Overview

Framework:
RQF
Level:
Level 1
Unit No:
A/651/9222
Credits:
6
Guided learning hours:
48 hours

Aim

Learners will develop an understanding of the impact of cybercrime and importance of cybersecurity. They will learn about protective methods individuals and organisations should use to minimise the impact of cybercrime and how user access controls can prevent unauthorised access, data breaches and fraud.

Unit Learning Outcomes

1

Understand the motives for cybercrime 

Assessment Criteria

  • 1.1

    Identify different types of cybercrime and possible motives

    1.1: Types of cybercrime, for example:

    • malware attacks
    • phishing
    • ransomware
    • identity theft
    • denial-of-service (DoS) attacks
    • cyber espionage
    • online fraud
    • cyberbullying

    1.1: Motives, for example:

    • steal and misuse data (personal, corporate, or financial information)
    • commit fraud
    • hack IT systems
    • cause disruption to organisations
    • cyberextortion (demanding money to prevent a threatened attack)
    • ransomware attacks
    • Denial of Service (DoS) attacks
    • cryptojacking (using someone else’s computing resources to mine cryptocurrency)
    • cyberespionage (accessing government or company data)
  • 1.2

    Outline how cybercrime can affect individuals and organisations.

    1.2: How cybercrime can affect individuals and organisations, for example:

    • financial loss
    • identity theft
    • emotional distress for individuals
    • significant financial losses for organisations due to data breaches
    • operational disruption
    • legal penalties
    • reputational damage
    • loss of customer trust
    • disruption of IT infrastructures
    • long-term financial and operational consequences
  • 1.3

    Describe methods used by cybercriminals to defraud individuals and organisations.

    1.3: Methods, for example:

    • phishing - deceptive emails, websites, and text messages to steal information
    • spear phishing - emails used to carry out targeted attacks
    • baiting - online and physical social engineering attacks that entice victims with a reward
    • malware - victims are tricked into thinking that malware is installed on their computer and reveal information or pay money to have malware removed
    • pretexting - uses false identity to trick victims into giving up information
    • vishing - urgent voice mails convince victims they need to act quickly to protect themselves from an online risk

2

Understand the importance of protective methods in cybersecurity

Assessment Criteria

  • 2.1

    Identify routine protective methods individuals and organisations can use to maintain cybersecurity.

    2.1: Routine protective methods that individuals and organisations can use to maintain cybersecurity, for example:

    • practising online safety principles
    • installing and maintaining anti‑virus, anti‑malware, firewalls, and other security software
    • ensuring browser safety (for example, privacy settings, VPN use, incognito mode)
    • carrying out regular software updates and system/data backups
    • being aware of suspicious emails, attachments, links, and pop‑ups
    • understanding the difference between http and https when accessing websites
    • using strong passwords and protecting them (for example, password managers)
    • using Multi‑Factor Authentication (MFA) methods
    • restricting user access to certain types of information (access control)
  • 2.2

    Identify why cybersecurity testing is important for organisations.

    2.2 Why cybersecurity testing is important for organisations, for example:

    • understanding that testing helps identify vulnerabilities before they can be exploited
    • recognising that testing supports the effectiveness of protective methods and security controls
    • ensuring systems, data, and networks remain secure and compliant with organisational or legal requirements
    • reducing the risk of data breaches, financial loss, and reputational damage
    • supporting continuous improvement of cybersecurity measures

3

Understand legislation and ethical conduct in cybersecurity

Assessment Criteria

  • 3.1

    Identify legislation, codes of conduct and ethical considerations in cybersecurity.

    3.1: Legislation, for example:

    • The Data Protection Act 2018 (GDPR)
    • The Computer Misuse Act 1990
    • The Official Secrets Act 1989
    • The Privacy and Electronic Communications Regulations 2003
  • 3.2

    Identify why cybersecurity codes of conduct are used by organisations.

    3.2: Codes of conduct, for example:

    • adherence to organisational IT policies and procedures
    • maintaining confidentiality
    • compliance with legislation
    • awareness of information security

4

Understand the role of user access controls in cybersecurity

Assessment Criteria

  • 4.1

    Describe the importance of user access controls.

    4.1: Importance of user access controls, for example:

    • importance of user access controls in protecting organisational data and IT systems
    • role of access controls in preventing data breaches, fraud, and compliance violations
    • understanding authorised users and user permissions within an organisation
    • how limiting access to data helps maintain cybersecurity
    • contribution of access controls to preventing cybercrimes and minimising security risks
    • maintaining data confidentiality, privacy, and overall security through controlled access
    • reducing the likelihood of cyberattacks by restricting unnecessary or unauthorised access
    • supporting compliance with legal, regulatory, and organisational requirements
  • 4.2

    Describe how to create user access controls.

    4.2 Create user access controls, for example:

    • the hardware and software involved
    • the login process
    • the identification of roles (administrator, editor, viewer)
    • the assigning of permissions to different roles to determine what actions or resources each role can access;
    • oadministrator: full control over all features and data
    • oeditor: can create, modify, and delete data
    • oviewer: can only view data

    Learners should also cover the role and importance of usernames and passwords, and how users can be blocked from performing certain actions, such as, installing unauthorised software and making system changes at Administrator level.