Module Outline

Date retreived
22/07/2026 11:58 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Plan and conduct a security risk assessment for an organisation

Plan and conduct a security risk assessment for an organisation

Module
National Code
VU23297
State Code
AZ604
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to plan and conduct a risk assessment for the organisation.

It requires the ability to assess current assets, identify current threats and vulnerabilities, identify a risk process and perform an assessment.

This unit applies to cyber security practitioners working as a team member and as part of the role required to perform or review a risk assessment for an organisation.

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Compile and evaluate risk management plan for the organisation
  • Methodologies for risk assessment are investigated
  • Vulnerabilities and threats for an organisation are identified
  • Risk management plan for the organisation is sourced
  • Risk assessment analysis process for an organisation is defined
  • A cyber security disaster recovery plan for an organisation is developed
Compile risk categories for the security system
  • Information assets for the organisation are ranked and documented
  • Risk analysis classification criteria is determined
  • Use risk analysis processes to qualify and quantify risks and threats
  • Risk priorities for information assets are allocated
  • Risk analysis outcomes for inclusion in the risk register and the risk management plan are documented
Implement appropriate security system controls for managing the risk
  • Effective controls to manage risk are devised documented and implemented
  • Emerging risks or threats are monitored with corrective measures planned documented
Monitor security system controls and processes
  • Controls that manage risks are reviewed and monitored for their continued effectiveness
  • Regular risk review processes to maintain currency of risk plans are established
  • Environment is regularly monitored to determine changed conditions
  • If environment or a condition changes, implement and document appropriate changes to the risk controls and report changes to appropriate personnel
Promote cybersecurity awareness in the organisation
  • Implications of the organisation’s security policy are defined and evaluated
  • Strategies to promote security policy awareness in the organisation are planned and implemented
Replaces
State Code National Code Title Type
AX655 VU22249 Perform a security risk assessment for an organisation Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course