Module Outline

Date retreived
22/07/2026 2:53 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Utilise tools to gather and interpret data anomalies

Utilise tools to gather and interpret data anomalies

Module
National Code
VU23299
State Code
AZ606
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
60
Description
No information
Evidence Guide
This unit describes the performance outcomes, skills and knowledge required to utilise tools to gather, analyse and interpret data anomalies.

It requires the ability to operate hardware and software tools to detect cyber incidents. The unit includes the selection and use of tools to analyse logged data, detection of malicious data streams as well as analysis of the results and evaluation of the selected tools for their effectiveness in detecting data patterns.

The unit applies to cyber security practitioners who, as part of a team respond to cyber security incidents in an organization.

No licensing or certification requirements apply to this unit at the time of accreditation.
Elements and Performance Criteria
  • Hardware devices used to detect incidents for an organisation are evaluated
  • Software used to detect incidents for an organisation is evaluated
  • Data sources used to gather incident information are identified
  • Types of data sources for a particular incidents are selected
  • Effectiveness of data sources used to detect incidents for an organisation are evaluated
Select and use tools that analyse logged data
  • Tools that support the interpretation of logged data are evaluated
  • Features of the logged data tool environment are identified and evaluated
  • Plans for data and log management are identified
  • Appropriate tool to analyse logged data is selected
Develop skills for analysing data
  • Data source to perform analyse is selected
  • Normal baseline data standard for the network is identified
  • Correlation of sampled data to other data sets is preformed
  • Techniques and procedures to identify irregular events are developed including assigning significance to alerts, derivation from baselines and correlation of events with other data sets
  • Effectiveness of the strategy to detect irregular events is evaluated and modified if required
Apply tools to detect and analyse logged data stream anomalies
  • Most appropriate tool to analyse logged data stream is selected from the working environment
  • Skills using tools to detect data stream anomalies and correlating events are developed and demonstrated
  • An overview of incident playbooks and their role in responding to incidents is investigated
  • Overview of the methodology to integrate scripts to the logged data analysis tool in order to detect data patterns are demonstrated
  • Typical features of Security Orchestration, Automation and Response (SOAR) tools are identified
Develop continuous improvement strategies to detect anomalous events for an organisation
  • Effectiveness of the tools used to detect data patterns is evaluated
  • Strategies to detect data patterns are evaluated and modified if required
Replaces
State Code National Code Title Type
AX657 VU22251 Gather, analyse and interpret threat data Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course