Module Outline
Date retreived
22/07/2026 5:28 PM AWST
22/07/2026 5:28 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Implement processes and procedures to deal with cyber security incidents
Implement processes and procedures to deal with cyber security incidents
Module
National Code
VU23298
VU23298
State Code
AZ605
AZ605
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to prepare for and respond to a cyber security incident within an organisation. The unit also includes the skills and knowledge to accurately document the incident and to update the organisation’s incident response plan to reduce the risk of further incidents.
It requires the ability to identify when the incident occurred, develop and implement an appropriate response’ strategy, evaluate the success of the response and any long term effects of the incident.
The unit applies to cyber security practitioners who as part of a team, are responsible for the control and ongoing management of cyber incidents in an organisation.
No licensing or certification requirements apply to this unit at the time of accreditation.
It requires the ability to identify when the incident occurred, develop and implement an appropriate response’ strategy, evaluate the success of the response and any long term effects of the incident.
The unit applies to cyber security practitioners who as part of a team, are responsible for the control and ongoing management of cyber incidents in an organisation.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Prepare to respond to an incident
- Procedures to address incidents in the organisation’s incident response plan (IRP) are identified and reviewed
- Organisation’s processes to deal with incident responses are benchmarked against published incident response strategies
- Incident response team (IRT) members to deal with the incident are identified
- IRT member’s roles and responsibilities are clearly defined
- IRT member’s communication expectations during incidents are clarified
- IRT reporting and communication procedures to relevant organisational groups are defined
- Function and role of cyber security tools and techniques chosen to detect incidents are defined
- Data sources to gather incident information are identified
Data sources to gather incident information are identified
- System messages and events to identify malicious activity are evaluated
- Data is collected from appropriate data sources
- Initial triage of the incident is performed
- Risk assessment of the incident is performed
- Need to escalate the incident is assessed
Respond to the incident
- IRT members are recruited to deal with the incident
- Defined incident response strategy is implemented if the incident is part of the organisation’s incident response strategy plan
- Strategy to deal with the incident is planned if the incident is not part of the organisation’s incident response strategy plan
- Mitigation strategies that quarantine the incident are planned and implemented
Monitor effectiveness of the strategies to deal with the incident
- Effectiveness of the strategies to deal with the incident are monitored, evaluated and if required modified
- Additional IRT members are recruited if required to develop strategies to deal with the incident
- Incident response is escalated where appropriate
- Incident is communicated within the organisation according to defined communication strategies
Evaluate the impact of the incident
- Impact of the incident is evaluated with appropriate personnel
- Strategies to deal with any lost or compromised data or resources are planned and implemented
Communicate and document the incident
- Incident is documented according to standard organisational templates
- Incident is communicated to relevant personnel within the organisation
Implement post incident review and actions
- Existing incident response strategies are reviewed, modified and documented as required.
- New incident response strategies developed for the incident are included in the organisation’s incident response strategy procedure’s document
- Incident response procedure is stored for future reference and used when inducting new staff
- Business plans and processes are evaluated for change if required with appropriate personnel
- Existing security equipment and security infrastructure are reviewed
- Procurement of new security equipment is organised with appropriate personnel if required
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AX656 | VU22250 | Respond to cyber security incidents | Unit of competency |
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |