Unit of competency Outline

Date retreived
23/07/2026 11:57 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Assess security risk management options

Assess security risk management options

Unit of competency
National Code
CPPSEC5003
State Code
OBI60
TGA Status
Current
DTWD Status
Approved
Current Release Number
1.00
Current Release Date
30/09/2019
State Implementation and Classification
Approved Date
20/05/2020
Field of Education
099905 - Security Services
Original Release Date
20/05/2020
Nominal Hours
40
Description
This unit specifies the skills and knowledge required to assess security risks associated with client operations and formulate suitable treatment options as part of a risk management strategy. It includes analysing the client’s security objectives and operating environment and establishing criteria to select and prioritise risk treatment options consistent with recognised industry practice and guidelines provided by ISO31000:2018 Risk management - Guidelines (ISO 31000). The unit requires preparing formal reports detailing risk management options and possible consequences of not implementing recommended treatments.This unit is suitable for those using a broad range of cognitive, technical and communication skills to select and apply methods and technologies to analyse information and provide solutions to sometimes complex problems.Legislative, regulatory or certification requirements apply in some states and territories to the provision of advice on security solutions, strategies, protocols and procedures. For further information, check with the relevant regulatory authority.
Notes
Elements and Performance Criteria
1 Assess client’s security requirements and risk environment.
  • 1.1 Access and interpret key requirements of legislation, regulations and Australian standard ISO31000 to understand and comply with requirements for assessing security risk management options.
  • 1.2 Clarify client security objectives and risk assessment terms of reference in consultation with relevant persons.
  • 1.3 Source and review information to identify and assess risks associated with operating environment of client.
  • 1.4 Analyse type, nature and cause of identified security risks and prioritise based on severity and likelihood of occurrence.
  • 1.5 Document risk assessment outcomes and check to ensure data currency and reliability.
2 Formulate security risk management options.
  • 2.1 Identify security risk treatment options commensurate with risk assessment and client requirements.
  • 2.2 Research the application of identified treatment options in similar contexts to assess their effectiveness in mitigating risks to client’s operating environment.
  • 2.3 Establish criteria to assess effectiveness of treatment options consistent with recognised industry practice and guidelines provided byISO 31000.
  • 2.4 Apply criteria to select and prioritise recommended treatment options.
3 Finalise and present security risk management options.
  • 3.1 Finalise and document security risk assessment detailing recommended risk management options and possible consequences of not implementing recommended treatments.
  • 3.2 Check report to ensure analysis and recommendations are clear, coherent and consistent with terms of reference, and supported by verifiable information.
  • 3.3 Present report to relevant persons within agreed timeframes and explain identified security risks and treatment options to enhance understanding and acceptance of recommendations.
  • 3.4 Complete and secure risk assessment documentation in a manner that facilitates future retrieval and maintains client confidentiality according to workplace and regulatory requirements.
No information
No information
Replaces
State Code National Code Title Type
D1474 CPPSEC5003A Assess security risk management options Unit of competency