BTEC HND Computing Unit 5 Security Assignment Answer Guide

BTEC HND Computing Unit 5 Security Assignment Answer Guide
08 Oct, 2026 /

Author : Christopher Anderson

This BTEC HND Computing computer security assignment guide covers Unit 5 Security (D/618/7406), the core security unit in the Pearson BTEC Higher Nationals in Computing (RQF). It is a Level 4 unit studied in the HNC year and counted towards the HND. You will find every P, M and D criterion explained, a report structure for each learning outcome, model paragraphs and a worked risk calculation.

What the Unit 5 Security assignment asks you to do

Unit 5 briefs usually place you as a security consultant or junior IT security officer for an organisation, such as a small company moving services online. Across one or two assignments you:

  • identify and discuss security risks and assess the organisation’s security procedures;
  • explain network security solutions: firewall policies, VPNs, DMZ, static IP and NAT, and network monitoring;
  • review risk assessment, data protection regulations, ISO standards and IT security audits;
  • design a security policy with a disaster recovery plan and explain stakeholder roles in audits.

Learning outcomes for Unit 5 Security

Learning outcome What it covers
LO1 Assess risks to IT security Threats and vulnerabilities, organisational security procedures, legal requirements, business continuity
LO2 Describe IT security solutions Firewalls and VPNs, DMZ, NAT, static and dynamic IP, data security, monitoring, staff awareness
LO3 Review mechanisms to control organisational IT security Risk assessment, ISO 31000 and ISO/IEC 27001, Data Protection Act 2018, Computer Misuse Act 1990, audits
LO4 Manage organisational security Security policy, disaster recovery, compliance monitoring, auditing, penetration testing

Pass, Merit and Distinction criteria explained

Criterion What it asks How to evidence it
P1 Discuss types of security risks to organisations Malware, phishing, insider threat, data loss, unauthorised access, physical risks — each with impact on the scenario organisation
P2 Assess organisational security procedures Judge existing procedures (access control, backup, patching, passwords) as adequate or not
P3 Discuss the potential impact of incorrect configuration of firewall policies and third-party VPNs Concrete misconfigurations and what an attacker could do
P4 Discuss, using an example for each, how a DMZ, static IP and NAT improve network security Network diagram plus one example per technique
M1 Analyse the benefits of implementing network monitoring systems with supporting reasons IDS/IPS, SIEM, flow monitoring — benefits linked to specific risks
M2 Propose a method to assess and treat IT security risks Risk register, likelihood × impact scoring, treatment options
D1 Evaluate a range of physical and virtual security measures to ensure integrity of organisational IT security Balanced judgement of controls, cost and effectiveness
P5 Review risk assessment procedures in an organisation Steps, who is involved, frequency, weaknesses
P6 Explain data protection processes and regulations as applicable to an organisation UK GDPR and Data Protection Act 2018 principles, breach reporting, retention
M3 Summarise an appropriate risk-management approach or ISO standard and its application in IT security ISO 31000 or ISO/IEC 27001 applied to the scenario
M4 Analyse possible impacts to organisational security resulting from an IT security audit What an audit finds and how that changes controls and priorities
D2 Recommend how IT security can be aligned with an organisational policy, detailing the security impact of any misalignment Specific gaps between policy and practice and their consequences
P7 Design a suitable security policy, including the main components of a disaster recovery plan A written policy document with DR plan section
P8 Discuss the roles of stakeholders in implementing security audits Board, IT, data protection officer, staff, external auditors
M5 Justify the security plan, giving reasons for the elements selected Rationale linked to risks found earlier
D3 Evaluate the suitability of the tools used in the policy to meet business needs Fit, cost, usability and limits of each tool

How to answer LO1 and LO2: risks and solutions

Base everything on the scenario organisation. Start with an asset list (customer database, website, staff laptops, payment system), then the risks to each.

  1. P1: discuss five or six risk types, each with a realistic example and impact.
  2. P2: assess current procedures in a table: procedure, strength, weakness, rating.
  3. P3: explain misconfigurations such as an “allow any” rule, unused open ports or a supplier VPN with excessive access.
  4. P4: draw the network with a DMZ for the public web server and explain NAT and static IP with examples.
  5. M1 and M2: analyse monitoring benefits and propose your risk method.

Example paragraph: The company’s third-party VPN gives its payroll supplier access to the whole internal network rather than only the payroll server. If the supplier’s credentials were stolen, an attacker could move from the VPN into the file server holding customer records. This breaks the principle of least privilege. Restricting the VPN to a single host and port, enforcing multi-factor authentication and logging every session would reduce the impact of a compromised account without stopping the supplier from doing its job.

How to answer LO3: controlling organisational security

LO3 is about governance. Review how the organisation assesses risk, then explain the data protection rules it must follow. Cover the UK GDPR principles, lawful basis, the 72-hour deadline for reporting notifiable breaches to the ICO, and the Computer Misuse Act 1990 offences. For M3, summarise ISO 31000 (identify, analyse, evaluate, treat, monitor) or ISO/IEC 27001 (an information security management system with Annex A controls). For M4, analyse what an audit could reveal, such as unpatched systems or shared accounts, and how that changes priorities.

Example paragraph: An internal audit found that four former employees still had active accounts. The immediate impact is a risk of unauthorised access, an offence under the Computer Misuse Act 1990 if used, and a possible personal data breach. The wider impact is on process: the audit shows that the leavers procedure is not linked to account removal. The organisation should make HR notify IT automatically on a leaving date and run a monthly account review, turning a one-off finding into a lasting control.

How to answer LO4: managing organisational security

P7 needs an actual policy, not an essay about policies. Include purpose and scope, roles, acceptable use, access control, passwords and MFA, patching, backup, incident response and a disaster recovery plan with recovery time objective (RTO), recovery point objective (RPO), backup location and testing schedule. For P8, explain stakeholders’ roles in audits. M5 justifies each element by the risks you found; D3 evaluates whether the tools named in the policy (for example, a firewall, endpoint protection, a SIEM and backup software) actually suit the business’s size and budget.

Worked example: quantifying a security risk

Annualised loss expectancy (ALE) is a simple way to support M2 and D1. Suppose ransomware on the file server would affect an asset valued at £40,000 (data, downtime and recovery).

  1. Exposure factor (share of value lost per incident) = 25%.
  2. Single loss expectancy: SLE = asset value × exposure factor = £40,000 × 0.25 = £10,000.
  3. Annual rate of occurrence without controls: ARO = 0.5 (once every two years).
  4. ALE = SLE × ARO = £10,000 × 0.5 = £5,000 per year.
  5. Proposed control: offline backups plus endpoint detection costing £3,000 per year, reducing ARO to 0.1. New ALE = £10,000 × 0.1 = £1,000.
  6. Net annual benefit = (£5,000 − £1,000) − £3,000 = £1,000.

The control is worth adopting because it saves more than it costs. For D1, add what the number does not capture, such as reputational damage and ICO enforcement, which strengthens the case further. The figures here are illustrative; use estimates that fit your scenario.

Common mistakes that cost marks

  • Generic risk lists with no link to the scenario organisation.
  • Explaining DMZ, NAT and static IP without the example each one needs for P4.
  • Quoting the old Data Protection Act 1998 instead of the Data Protection Act 2018 and UK GDPR.
  • Writing about security policies instead of producing one for P7.
  • No disaster recovery detail: missing RTO, RPO, roles and testing.
  • D criteria answered with description rather than evaluation of strengths, weaknesses and fit.

How to move from Merit to Distinction

D1 needs a range of physical controls (locks, CCTV, server room access, secure disposal) and virtual controls (MFA, encryption, segmentation, monitoring) judged on cost, effectiveness and residual risk. D2 needs specific misalignments between policy and practice and their impact, with recommendations. D3 needs an honest evaluation of your chosen tools, including their limits. In each case, finish with a justified conclusion.

FAQs

Is Unit 5 Security part of the HND?

Yes. It is a Level 4 core unit, normally completed in the HNC year, and the credit counts towards the HND.

What is the difference between Unit 5 Security and Unit 10 Cyber Security?

Unit 5 focuses on organisational IT security, networks, risk and policy. Unit 10 focuses on cybercrime, threat actors, information assurance and incident response.

Do I need to build a real network?

Not usually. A clear diagram, often made in a tool such as Cisco Packet Tracer, is enough unless your brief asks for a configured simulation.

Which ISO standard should I use for M3?

ISO/IEC 27001 suits information security management; ISO 31000 suits general risk management. Pick one and apply it to the scenario.

For other HN Computing units, see our guides to Unit 4 Database Design and Development and Unit 7 Software Development Lifecycles. If you want feedback on your report or policy, get expert help with your BTEC assignment.

Get AI-Free Assignment Help Instantly

Facing Issues with Assignments? Talk to Our Experts Now! Download Our App Now!

WhatsApp Icon