Module Outline

Date retreived
22/07/2026 5:28 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Detect and respond to cybersecurity threats

Detect and respond to cybersecurity threats

Module
National Code
VU23300
State Code
AZ607
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to detect and respond to cyber security threats in an organisation.

It requires the ability to prepare an organisation for an incident, know how the incident could occur and the processes and procedures to respond. The unit also includes the use of tools and processes to analyse data and detect intrusions.

The unit applies to cyber security practitioners who are responsible for implementing and monitoring cyber security operations for an organisation.

(The unit applies procedures and processes developed by the National Institute of Standards and Technology (NIST) and is aligned with the Cisco Cyber Operations course).

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Define endpoint threat analysis and computer forensics
  • Common Vulnerability Scoring System CVSS 3.0 for risk assessment is defined
  • Cyber security features are classified for risk assessment
  • Windows file system components are defined
  • Linux file system components are defined
  • Evidence types are contrasted
  • Altered and unaltered disk images are contrasted
  • Role of assets and threat actors are defined
Analyse network intrusion events
  • Vulnerabilities in networking protocols are evaluated
  • Elements from a NetFlow record of a security event are analysed
  • Network monitoring tools are identified, evaluated and selected
  • Key elements in an intrusion are identified
  • Data from an event is acquired
  • Selected intrusion elements from an event to common source technologies are mapped
  • Intrusion detection flags such as False Positive, False Negative, True Positive and True Negative are defined
Prepare to deal with incident responses
  • Incident response plan from the National Institute of Standards and Technology (NIST) described in the NIST.SP800-61 r2 document is evaluated and implemented
  • Organisation incident response plan is implemented
  • Function and role of the Cyber Security Incident Response Team (CSIRT) is defined
  • Elements for network profiling are defined
  • Elements for server profiling are defined
  • Acquired data is mapped to finance, health or credit card compliance frameworks
Compose processes for data and event analysis
  • Steps and methods used to gather data are described and evaluated
  • Domain Name Server (DNS) and HTTP logs are mapped to identify threat actors
  • Threat intelligence data is collated from internal records and public trusted sites
  • Organisational detection tools and methods are utilised to correlate generated alerts from multiple data sources
  • Alternative tools and techniques used for data analysis are utilised
Apply models and processes to incidents
  • Models of intrusion detection (e.g. MITRE ATT&CK) are described and evaluated
  • Intrusion events are classified
  • Incident response processes are applied to the event
  • Selected range of activities relating to incident handling are defined
  • Documents that support the organisation to collect forensic data for incident responses are identified, evaluated and adopted
  • Data evidence and collection forensic activities are defined according to organisational guidelines
  • Structured Threat Information Expression (STIX) language for describing cyber threat information for it to be shared, stored, and analysed is evaluated
  • STIX methods are applied to the incident
Replaces
State Code National Code Title Type
AX658 VU22252 Implement cyber security operations Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course