BTEC HND Computing Unit 5 Security Assignment Answer Guide
This BTEC HND Computing computer security assignment guide covers Unit 5 Security (D/618/7406), the core security unit in the Pearson BTEC Higher Nationals in Computing (RQF). It is a Level 4 unit studied in the HNC year and counted towards the HND. You will find every P, M and D criterion explained, a report structure for each learning outcome, model paragraphs and a worked risk calculation.
Assignment brief: BTEC Level 4 Unit 5 Security assignment brief (D/618/7406) — read the full task first, then use this guide to plan and check your answer.
Related brief: BTEC Level 4 Unit 10 Cyber Security assignment brief (M/618/5661) — a different unit on cybercrime and incident response; useful extra reading but not the same criteria.
What the Unit 5 Security assignment asks you to do
Unit 5 briefs usually place you as a security consultant or junior IT security officer for an organisation, such as a small company moving services online. Across one or two assignments you:
- identify and discuss security risks and assess the organisation’s security procedures;
- explain network security solutions: firewall policies, VPNs, DMZ, static IP and NAT, and network monitoring;
- review risk assessment, data protection regulations, ISO standards and IT security audits;
- design a security policy with a disaster recovery plan and explain stakeholder roles in audits.
Learning outcomes for Unit 5 Security
| Learning outcome | What it covers |
|---|---|
| LO1 Assess risks to IT security | Threats and vulnerabilities, organisational security procedures, legal requirements, business continuity |
| LO2 Describe IT security solutions | Firewalls and VPNs, DMZ, NAT, static and dynamic IP, data security, monitoring, staff awareness |
| LO3 Review mechanisms to control organisational IT security | Risk assessment, ISO 31000 and ISO/IEC 27001, Data Protection Act 2018, Computer Misuse Act 1990, audits |
| LO4 Manage organisational security | Security policy, disaster recovery, compliance monitoring, auditing, penetration testing |
Pass, Merit and Distinction criteria explained
| Criterion | What it asks | How to evidence it |
|---|---|---|
| P1 | Discuss types of security risks to organisations | Malware, phishing, insider threat, data loss, unauthorised access, physical risks — each with impact on the scenario organisation |
| P2 | Assess organisational security procedures | Judge existing procedures (access control, backup, patching, passwords) as adequate or not |
| P3 | Discuss the potential impact of incorrect configuration of firewall policies and third-party VPNs | Concrete misconfigurations and what an attacker could do |
| P4 | Discuss, using an example for each, how a DMZ, static IP and NAT improve network security | Network diagram plus one example per technique |
| M1 | Analyse the benefits of implementing network monitoring systems with supporting reasons | IDS/IPS, SIEM, flow monitoring — benefits linked to specific risks |
| M2 | Propose a method to assess and treat IT security risks | Risk register, likelihood × impact scoring, treatment options |
| D1 | Evaluate a range of physical and virtual security measures to ensure integrity of organisational IT security | Balanced judgement of controls, cost and effectiveness |
| P5 | Review risk assessment procedures in an organisation | Steps, who is involved, frequency, weaknesses |
| P6 | Explain data protection processes and regulations as applicable to an organisation | UK GDPR and Data Protection Act 2018 principles, breach reporting, retention |
| M3 | Summarise an appropriate risk-management approach or ISO standard and its application in IT security | ISO 31000 or ISO/IEC 27001 applied to the scenario |
| M4 | Analyse possible impacts to organisational security resulting from an IT security audit | What an audit finds and how that changes controls and priorities |
| D2 | Recommend how IT security can be aligned with an organisational policy, detailing the security impact of any misalignment | Specific gaps between policy and practice and their consequences |
| P7 | Design a suitable security policy, including the main components of a disaster recovery plan | A written policy document with DR plan section |
| P8 | Discuss the roles of stakeholders in implementing security audits | Board, IT, data protection officer, staff, external auditors |
| M5 | Justify the security plan, giving reasons for the elements selected | Rationale linked to risks found earlier |
| D3 | Evaluate the suitability of the tools used in the policy to meet business needs | Fit, cost, usability and limits of each tool |
How to answer LO1 and LO2: risks and solutions
Base everything on the scenario organisation. Start with an asset list (customer database, website, staff laptops, payment system), then the risks to each.
- P1: discuss five or six risk types, each with a realistic example and impact.
- P2: assess current procedures in a table: procedure, strength, weakness, rating.
- P3: explain misconfigurations such as an “allow any” rule, unused open ports or a supplier VPN with excessive access.
- P4: draw the network with a DMZ for the public web server and explain NAT and static IP with examples.
- M1 and M2: analyse monitoring benefits and propose your risk method.
Example paragraph: The company’s third-party VPN gives its payroll supplier access to the whole internal network rather than only the payroll server. If the supplier’s credentials were stolen, an attacker could move from the VPN into the file server holding customer records. This breaks the principle of least privilege. Restricting the VPN to a single host and port, enforcing multi-factor authentication and logging every session would reduce the impact of a compromised account without stopping the supplier from doing its job.
How to answer LO3: controlling organisational security
LO3 is about governance. Review how the organisation assesses risk, then explain the data protection rules it must follow. Cover the UK GDPR principles, lawful basis, the 72-hour deadline for reporting notifiable breaches to the ICO, and the Computer Misuse Act 1990 offences. For M3, summarise ISO 31000 (identify, analyse, evaluate, treat, monitor) or ISO/IEC 27001 (an information security management system with Annex A controls). For M4, analyse what an audit could reveal, such as unpatched systems or shared accounts, and how that changes priorities.
Example paragraph: An internal audit found that four former employees still had active accounts. The immediate impact is a risk of unauthorised access, an offence under the Computer Misuse Act 1990 if used, and a possible personal data breach. The wider impact is on process: the audit shows that the leavers procedure is not linked to account removal. The organisation should make HR notify IT automatically on a leaving date and run a monthly account review, turning a one-off finding into a lasting control.
How to answer LO4: managing organisational security
P7 needs an actual policy, not an essay about policies. Include purpose and scope, roles, acceptable use, access control, passwords and MFA, patching, backup, incident response and a disaster recovery plan with recovery time objective (RTO), recovery point objective (RPO), backup location and testing schedule. For P8, explain stakeholders’ roles in audits. M5 justifies each element by the risks you found; D3 evaluates whether the tools named in the policy (for example, a firewall, endpoint protection, a SIEM and backup software) actually suit the business’s size and budget.
Worked example: quantifying a security risk
Annualised loss expectancy (ALE) is a simple way to support M2 and D1. Suppose ransomware on the file server would affect an asset valued at £40,000 (data, downtime and recovery).
- Exposure factor (share of value lost per incident) = 25%.
- Single loss expectancy: SLE = asset value × exposure factor = £40,000 × 0.25 = £10,000.
- Annual rate of occurrence without controls: ARO = 0.5 (once every two years).
- ALE = SLE × ARO = £10,000 × 0.5 = £5,000 per year.
- Proposed control: offline backups plus endpoint detection costing £3,000 per year, reducing ARO to 0.1. New ALE = £10,000 × 0.1 = £1,000.
- Net annual benefit = (£5,000 − £1,000) − £3,000 = £1,000.
The control is worth adopting because it saves more than it costs. For D1, add what the number does not capture, such as reputational damage and ICO enforcement, which strengthens the case further. The figures here are illustrative; use estimates that fit your scenario.
Common mistakes that cost marks
- Generic risk lists with no link to the scenario organisation.
- Explaining DMZ, NAT and static IP without the example each one needs for P4.
- Quoting the old Data Protection Act 1998 instead of the Data Protection Act 2018 and UK GDPR.
- Writing about security policies instead of producing one for P7.
- No disaster recovery detail: missing RTO, RPO, roles and testing.
- D criteria answered with description rather than evaluation of strengths, weaknesses and fit.
How to move from Merit to Distinction
D1 needs a range of physical controls (locks, CCTV, server room access, secure disposal) and virtual controls (MFA, encryption, segmentation, monitoring) judged on cost, effectiveness and residual risk. D2 needs specific misalignments between policy and practice and their impact, with recommendations. D3 needs an honest evaluation of your chosen tools, including their limits. In each case, finish with a justified conclusion.
FAQs
Is Unit 5 Security part of the HND?
Yes. It is a Level 4 core unit, normally completed in the HNC year, and the credit counts towards the HND.
What is the difference between Unit 5 Security and Unit 10 Cyber Security?
Unit 5 focuses on organisational IT security, networks, risk and policy. Unit 10 focuses on cybercrime, threat actors, information assurance and incident response.
Do I need to build a real network?
Not usually. A clear diagram, often made in a tool such as Cisco Packet Tracer, is enough unless your brief asks for a configured simulation.
Which ISO standard should I use for M3?
ISO/IEC 27001 suits information security management; ISO 31000 suits general risk management. Pick one and apply it to the scenario.
Need one-to-one support from a subject specialist? Our BTEC Level 5 (HND) assignment help service covers planning, feedback on drafts and referencing.
For other HN Computing units, see our guides to Unit 4 Database Design and Development and Unit 7 Software Development Lifecycles. If you want feedback on your report or policy, get expert help with your BTEC assignment.
BTEC HNC Unit 15 Healthcare Technology in Practice Assignment Answer Guide
This BTEC HNC Unit 15 Healthcare Technology in Practice assignment guide is written for learners on the Pearson BTEC Higher National Certificate in Healthcare Practice...
View or Download >>Unit 33 Marketing Insights and Analytics BTEC HND Assignment Answer Guide
This guide covers Unit 33 Marketing Insights and Analytics, a Level 5 unit in the Pearson BTEC Higher National Diploma in Business (marketing pathway). It...
View or Download >>BTEC HND Unit 30 Pharmacology and Medicine Management Answer Guide
This Unit 30 Pharmacology and Medicine Management BTEC HND assignment guide is for Level 5 learners on the Pearson BTEC Higher National Diploma in Healthcare...
View or Download >>BTEC HND Unit 9 Empowering Users of Health and Social Care Answer Guide
This guide covers Unit 9 Empowering Users of Health and Social Care Services from the Pearson BTEC HNC/HND in Health and Social Care (QCF). It...
View or Download >>Unit 8 Innovation and Commercialisation BTEC HND Assignment Answer Guide
This guide covers Unit 8 Innovation and Commercialisation (unit code M/508/0494), an optional unit in the Pearson BTEC Higher National Certificate and Diploma in Business...
View or Download >>Unit 5 Accounting Principles BTEC HND Business Assignment Answer Guide
This guide covers Unit 5 Accounting Principles (unit code Y/618/5038) from the Pearson BTEC Higher National Certificate and Diploma in Business. It is a Level...
View or Download >>Unit 1 Communication in Health and Social Care Assignment Answer Guide
This guide covers Unit 1 Developing Effective Communication in Health and Social Care (unit code R/600/8939) from the QCF BTEC Level 3 Nationals in Health...
View or Download >>Health and Social Care Strategies and Policies Assignment Answer Guide
This Health and Social Care Strategies and Policies assignment answer guide covers the Level 7 unit of the OTHM Level 7 Diploma in Health and...
View or Download >>Unit 32 Business Strategy BTEC HND Level 5 Assignment Answer Guide
This Unit 32 Business Strategy BTEC HND assignment answer guide covers the Level 5 Business Strategy unit of the Pearson BTEC Higher National Diploma in...
View or Download >>BTM5EIT Entrepreneurship in Tourism Assignment Answer Guide (Level 5)
This guide covers the Level 5 module BTM5EIT Entrepreneurship in Tourism, a module code used on some UK business and tourism management degree programmes (it...
View or Download >>BTEC HND Health and Social Care Unit 7 Social Policy Assignment Answers
This guide covers Unit 7 Social Policy from the Pearson BTEC Higher National (HNC/HND) in Health and Social Care, a unit that asks you to...
View or Download >>HND Unit 15 Psychology for Health and Social Care Assignment Answer Guide
This guide covers Unit 15 Psychology for Health and Social Care from the Pearson BTEC HNC/HND in Health and Social Care. The unit asks you...
View or Download >>