever is deciding with you.

  • All 7 units, with the hours behind each one
  • How you are assessed, and who checks the marking
  • How paying works, and what is due when
  • Entry requirements and where the qualification leads
Download the guide (PDF)

Generated from this qualification's record, so the units and hours in it are the ones on this page. The fee is here on the page rather than in the guide, so a saved copy cannot quote you an old one.

How you are assessed

Your work is assessed by our qualified assessors, internally quality assured, and externally quality assured by NCFE. Assessment is against the criteria published in the qualification specification, and your assessor tells you what is needed before you start each unit.

For what happens after you submit: who marks it, who checks the marking, how long feedback takes and what to do if you disagree with a decision, see how assessment works.

If you need an adjustment to how you are assessed, for a disability or any other reason, ask us before you begin. We arrange adjustments under our Reasonable Adjustments policy, and you can request one online.

How we assess and quality assure is set out in DAIS-POL-016 Assessment and Internal Quality Assurance.

How you study, and what you need

You study online through our virtual learning environment, which is where the teaching material, your assessment submissions, your feedback and your progress all live. You work at your own pace, with tutor support throughout. Everyone completes a short online induction before starting an assessed unit.

What you need to take part
Device Laptop or desktop computer
Operating system Windows 10 or macOS 10.15 or later
Browser Google Chrome or Mozilla Firefox, latest version
Internet speed 10 Mbps download and 5 Mbps upload
Webcam Required for live sessions and identity verification
Microphone Required for live sessions

These are the minimum requirements published in DAIS-POL-024 Online Learning and Digital Delivery.

Support, and how quickly we reply

These are the response times we commit to in policy, not an aspiration.

What How Response
General questions Message your tutor in the VLE Within 2 working days
Assessment feedback Returned in the VLE or e-portfolio Within 10 working days of submission
Technical problems Technical support email Within 1 working day
Urgent welfare concerns Email to the Designated Safeguarding Lead Within 1 working day

Published in DAIS-POL-024 and DAIS-POL-009 Learner Support.

Registration and your certificate

We register you with NCFE before you begin any assessed unit, and we collect your Unique Learner Number as part of that. When your assessment decisions are finalised and quality assured, we claim your certificate through the NCFE portal and you are notified digitally. The certificate comes from NCFE, not from us.

Set out in DAIS-POL-008 Learner Registration and Certification.

Progression

Learners who achieve this qualification could progress to the following:

  • employment:
    • cyber security administrator
    • cyber security technician
    • access control administrator
    • incident response technician
    • junior information security analyst
    • junior threat and risk analyst
    • junior penetration tester
  • higher education

Progression to higher-level studies

Level 3 qualifications can support progression to higher-level study, which requires knowledge and skills

different from those gained at levels 1 and 2. Level 3 qualifications enable learners to:

  • apply factual, procedural and theoretical subject knowledge
  • use relevant knowledge and methods to address complex, non-routine problems
  • interpret and evaluate relevant information and ideas
  • understand the nature of the area of study or work
  • demonstrate an awareness of different perspectives and approaches
  • identify, select and use appropriate cognitive and practical skills
  • use appropriate research to inform actions
  • review and evaluate the effectiveness of their own methods

At The Data and AI School of London this diploma also prepares you for our Level 4 Diploma: Cyber Security Engineer, an approved Higher Technical Qualification, for which a relevant Level 3 qualification in cyber security, IT or digital is strongly recommended.

Common questions

Who awards NCFE Level 3 Technical Occupational Entry in Cyber Security - Diploma, and how do I get my certificate?

NCFE Level 3 Technical Occupational Entry in Cyber Security - Diploma is awarded by NCFE, an Ofqual-approved awarding organisation, and sits on the Regulated Qualifications Framework (RQF). The qualification number is 610/4004/6. The Data and AI School of London is an NCFE approved centre (Account No. 11001657). We register you with NCFE before you start any assessed unit and collect your Unique Learner Number. Once your work is assessed and quality assured we claim your certificate through the NCFE portal, and it is issued by NCFE rather than by us.

How long does NCFE Level 3 Technical Occupational Entry in Cyber Security - Diploma take?

This qualification carries 360 guided learning hours. It is studied online at your own pace, so how long it takes in calendar time depends on how much you can commit each week.

What do I need before I can start?

Learners must be aged 19 or above. We assess every applicant individually and will tell you if a different level would suit you better.

Can I study this entirely online?

Yes. Teaching, materials and assessment are all delivered through our Moodle-based virtual learning environment, so you can study from anywhere in the UK. You need a laptop or desktop computer, a current version of Chrome or Firefox, and a broadband connection of at least 10 Mbps down and 5 Mbps up. Tutor support is available throughout, and we answer questions within 2 working days and return assessment feedback within 10 working days of submission.

Can I enrol now, and when do I pay?

The fee is £995. Enrolment is open, so you can apply online today. Nothing is paid at application: payment is taken only after you accept an offer.

Not sure this is the right qualification?

Ask before you apply. We will say honestly if a different level would suit you better.

Other qualifications

See all qualifications