Unit of competency Outline
Date retreived
22/07/2026 5:49 AM AWST
22/07/2026 5:49 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Undertake penetration testing for organisations
Undertake penetration testing for organisations
Unit of competency
National Code
ICTCYS603
ICTCYS603
State Code
OBV07
OBV07
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
70
Description
This unit describes the skills and knowledge required to use a range of methodologies to simulate an attack on an organisation’s information and security systems and report the results back to the organisation.It applies to those who work as network security specialists or administrators and conduct a simulated attack on an organisation’s cyber assets to determine the effectiveness of the organisation’s cyber security measures. No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare for penetration testing
- 1.1 Analyse organisation’s existing cyber security environment, systems and network requirements
- 1.2 Identify individual data types and level of security requirements
- 1.3 Establish and outline goal and objectives of performing penetration testing
- 1.4 Evaluate scanning tools and select according to vulnerability assessment requirements
- 1.5 Establish and document testing regime and schedule, and requirements according to organisational procedures
2. Conduct penetration tests
- 2.1 Perform penetration test according to testing plan and procedures
- 2.2 Identify and document vulnerabilities arising from vulnerability assessment
- 2.3 Identify and document potential threats arising from penetration test according to organisational and testing procedures
3. Conduct follow up activities
- 3.1 Remediate identified vulnerabilities according to testing procedures
- 3.2 Determine and document improvement plan
- 3.3 Evaluate penetration testing effectiveness against testing plan and procedures
- 3.4 Escalate unresolved vulnerabilities to required personnel
- 3.5 Submit documentation to required personnel and seek and respond to feedback
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| AE715 | ICTSS00126 | Advanced Cyber Incident Threat Detection and Prevention Skill Set | Skill set |
| BGJ5 | ICT60220 | Advanced Diploma of Information Technology | Qualification |
| BFF8 | ICT60120 | Advanced Diploma of Information Technology | Qualification |
| BGS59 | 11062NAT | Certificate IV in Offensive Cyber Security | Accredited course |