Module Outline

Date retreived
22/07/2026 1:21 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Identify and monitor an organisation's cyber security legal compliance requirements

Identify and monitor an organisation's cyber security legal compliance requirements

Module
National Code
VU23294
State Code
AZ601
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to identify relevant cyber standards and laws pertaining to an organisation.

It requires the ability to evaluate current working practices and to plan and implement any required work practice changes to ensure the organisations compliance with the relevant Australian, international standards and laws.

The unit applies to cyber security practitioners who, as part of a team are responsible for implementing and monitoring an organisation’s compliance to relevant Australian, international standards and law.

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Identify the structure of the Australian legal system
  • Key legal terms are defined
  • Structure of the Australian legal systems are investigated
  • Common laws are identified
  • Structure of the Australian federal system of government is defined
  • Relationship between federal and state regulation is clarified
Define Australian cyber law
  • Model laws on electronic commerce are investigated
  • Conventions on the use of electronic communications are defined
  • Relevant international cybercrime convention is investigated
  • Repercussions of the international General Data Protection Regulation (GDPR) and its adoption in Australia is investigated
  • Implication of Australian electronic transactions law is investigated
Identify mandatory and discretionary cyber laws and practices
  • Categories of information the law affords cyber security protection for an organisation are identified
  • Legal resources pertaining to cyber law are identified
  • Relevant laws for particular industry sectors are identified and collated
  • Difference between State and federal legislation for relevant laws pertaining to cyber security are identified
  • Outcomes of current Commonwealth Acts as they pertain to cyber security for an organisation are identified
  • Mandatory outcomes of current State based Acts as they pertain to cyber security for an organisation are identified
  • Codes pertinent to an organisation’s industry sector are identified
  • Frameworks pertinent to an organisation’s industry sector are identified
  • Voluntary codes and best practices for the industry sector aligned to an organisation are identified
Evaluate and select relevant Australian regulation and practices pertaining to security for an organisation
  • Methodology of utilising legal resources relevant to cyber law for an organisation is defined and demonstrated
  • Mandatory regulations, standards, codes and frameworks pertaining to cyber security for an organisation are evaluated and selected
  • Discretionary standards, codes and frameworks pertaining to cyber security for an organisation are evaluated and selected
  • Voluntary codes and best practice for the industry sector aligned to an organisation are evaluated and selected
Implement relevant Australian regulation and practices pertaining to security for an organisation
  • Strategies to implement mandatory regulations, standards, codes and frameworks for an organisation are developed
  • Strategies to implement discretionary standards, codes and frameworks for an organisation are developed
  • Strategies to implement voluntary codes and best practice guidelines for an organisation are developed
  • Organisational changes to appropriate personnel within an organisation are articulated
Monitor the effectiveness of an organisation’s implementation of regulation and practices
  • Criteria to measure the effectiveness of implemented changes to work practices adopted by an organisation is created
  • Utilising the developed criteria, the effectiveness of changes to an organisation’s work practices are measured and monitored
  • Changes to the organisation’s working practices are documented and reported to appropriate personnel
Replaces
State Code National Code Title Type
AX652 VU22246 Evaluate an organisation's compliance with relevant cyber security standards and law Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course