Unit of competency Outline
Date retreived
23/07/2026 4:43 AM AWST
23/07/2026 4:43 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Conduct security risk assessment of client operations
Conduct security risk assessment of client operations
Unit of competency
National Code
CPPSEC4006
CPPSEC4006
State Code
OBI80
OBI80
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
20/05/2020
Field of Education
099905 - Security Services
Original Release Date
20/05/2020
Nominal Hours
50
Description
This unit specifies the skills and knowledge required to conduct a security risk assessment of client operations. It includes analysing client operations and associated information and intelligence to develop a risk assessment register, develop and apply risk assessment criteria to measure risks and consequences to client operations and recommend appropriate countermeasures. This unit of competency does not cover development of risk management plans.This unit is suitable for those using specialised knowledge to complete routine and non-routine tasks and using their own judgement to deal with predictable and sometimes unpredictable problems.Legislative, regulatory or certification requirements apply in some states and territories to the provision of advice on security solutions, strategies, protocols and procedures. For further information, check with the relevant regulatory authority.
Notes
Elements and Performance Criteria
1 Analyse client operations and risk environment.
- 1.1 Access and interpret key requirements of legislation, regulations and workplace policies and procedures and apply to work instructions to ensure compliance.
- 1.2 Consult with relevant persons to confirm risk assessment terms of reference, costs and timeframes.
- 1.3 Develop and document a structured risk assessment register that includes an agreed methodology and allows for possible changes to client operations.
- 1.4 Consult with client to confirm their core business, operating environment, goals and objectives.
- 1.5 Source valid and reliable information and intelligence to clarify client assets and analyse potential and actual security risks.
- 1.6 Recognise own limitations in assessing security risks and access specialist resources or advice to meet client requirements.
2 Assess security risks and consequences to operations.
- 2.1 Develop risk assessment criteria comprising qualitative and quantitative measures.
- 2.2 Apply risk assessment criteria to measure level of potential or existing security risk and associated consequences to client operations.
- 2.3 Identify gaps in predetermined methodology to respond to changing risk context of client operations and modify risk assessment in consultation with relevant persons.
- 2.4 Source additional required information to assess and confirm client security risk potential.
- 2.5 Use information technologies to document and present security risk assessment in a format and style to meet workplace requirements.
3 Finalise risk assessment and present findings.
- 3.1 Identify countermeasures to overcome security risks associated with client operations and incorporate recommended strategies into final risk assessment.
- 3.2 Finalise security risk assessment and check to ensure findings and recommendations are supported by verifiable information.
- 3.3 Present final security risk assessment to relevant persons for feedback within agreed timeframes.
- 3.4 Use questioning and active listening to explain identified security risks and countermeasures to mitigate risk to client operations.
- 3.5 Complete and secure risk assessment documentation in a manner that facilitates future retrieval and maintains confidentiality.
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| D1456 | CPPSEC4006A | Assess risks | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| BEW8 | CPP41519 | Certificate IV in Security Risk Analysis | Qualification |