City and Guilds of London Institute · RQF Level 4

City & Guilds Level 4 Diploma in Information Security Professional Competence (QCF)

You don’t just earn this. You learn to use it, one-to-one, on your own real work.

  • LevelRQF Level 4
  • Total credits78
  • Units in this qualification27

Awarded by City and Guilds of London Institute · on the Ofqual register

Start here

See how this course maps onto your role

Ten quick questions, one per Future Fluency, asked against this qualification rather than a generic one.

Check my fluency, free

About 5 minutes · No card · Nothing to commit to

What you’ll learn

What each unit actually teaches you to do

This Level 4 diploma validates competence in information security practices. It is intended for digital technology practitioners who conduct audits, investigate incidents, manage user profiles, and handle risk management. Successful candidates will demonstrate the ability to operate systems and maintain security procedures.

These are the units City and Guilds of London Institute registers against this qualification. It is a catalogue, not a syllabus. Which of them you take depends on the combination the qualification requires, and that is set by the awarding body rather than by us. Every unit here is regulated, and every one you earn is yours to keep.

Carrying out Information Security auditsReal unit · City and Guilds of London Institute
You'll carry out Information Security audits by understanding audit purposes, preparing plans, gathering evidence through various methods, analysing findings, and reporting results to ensure compliance with standards.

What you'll be able to do

  • Carry out Information Security audit activities in accordance with relevant standards and procedures
Carrying out Information Security forensic examinationsReal unit · City and Guilds of London Institute
You'll learn to plan, conduct, document, and report on information security forensic examinations. The unit addresses legal and ethical considerations, chain of custody maintenance, and the application of appropriate tools and techniques during forensic investigations.

What you'll be able to do

  • Plan and prepare for carrying out Information Security forensic examinations.
  • Conduct Information Security forensic examinations in a structured and methodical manner.
  • Document and report on the findings of Information Security forensic examinations.
Carrying out Information Security forensic examinationsReal unit · City and Guilds of London Institute
It teaches you to carry out Information Security forensic examinations by understanding legal and ethical guidelines, conducting examinations, gathering and preserving digital evidence, and analysing findings to identify security breaches and vulnerabilities.

What you'll be able to do

  • Carry out Information Security forensic examinations in accordance with legal and ethical guidelines
Carrying out Information Security Incident Management activitiesReal unit · City and Guilds of London Institute
You'll learn to gather and evaluate information necessary for managing Information Security incidents, following organisational procedures to identify, document, and respond effectively to security events.

What you'll be able to do

  • Gather information effectively to manage Information Security incidents
  • Carry out Information Security Incident Management activities in line with organisational procedures
Carrying out Information Security Risk AssessmentReal unit · City and Guilds of London Institute
This unit equips learners to prepare for and conduct Information Security Risk Assessments by identifying policies, gathering organisational information, defining assessment scope, and documenting vulnerabilities and threats.

What you'll be able to do

  • Prepare for Information Security Risk Assessments by gathering relevant information and defining the scope
  • Carry out Information Security Risk Assessments, identifying vulnerabilities and potential threats
Carrying out Information Security Risk AssessmentReal unit · City and Guilds of London Institute
It teaches you to gather and assess information security risks using recognised methodologies. You'll identify threat sources, evaluate potential impacts, document findings, and report on risk levels to support informed risk management decisions.

What you'll be able to do

  • Gather information on Information Security risks from various sources.
  • Assess the likelihood and impact of identified Information Security risks.
  • Report on Information Security risks, including potential consequences and mitigation strategies.
Carrying out Information Security Risk ManagementReal unit · City and Guilds of London Institute
It teaches you to develop and implement information security risk contingency plans. You'll prioritise risks, allocate resources, and manage risks through policy implementation, monitoring, and evaluation to mitigate potential organisational threats.

What you'll be able to do

  • Develop information security risk contingency plans to mitigate potential threats.
  • Manage information security risks effectively within an organisation.
Carrying out Information Security auditsReal unit · City and Guilds of London Institute
You'll learn to prepare for and conduct information security audits. The unit covers defining audit scope, gathering documentation, conducting interviews, reviewing systems, analysing data, and documenting findings to assess information security controls.

What you'll be able to do

  • Prepare for information security audit activities, including defining the scope of the audit and gathering relevant documentation.
  • Carry out information security audit activities, including conducting interviews, reviewing systems, and analysing data.
Creating a procedural computer programReal unit · City and Guilds of London Institute
You'll learn to create, refine, test, and document procedural computer programs. The unit covers implementing software designs using procedural constructs, adhering to coding standards, improving program quality, and ensuring functionality through systematic testing.

What you'll be able to do

  • Implement a software design using procedural programming techniques, adhering to coding standards and best practises.
  • Refine a procedural program to improve quality, addressing issues related to efficiency, readability, and maintainability.
  • Test the operation of a procedural program thoroughly to ensure it functions correctly and meets the specified requirements.
  • Document a computer program comprehensively, including code comments, user manuals, and technical specifications.
Creating an event driven computer programReal unit · City and Guilds of London Institute
It teaches you to implement, refine, test, and document event-driven computer programs by applying event-driven programming principles and improving program quality through systematic evaluation.

What you'll be able to do

  • Implement a software design by utilising event-driven programming principles and techniques.
  • Refine an existing event-driven program to improve its overall quality, performance, and maintainability.
  • Test the operation of an event-driven program to ensure it functions correctly and meets specified requirements.
  • Document an event-driven program comprehensively, including its design, functionality, and usage.
Creating an object oriented computer programReal unit · City and Guilds of London Institute
It teaches you to design, develop, test, and document object oriented computer programs. You'll apply programming principles such as encapsulation, inheritance, and polymorphism to create robust software solutions that meet design specifications.

What you'll be able to do

  • Implement a software design using object oriented programming principles, including encapsulation, inheritance, and polymorphism.
  • Refine an object oriented program to improve quality, addressing issues related to efficiency, readability, and maintainability.
  • Test the operation of an object oriented driven program thoroughly to ensure it functions correctly and meets the specified requirements.
  • Document an object oriented driven program comprehensively, including class diagrams, user manuals, and technical specifications.
Designing and developing event-driven computer programsReal unit · City and Guilds of London Institute
It teaches you to design, develop, and test event-driven computer programs that respond to user interactions and system events, applying programming principles and producing comprehensive documentation.

What you'll be able to do

  • Design event-driven programs to address loosely-defined problems, taking into account user interactions and system events
  • Produce a working event-driven program which meets the design specification, demonstrating responsiveness and efficient event handling
  • Develop event-driven programs that reflect established programming and software engineering practice, including event delegation and asynchronous programming
  • Develop test strategies and apply these to event-driven programs, ensuring correct event sequencing and error handling
  • Develop design documentation for use in program maintenance and end-user documentation, providing clear explanations of event flows and program logic
Designing and developing object-oriented computer programsReal unit · City and Guilds of London Institute
This unit covers the design, development, and testing of object-oriented computer programs, including applying programming principles such as encapsulation, inheritance, and polymorphism to produce functional software that meets specified requirements.

What you'll be able to do

  • Design object-oriented programs to address loosely-defined problems, taking into account user needs and system requirements
  • Produce a working object-oriented program which meets the design specification, demonstrating functionality and adherence to standards
  • Develop object-oriented programs that reflect established programming and software engineering practice, including coding conventions and design patterns
  • Develop test strategies and apply these to object-oriented programs, ensuring robustness and reliability
  • Develop design documentation for use in program maintenance and end-user documentation, providing clear and concise information
Designing and developing procedural computer programsReal unit · City and Guilds of London Institute
This unit develops learners' ability to design, develop, and test procedural computer programs addressing loosely-defined problems. You'll analyse user needs, produce working programs following software engineering practices, and apply comprehensive testing strategies.

What you'll be able to do

  • Design procedural programs to address loosely-defined problems, considering user needs and system requirements.
  • Produce a working procedural program which meets the design specification, demonstrating functionality and adherence to coding standards.
  • Develop procedural programs that reflect established programming and software engineering practice, including modularity, reusability, and maintainability.
  • Develop test strategies and apply these to procedural programs, ensuring comprehensive coverage and identifying potential defects.
  • Develop design documentation for use in program maintenance and end-user documentation, providing clear and concise information about the program's functionality and architecture.
Develop own effectiveness and professionalismReal unit · City and Guilds of London Institute
You'll develop personal and professional skills, work effectively within teams, understand professional IT practice, and gain knowledge of ethical and legislative frameworks to improve organisational effectiveness.

What you'll be able to do

  • Develop own personal and professional skills to enhance performance and career progression.
  • Work effectively as a member of a team to achieve defined goals and implement agreed plans.
  • Understand what is meant by professional practice in the context of IT.
  • Understand the ethical and legislative environment relating to IT activities and their implications.
  • Improve organisational effectiveness through the application of professional skills and knowledge.
Health and Safety in ICTReal unit · City and Guilds of London Institute
This unit covers compliance with Health and Safety legislation and procedures in ICT environments, including accident reporting, safe working practices, and the importance of risk assessments when using ICT equipment.

What you'll be able to do

  • Comply with relevant Health and Safety procedures in an ICT environment
IT & Telecoms System ManagementReal unit · City and Guilds of London Institute
You'll understand the principles and practices of managing IT and telecoms systems. The unit covers reviewing system functionality, identifying risks, and implementing management activities to ensure effective operation and alignment with organisational objectives.

What you'll be able to do

  • Understand how to manage IT and telecoms systems effectively
  • Review the functionality of IT and telecoms systems and their management processes
  • Manage IT and telecoms systems according to organisational policies and procedures
IT & Telecoms System OperationReal unit · City and Guilds of London Institute
This unit provides learners with an understanding of IT and telecoms system architecture and operation. You'll specify system parametres, control system functions, and manage maintenance activities to ensure optimal performance and adherence to organisational requirements.

What you'll be able to do

  • Understand the technical architecture of IT or Telecoms systems, including hardware, software, and network components.
  • Understand how to specify system operation parameters, including performance metrics, security settings, and resource allocation.
  • Control the operation of systems, ensuring they function according to specified parameters and service level agreements.
  • Control system maintenance activities, including scheduling, execution, and documentation of maintenance tasks.
Investigating Information Security incidentsReal unit · City and Guilds of London Institute
You'll learn to investigate Information Security incidents by gathering information from multiple sources, analysing data, maintaining evidence integrity, and following established procedures to determine incident causes.

What you'll be able to do

  • Gather relevant information from various sources to investigate Information Security incidents effectively.
  • Investigate Information Security incidents thoroughly, following established procedures and protocols.
Investigating Information Security incidentsReal unit · City and Guilds of London Institute
This unit covers preparation for and investigation of information security incidents. You'll learn to identify evidence sources, maintain chain of custody, consider legal and ethical issues, analyse data, interview witnesses, determine root causes, and document investigation outcomes.

What you'll be able to do

  • Prepare for Information Security incident investigations, including identifying potential sources of evidence and establishing a chain of custody.
  • Investigate Information Security incidents, including analysing logs, interviewing witnesses, and determining the root cause.
Investigating and Defining Customer Requirements for ICT SystemsReal unit · City and Guilds of London Institute
You'll control investigations of existing and proposed ICT systems, ensuring adherence to organisational policies and procedures while analysing information to identify customer needs and system constraints.

What you'll be able to do

  • Control the investigation of existing and proposed ICT systems and processes, ensuring adherence to relevant organisational policies and procedures
  • Analyse gathered information to accurately identify customer needs and system constraints, documenting findings in a clear and concise manner
Investigating and defining customer requirements for ICT systemsReal unit · City and Guilds of London Institute
You'll investigate existing ICT systems and processes to define customer requirements, gathering and analysing information to identify needs and constraints from both technical and business perspectives.

What you'll be able to do

  • Investigate existing systems and processes to understand their functionality and limitations
  • Analyse information gathered to identify needs and constraints for ICT systems, considering both technical and business perspectives
System ManagementReal unit · City and Guilds of London Institute
You'll gain knowledge of system administration, including user management, resource allocation, and security settings. The unit covers performing routine maintenance tasks such as software updates, backups, and performance monitoring, alongside managing system configurations.

What you'll be able to do

  • Understand how to administer a system, including user management, resource allocation, and security settings.
  • Administer a system by performing routine tasks such as software updates, backups, and performance monitoring.
  • Change system configurations to meet specific requirements, ensuring minimal disruption to users.
System OperationReal unit · City and Guilds of London Institute
It teaches you to operate systems according to established procedures, ensuring efficient use of resources. You'll develop skills in system operation, troubleshooting common problems, and maintaining system operating procedures within organisational guidelines.

What you'll be able to do

  • Operate the system according to established procedures
  • Operate systems effectively and efficiently
  • Maintain and implement system operating procedures in accordance with organisational guidelines
Testing the security of Information SystemsReal unit · City and Guilds of London Institute
You'll learn to plan, prepare, execute, and report on security testing of information systems. The unit covers selecting testing tools, developing test plans, setting up environments, identifying vulnerabilities, analysing results, and recommending remediation actions.

What you'll be able to do

  • Plan and prepare to conduct security testing on Information Systems.
  • Execute security tests, using appropriate tools and techniques.
  • Analyse and interpret the results of security tests.
  • Report on test results, including vulnerabilities identified and recommendations for remediation.
Testing the security of Information SystemsReal unit · City and Guilds of London Institute
It teaches you to plan and execute security testing on information systems by identifying threats and vulnerabilities, developing testing plans, prioritising activities, and reporting findings with recommendations.

What you'll be able to do

  • Plan security testing activities, considering relevant threats, vulnerabilities, and security requirements.
  • Carry out security testing procedures effectively, using appropriate tools and techniques to identify security weaknesses.
User Profile AdministrationReal unit · City and Guilds of London Institute
You'll gain knowledge and skills to administer user profiles effectively, including creating, modifying, and deleting user accounts. The unit emphasises managing user permissions and security considerations to ensure appropriate access and data protection.

What you'll be able to do

  • Administer user profiles, including creating, modifying, and deleting user accounts and managing user permissions
  • Administer user profiles effectively, ensuring data security and appropriate access levels for different users

The honest bit

You’ve started things before

Most courses were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

Your passport

Every credit is a stamp you keep

Level 4 credits are regulated. They don’t vanish when a subscription ends or a website closes. They travel to any employer, and Zavmo keeps the map of what you’ve earned and what’s next.

Carrying out Information Security auditsCarrying out Information Security forensic examinationsCarrying out Information Security forensic examinationsCarrying out Information Security Incident Management activitiesCarrying out Information Security Risk AssessmentCarrying out Information Security Risk AssessmentCarrying out Information Security Risk ManagementCarrying out Information Security audits

Each stamp is a real unit registered against this qualification.

Who’d teach you this

The Evidence Evaluator

Assessor

Helps you show what you can actually do, gathering the evidence that proves it as you learn.

Meet all twelve tutors

Where this connects

Where these credits take you

A qualification is never a dead end here. See the jobs its credits open, the national occupational standards its units map to, and the future skills they quietly build.

See Your Progress GrowIllustration
City & Guilds Level 4 Diploma in Information Security Professional Competence (QCF)
  • Assist in Implementing Vulnerability Assessment Processes
  • Carry Out Intrusion Detection and Analysis
  • Carry out information security audit, compliance and assurance activities
  • Carry out information security governance activities
  • Carry out information security identity and access management activities
  • Carry out information security incident investigation and management activities
  • Carry out information security risk assessment and management activities
  • Carry out information security vulnerability assessments
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

Where this can lead

Information Security Analyst

Your journey starts here, but where it goes is really up to you. We'll provide the tools, the training, and the opportunities, but your drive and curiosity will define your ultimate path. This is a field with endless possibilities, and we're excited to see where you take it.

See the whole journey →

Showing 6 roles, drawn from 22 job records mapped to this qualification.

Skills it covers

What the job actually needs. These are the standards the units are built against, in the words employers and awarding bodies already use for the work itself.

Assist in Implementing Vulnerability Assessment ProcessesCarry Out Intrusion Detection and AnalysisCarry out information security audit, compliance and assurance activitiesCarry out information security governance activitiesCarry out information security identity and access management activitiesCarry out information security incident investigation and management activitiesCarry out information security risk assessment and management activitiesCarry out information security vulnerability assessmentsConduct Information Security Audit Activities Under SupervisionContribute to information security identity and access management activitiesContribute to information security risk assessment and management activitiesDirect and Be Fully Accountable for Information Security AuditDirect information security incident management and forensicsDirecting Information Assurance: Strategy, Policy, GovernanceLead Information Risk Assessment ActivitiesManage information security audit, compliance and assurance activitiesManage information security incident investigation and management activitiesPerform Incident Management Activities Under Supervision+2 more

How you’ll actually learn this

One-to-one, on your own real work

A qualification is usually something done to you: sit the class, sit the exam, hope it sticks. Here it’s the opposite. You learn it one-to-one with a companion, on your own real work, and you keep going until you can use it, not just recall it.

One-to-one, on your real workNo lectures, no past-papers. Every unit is practised on the actual tasks your job throws at you, a tutor beside you, not a video in front of you.
Taught to the top, not the testMost courses stop at remembering. Your companion keeps climbing: analysing, judging, creating. That’s the part a machine can’t do for you.
Credits you keep, a map that continuesEvery unit is regulated and yours for good. The day you finish, Zavmo already knows the next role your new credits open.
Carrying out Information Security auditsLevel 4

Applied to your work in any of these jobs

Learners will carry out Information Security audits by understanding audit purposes, preparing plans, gathering evidence through various methods, analysing findings, and reporting results to ensure compliance with standards.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.
Your PlanIllustration

Built for City & Guilds Level 4 Diploma in Information Security Professional Competence (QCF)

24 units in this credential, in the order it lists them, awarded by City and Guilds of London Institute.

  1. Carrying out Information Security audits
  2. Carrying out Information Security forensic examinations
  3. Carrying out Information Security Incident Management activities
  4. Carrying out Information Security Risk Assessment
  5. Carrying out Information Security Risk Management
  6. Carrying out Information Security audits

and 18 more in the full unit list below.

These are the real units of this credential, in its own order. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every unit is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

Why it sticks

Most courses stop at remembering

There’s a well-known ladder of how deeply you learn something, called Bloom’s Taxonomy. Most courses get you up the first two rungs: you remember some facts, you pass a test, you forget it. Real skill lives at the top. Judging, deciding, creating. And this isn’t a generic ladder: every rung has a named Zavmo tutor who walks you up it.

  1. 6CreateThe Creative Catalyst
  2. 5EvaluateThe Evidence Evaluator
  3. 4AnalyseThe Analyst
  4. 3ApplyThe Coach
  5. 2UnderstandThe Connector
  6. 1RememberThe Builder

Where most courses leave you Where Zavmo takes you

Why this matters: AI can already remember and understand for you. What it can’t do is take your real problem and judge the right call. So the only learning worth paying for is the learning that takes you to the top. That’s exactly what a tutor doing it with you, on your real work, is for.

The value

Why the companion is worth £70 a month

You’re not paying for the units. They’re regulated, and the same wherever you earn them. You’re paying for the one thing that decides whether you actually get there: a companion that makes them stick, on your real work.

That is one-to-one on this qualification, every day, on the work you already do, for £70 a month. Your first module is free, so you can see the teaching before you pay for any of it. Billed monthly, cancel any time and billing stops.

Earned on your own work, taught to the top.

Everything you just read, learned one-to-one on the job you already do. Your first module is free, so you can see the teaching before you pay for any of it.

Build my plan, free

No card. See how this qualification maps onto your role and meet the tutors who’d teach it, free. The learning begins when you subscribe. It’s £70 a month, billed monthly. Cancel any time and billing stops.