The unit as writtenunit scope
This is the official scope of the national unit, kept here (folded) so the intended coverage is visible at a glance. The notes below follow it where it still holds and go past it where current practice has moved on.
Unit: ICTICT223 Install software applications, from the ICT Information and Communications Technology Training Package. In the Certificate II in Applied Digital Technologies (ICT20120) it is an elective. There are no prerequisites and no licensing requirements.
The unit covers selecting and installing basic software applications on systems, including identifying software requirements, integrating applications and developing testing schedules. It applies to people such as digital developers and support desk technicians who contribute to installing software.
What the unit expects, from its three elements:
Prepare to install software applications. Confirm the work brief and tasks according to organisational policies and procedures; identify installation, workflow and delivery requirements from the brief; identify software constraints in consultation with the right people.
Obtain the installation software. Investigate the software options for the system; select the option that fits the brief; source the software components; record the licensing requirements; confirm that the system meets the application's minimum hardware and operating system requirements.
Integrate and test the software. Incorporate the application into the system as the brief requires; confirm the installation complies with organisational policies and procedures; test the application and raise any issues; document outstanding issues and send them to the right people; complete the workplace documentation.
Knowledge the unit covers: functions and features of basic hardware and software in relation to computer systems; standard hardware and operating system requirements of applications; methods to incorporate applications into systems; configuration instructions and techniques for installation, workflow and delivery; testing and acceptance procedures; common software constraints; operating systems the organisation supports; organisational documentation formats; organisational procedures for the work.
Performance the unit expects: install at least two different applications, each on a different computer system; configure systems to accept new or upgraded software; apply organisational policies and procedures.
Assessment conditions: a workplace or simulated environment with a computer and an additional system to install on, the software to be installed, opportunities to interact with others, and a work brief and organisational procedures.
Source: the ICTICT223 Assessor Guide v4.4 in the CDU unit folder, which reproduces the national unit's elements, performance criteria and assessment requirements; the unit is published at training.gov.au. Nominal hours are not recorded here.
What software is
Software is the set of instructions that tells a computer what to do; hardware is the physical equipment that carries them out. Software is usually grouped three ways:
- System software runs the computer itself: the operating system, drivers and utilities. It controls memory, storage, the display and peripherals.
- Application software does work for the user: word processors, spreadsheets, accounting, design, browsers, games.
- Network software coordinates communication between connected computers.
Firmware is software permanently stored on a chip inside a device (a motherboard's UEFI, a router's operating system), sometimes called "hard software". It is updated far less often but it is still software and still needs patching.
Software lives on long-term storage (an SSD or hard drive). When you run a program, the operating system loads its instructions into RAM and the processor executes them. That is why RAM matters so much when installing new software: every open program is competing for it.
Did you know? The first "killer app" for personal computers, a program so useful that people bought the hardware just to run it, was VisiCalc, the 1979 spreadsheet for the Apple II. Its successors Lotus 1-2-3 and Excel did the same for the IBM PC. WordStar, also from 1979, did the same for word processing.
Preparing: the brief, the constraints and the people
Every installation starts with a work brief: what software, on which machines, for which users, by when, and under what conditions. Confirm it before you begin. From the brief, work out three kinds of requirement:
- Installation requirements: which machines, which version, which edition, which settings, which licence.
- Workflow requirements: how the software fits the way people work. Does it need to open files from another program, connect to a shared drive, sync to the cloud, or integrate with email?
- Delivery requirements: when and where the work happens, how much downtime is acceptable, and how the handover will be done.
Then identify the constraints, the things that limit what can be installed or how:
- Hardware: processor, RAM, storage space, graphics, screen resolution.
- Operating system: the edition and version the vendor supports.
- Compatibility with existing software, including conflicts (two real-time antivirus products, for example, will fight each other).
- Licensing: cost, number of seats, terms of use.
- Security policy: whether users may install software themselves, which vendors are approved, whether the application needs to be allowlisted.
- Network and internet: bandwidth for downloads and cloud services.
- Budget and time.
Constraints are identified with the people who own them: the client or manager for budget and timing, the ICT manager for policy, the users for workflow.
Recommending software for a new business
A useful exercise is to specify everything a small business needs. Take a two-person graphic design studio working from home, who want industry standard tools so they can exchange files easily with clients and other studios:
| Need | Common choices in 2026 |
|---|---|
| Operating system | macOS or Windows 11; both run the major design packages |
| Office and email | Microsoft 365 Business Standard (Word, Excel, Outlook, Teams, OneDrive) or Google Workspace |
| Accounting | Xero or MYOB, both widely used in Australia and both connecting to bank feeds and the ATO |
| Browsers | At least two current browsers for testing and fallback, such as Chrome, Edge, Firefox or Safari |
| Security | Built-in Microsoft Defender or Apple's protections, or a business endpoint product; plus a password manager and multi-factor authentication on every account |
| Raster graphics | Adobe Photoshop; alternatives include Affinity (owned by Canva) and GIMP |
| Vector graphics | Adobe Illustrator; alternatives include Affinity and Inkscape |
| Layout | Adobe InDesign or Affinity |
| 3D graphics | Blender (free and widely used), Autodesk 3ds Max or Maya, Cinema 4D |
| Video | Adobe Premiere Pro or DaVinci Resolve |
| Backup | Cloud backup plus a local copy |
The justification is what matters: industry standard file compatibility, cost (subscription versus free), ease of learning, hardware demands, and support.
Hardware and operating system requirements
Every vendor publishes minimum and usually recommended requirements. The minimum is the least capable system the vendor says will run the software at all, typically at its lowest settings, and often measured on a clean test machine with nothing else running. The recommended specification is what it needs to run as designed. Minimums have a marketing element, so treat them as a floor.
Which one should you work to? If the software is used occasionally and speed does not matter, the minimum may do. If people use it all day, meet or exceed the recommended specification: a few seconds' wait, repeated through a week and multiplied across users, adds up to real lost hours. Past a point, though, more hardware stops helping; systems have bottlenecks, and doubling the RAM will not fix a slow hard drive.
As a benchmark, Windows 11 needs a compatible 64-bit processor at 1 GHz or faster with at least two cores, 4 GB RAM, 64 GB storage, UEFI firmware with Secure Boot capability, TPM 2.0, a DirectX 12 compatible graphics adapter with a WDDM 2.0 driver, and a 720p display larger than 9 inches with 8 bits per colour channel. Microsoft publishes these at learn.microsoft.com and in its Windows 11 specifications page.
Installing onto an existing machine
Adding software to a computer that is already in use needs more thought than a fresh build:
- Will the existing hardware run the new software well, not just run it?
- Is the software supported on this operating system version?
- Will it slow down or break the applications already there by taking memory, processor time or disk space they need?
- Does it conflict with something installed (another antivirus, a different version of the same runtime)?
- New software is written for new hardware and often uses more resources than its stated minimum.
RAM in particular
RAM is the most common limit on older machines. Before installing a demanding application, check how much RAM is fitted and how much is typically in use (Task Manager, Performance, Memory). If there is not enough:
- Check what the motherboard supports before buying anything: the RAM generation (DDR3, DDR4 and DDR5 are physically and electrically incompatible with each other), the number of slots, the maximum capacity, and the supported speeds. The PC or motherboard maker's manual, or a memory vendor's configurator tool, gives this.
- Match the existing modules (capacity, speed, timings) or replace them as a matched pair to keep dual-channel performance.
- If the machine cannot take enough RAM, or the cost is close to that of a replacement, recommend replacing the machine, or a lighter alternative application.
Where software comes from, and staying safe getting it
How you source software is a security decision. Attackers regularly publish fake download sites and pay for search advertisements that look like the real vendor, serving installers with malware bundled in. Safe practice:
- Download only from the vendor's official site, the Microsoft Store or Apple App Store, or a trusted package manager.
- Check the installer's digital signature: in Windows, right-click the file, Properties, Digital Signatures, and confirm the signer is the vendor. Unsigned installers from unknown sources should not be run.
- Where the vendor publishes a checksum, compare it. In PowerShell,
Get-FileHash .\installer.exeprints the SHA-256 hash to compare with the vendor's value. - Never use cracked or pirated software; beyond the legal problem, it is one of the most common ways malware reaches a machine, and it usually means turning off updates.
Installing with a package manager
Windows 11 includes winget, the Windows Package Manager, which installs software from a curated repository by name. It is how many technicians now install and update applications, because it is fast, scriptable and repeatable:
winget search libreofficefinds the package and its exact ID.winget install --id TheDocumentFoundation.LibreOffice -einstalls it.winget listshows what is installed.winget upgrade --allupdates everything winget knows about.winget uninstall --id TheDocumentFoundation.LibreOffice -eremoves it.
macOS users often use Homebrew for the same purpose, and Linux distributions have always worked this way (apt, dnf).
Installing by hand: the general pattern
- Confirm the system meets the requirements and that you have the licence or account.
- Create a system restore point before significant installs.
- Close other applications.
- Run the installer as administrator only if required. Read each screen: choose Custom or Advanced install where offered, and untick bundled extras (browser toolbars, trial software, changed home pages).
- Choose the install location and components required by the brief.
- Activate or sign in with the organisation's licence.
- Apply updates straight away; the installer is often behind the current version.
- Test that it opens, saves, prints and does what the user needs.
- Record it in the software inventory.
To uninstall: Settings, Apps, Installed apps, the three-dot menu beside the app, Uninstall; or Control Panel, Programs and Features (appwiz.cpl); or winget uninstall. Some security products need the vendor's own removal tool to remove every component.
A worked example: an office suite
LibreOffice is the leading free, open-source office suite and is the one to use where a free suite is needed. (Older course material names Apache OpenOffice, but it is updated rarely and slowly; its latest release, 4.1.16, came in November 2025, and the Apache security team rated the project's risk status "red" in March 2026 over unfixed security issues. LibreOffice, a fork of the same original code, is actively maintained.) Install it from libreoffice.org or with winget, open Writer and Calc, create and save a test document in both the native format and the Microsoft format (.docx, .xlsx), reopen the files, and print a test page. That is a basic functional test.
A worked example: antivirus
Windows 11 includes Microsoft Defender Antivirus, switched on by default. Many organisations and home users also install a third-party product such as AVG, Avast, Bitdefender or Norton. When a third-party antivirus is installed and registered with Windows, Defender switches itself to a passive role, because two real-time scanners on one machine conflict and can quarantine each other's files.
The routine tasks, which look slightly different in every product but always exist:
- Check for program updates. In Defender, Windows Update handles it. In AVG, open the application and look in the menu, under Settings, for the update options; product menus move between versions, so the vendor's help pages are the reference.
- Update the virus definitions (the database of known threats). Defender: Windows Security, Virus & threat protection, Protection updates, Check for updates; or in PowerShell,
Update-MpSignature. Third-party products usually update automatically and offer a manual "update now" button. - Run a manual scan. A quick scan checks the places malware usually hides; a full scan checks everything; a custom scan checks a chosen file, folder or drive (in Windows you can also right-click a file and choose to scan it). Defender: Windows Security, Virus & threat protection, Scan options; or
Start-MpScan -ScanType QuickScan. - Schedule automatic scans at a time that causes the least disruption, such as overnight or during lunch, when the computer is on but not in use. The machine must be powered on (or set to wake) for the scan to run. Defender's scheduled scans are managed through Task Scheduler or, in organisations, through Intune policy.
- Handle detections. Quarantine moves a suspicious file into a locked area where it cannot run, without deleting it, so a false positive can be restored. Defender records detections in Protection history.
To test that antivirus is working without using real malware, security professionals use the EICAR test file, a harmless text string published by the European Institute for Computer Antivirus Research that every antivirus product agrees to detect as if it were a virus.
Keeping track: the software inventory
A software inventory records what software is installed on which machines. Small organisations can keep one in a spreadsheet; larger ones use IT asset management or endpoint management tools (such as Microsoft Intune, Lansweeper or ManageEngine) that collect it automatically.
At minimum, record enough to find the machine and account for every licence:
- Device: location, asset number or serial number, and the main user and their contact details.
- Software: vendor, product name, version (and build), where it is installed, licence type and licence key or subscription reference, installation date, and the date of the last update check.
Record the operating system and large suites first, then the smaller applications. An inventory is the basis for licence compliance, patching, security response ("which machines run the vulnerable version?") and budgeting.
Deploying to many machines
Imaging, then and now
For decades, organisations built one reference machine with the operating system, settings and applications, captured it as an image, and cloned it onto every computer. Imaging keeps machines identical and easy to manage as a group, and ensures every machine has at least the minimum security installed. Its weaknesses: images go out of date the day they are made, one image fits different hardware poorly, and users with special needs still need extra software. Every machine that receives an image still needs its own valid licences.
Current practice in most Windows organisations has moved away from imaging. New devices are enrolled with Windows Autopilot straight from the vendor, and Microsoft Intune installs applications, applies settings and pushes updates over the internet, with no image at all. Applications are packaged (as MSI, MSIX or Win32 app packages) and assigned to groups of users or devices. The technician's job shifts from building machines to packaging, assigning and monitoring.
Implementation plans
An implementation plan is the document that says how a rollout will happen. Starting with one creates a shared understanding of the goal, a roadmap, clear responsibilities and a way to judge success. It also protects against scope creep, where a project quietly grows beyond what was agreed.
A software implementation plan covers:
- Goals and objectives: the high-level outcome and the measurable steps towards it.
- Scope: which software, which machines, which users; and what is not included.
- Timeline and milestones, including realistic download, install, update and scan times, with contingency time.
- Minimising disruption: after hours, weekends, staged rollout, or building and testing machines in a workshop and delivering them ready to use.
- Locations and access arrangements.
- Order of work: operating system first, then drivers and updates, then security software, then applications, then their updates.
- Data: what must be backed up, how it will be transferred to the new setup, and how the restore will be tested; and how existing user accounts and sign-ins will work afterwards.
- Contingencies: spare hardware, rollback steps, extra time.
- Testing: with realistic user accounts, devices and files.
- Acceptance: how client satisfaction will be judged (a walkthrough, a checklist, a survey, a follow-up call) and the formal sign-off, which usually triggers final payment.
flowchart LR A[Confirm brief] --> B[Check requirements<br/>and constraints] B --> C[Source software<br/>and licences] C --> D[Pilot install<br/>and test] D --> E[Roll out] E --> F[Test and fix] F --> G[Client acceptance] G --> H[Update inventory<br/>and documentation] D -. issues .-> B
Testing, acceptance and raising issues
Testing confirms the software does what the brief requires on the actual machines, for the actual users. Test the obvious (it opens, saves, prints) and the specific (it opens the client's existing files, it connects to the shared drive, it works under a standard user account, not just an administrator one).
When something does not work as expected:
- Stop and document it: what you were doing, what happened, any error message (screenshot it), and whether you can repeat it.
- Record the details the next person will need: software name and exact version, operating system and build, hardware specifications, the asset number and location of the machine, and the date and time.
- Check the vendor's known issues and support pages.
- Raise it with the right person: your supervisor, the ICT manager, the client, or the vendor's support, according to the organisation's procedure.
- Record any outstanding issues in the handover documentation, and send it to the people who need it.
When issues are not fixed in time
Support teams manage issues with ticketing systems (ServiceNow, Jira Service Management, Freshdesk and similar), which record every request, who owns it, and how old it is. Service level agreements (SLAs) set response and resolution times by priority. If an issue is not resolved in the agreed time, it is escalated to a more senior technician or the vendor, and the client is kept informed of progress. Ticket ageing alerts and SLA reports are how a team makes sure issues do not quietly stall.
Patching and software security
Most successful attacks exploit known vulnerabilities for which a patch already exists. The WannaCry ransomware outbreak of May 2017 is the textbook case: Microsoft had released the patch for the vulnerability it used in March 2017, two months earlier, and the organisations hit were the ones that had not applied it.
Why do organisations delay patches? Usually because a patch might break a line-of-business application, so they test first. Testing is sensible, but long delays trade a known, small cost (testing and upgrading) for an unknown and potentially much larger one (a breach). Some legacy applications only run on unsupported operating systems that no longer receive patches at all, which is a risk that has to be isolated, replaced or formally accepted by management.
Australia's baseline is the Australian Signals Directorate's Essential Eight. Two of its eight strategies are patching applications and patching operating systems. At the first maturity level, security patches for internet-facing and core applications (browsers and their extensions, office suites, email clients, PDF software and security products) should be applied within two weeks of release, and within 48 hours where a vulnerability is critical or an exploit exists; applications that are no longer supported by their vendor should be removed. The current maturity model was published in November 2023.
Storing data
Installing an application raises the question of where its data will live. The three broad options:
| Local storage | Network attached storage (NAS) | Cloud storage | |
|---|---|---|---|
| What it is | A drive inside or plugged into the computer | A dedicated storage device on the local network serving files to many users, usually over SMB | Storage in a provider's data centres, reached over the internet |
| Advantages | Fast, cheap, works offline, simple | Shared by the office, central, can use RAID for drive redundancy, data stays on premises | Accessible anywhere, shared easily, provider handles hardware, strong built-in redundancy, scales on demand |
| Disadvantages | Single point of failure, hard to share, easily lost or stolen, backup is the user's job | Up-front cost, needs some expertise, still needs off-site backup, can be hit by ransomware on the network | Ongoing subscription, depends on internet connection, data held by a third party (check where), speed limited by bandwidth |
None of these is a backup on its own. RAID in a NAS protects against a drive failing, not against deletion, corruption or ransomware, and cloud sync faithfully syncs deletions. The standard advice is the 3-2-1 rule: three copies, on two types of media, one of them off-site. In remote parts of the Northern Territory, where internet connections can be slow or satellite-based, cloud-only arrangements need particular thought about bandwidth and outages.
Procurement
Procurement is the structured process a business follows to acquire goods and services. It differs from simple purchasing: it defines the need, invites and compares options, assesses risk and value, and documents the decision. Most organisations set a dollar threshold; below it staff can buy directly, above it the procurement process applies.
Why bother? To get goods and services that genuinely meet the organisation's needs, at the best value over their life (not just the lowest price), with appropriate warranties and support, from suppliers who can reliably deliver, through a process that is fair and accountable.
A Darwin example shows the risk side of the reasoning. When uniforms were procured for the Arafura Games, a small local family business quoted far below interstate competitors, but the contract went to a larger interstate supplier. The deciding factor was risk: a small business with no redundancy could be derailed by a single illness or mishap in the family, and the event could not run without its uniforms. Value in procurement includes the risk of non-delivery. (Many public bodies now also weight local content; the Northern Territory Government's procurement framework includes a "buy local" policy, which shows that these judgements are always a balance.)
Licences and intellectual property
Intellectual property (IP) is property in creations of the mind: copyright, patents, trademarks, designs and trade secrets. Software is protected by copyright, and in Australia that is the Copyright Act 1968 (Cth). You never own the software you buy; you own a licence to use it on the terms of its end user licence agreement (EULA).
- Copyright is the owner's exclusive right to copy, distribute, adapt and publish a work. It arises automatically. Proprietary software keeps the source code private and licenses use under restrictive terms.
- Open source licences grant everyone the rights to use, study, change and share the software and its source code. Permissive open source licences (such as MIT, BSD and Apache) allow the code to be reused in closed, commercial products.
- Copyleft is a licensing technique within open source: you may use, modify and redistribute the work, but anything you distribute that is derived from it must carry the same freedoms. The GNU General Public License (GPL), used by Linux, is the best-known copyleft licence.
Licensing models you will record in an inventory:
- Perpetual: a one-off purchase to use a version indefinitely, with upgrades bought separately.
- Subscription: a monthly or annual fee for the current version, updates and often cloud services, usually covering several devices per user. Microsoft 365 and Adobe Creative Cloud work this way.
- Per user or per device; volume or site licences for organisations.
- Freeware and free open source.
- Trial or evaluation, which expires.
Software piracy, copying or using software without a licence, grew with floppy disks when software was expensive and copying was easy. Vendors fought back with activation and anti-copying measures, trial versions, and eventually subscription pricing, which lowered the entry cost enough to make legitimate use affordable. For an organisation, unlicensed software is a legal and financial liability, and pirated installers are a major source of malware.
Artificial intelligence and software installation
AI changes this unit in three ways.
AI features increasingly arrive inside software people already use (Microsoft 365 Copilot, Adobe Firefly in Photoshop, AI assistants in browsers), often switched on by an update rather than a new installation. Installing or updating software now includes a governance question: should this feature be on, for whom, and what data can it see? Organisations increasingly manage this centrally through admin consoles and policy.
AI tools are also software to be procured and installed, and they carry specific constraints: where the provider stores and processes data, whether prompts are used to train models, what the licence says about ownership of outputs, and whether the tool meets the organisation's privacy obligations. These belong in the same requirements-and-constraints analysis as any other application.
Finally, AI is a practical helper for the technician, for reading a vendor's requirements page, drafting an implementation plan or explaining an installer's error code. Its suggestions still need checking against the vendor's own documentation before anything is run with administrator rights, and it cannot tell you whether an unfamiliar download site is legitimate.
Sources used
The unit's teaching content is drawn from the CDU material held in the unit folder: the ICTICT223 learning resource page on the CDU student site (last updated 21 January 2026), the ICTICT223 Assessor Guide v4.4 (undated), the ICTICT223 Student Unit Guide, the ICTICT223 validation report, and the ICT20120 practical observation checklist (February 2026). The unit is current at training.gov.au (no page date shown). Current-practice material was checked on 20 September 2026 against: Microsoft Learn, Windows 11 requirements (page updated 14 July 2026); ASD's Blueprint for Secure Cloud, patch applications (no date shown), and the cyber.gov.au Essential Eight maturity model changes page (maturity model dated 27 November 2023); and the Wikipedia article on Apache OpenOffice (read 20 September 2026) for its release and security status. The winget commands, Microsoft Defender behaviour and PowerShell cmdlets, Windows Autopilot and Intune deployment, the EICAR test file and the 3-2-1 backup rule reflect vendor documentation and established industry practice rather than a single dated source. The WannaCry timeline (patch MS17-010 released March 2017; outbreak May 2017) is widely documented.