Module Outline
Date retreived
22/07/2026 2:31 PM AWST
22/07/2026 2:31 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Protect industrial networks and operational technology infrastructure for an organisation
Protect industrial networks and operational technology infrastructure for an organisation
Module
National Code
VU23304
VU23304
State Code
AZ609
AZ609
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to examine the key standard bodies and frameworks that offer constructive support for addressing threats and vulnerabilities of Internet of Things (IoT) devices and Industrial Control System ((ICS) infrastructure for an organisation.
It requires the ability to identify the vulnerabilities of existing IoT and ICS systems and then apply mitigation strategies to protect an organisation’s IoT and ICS infrastructure. The mitigating strategies are then monitored for their effectiveness.
The unit applies to cyber security practitioners who are required to protect IoT and ICS infrastructure from cyber security threats and vulnerabilities.
No licensing or certification requirements apply to this unit at the time of accreditation.
It requires the ability to identify the vulnerabilities of existing IoT and ICS systems and then apply mitigation strategies to protect an organisation’s IoT and ICS infrastructure. The mitigating strategies are then monitored for their effectiveness.
The unit applies to cyber security practitioners who are required to protect IoT and ICS infrastructure from cyber security threats and vulnerabilities.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Define IoT and ICS differences and relevant security frameworks
- Differences between IoT and ICS is identified
- Key standards bodies and organisations that provide useful resources that address security issues for IoT and ICS infrastructure are identified
- Current IoT infrastructure architectures are reviewed and evaluated
- Current working frameworks or practices that can support the improvement of IoT and ICS from cyber security attack are identified
Evaluate current IoT and ICS infrastructure for an organisation with related vulnerabilities
- ICS devices used in an organisation are identified and classified
- IoT devices used in an organisation are identified and classified
- Responsibility for the installation and maintenance of the IoT and ICS devices for the organisation is identified
- Connectivity of the ICS and IoT devices for the organisation is determined
- Current vulnerabilities of the IoT and ICS devices for an organisation are identified
- Risk assessment for ICS and IOT devices used in an organisation is performed
- Case studies of two critical infrastructure attacks performed on an organisation are investigated
- Cyber-attacks on critical infrastructure as part of military campaigns are identified
Classify current cyber security vulnerabilities for IoT and ICS devices
- Classification of current cyber security vulnerabilities for ICS’s and IoT devices are identified
- Risk assessment of vulnerabilities for current organisation’s IoT and ICS devices is conducted
Select relevant cyber security frameworks and security critical infrastructure for IoT and ICS mitigation strategies
- Resources that provide strategies to protect IoT and ICS infrastructure are sourced
- Organisational security policies to protect IoT and ICS infrastructure are evaluated and selected
- Strategies to enhance the protection of IoT and ICS infrastructure are adopted
- Training for staff to improve the security culture is planned and implemented
Monitor the effectiveness of adopted IoT and ICS infrastructure mitigation strategies
- Criteria to measure the effectiveness of implemented IoT and ICS mitigation strategies is developed
- Tools to monitor the organisation’s IoT and ICS from cyber attacks are identified and selected
- Monitoring tools for an organisation’s IoT and ICS infrastructure are implemented
- Effectiveness of the monitoring tools implemented for an organisation’s IoT and ICS systems is reviewed and updated where necessary
- Changes to organisational processes and procedures to deal with IoT and ICS infrastructure incident responses are reviewed for their effectiveness and updated where necessary
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AX662 | VU22256 | Protect critical infrastructure for an organisation | Unit of competency |
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |