Unit of competency Outline
Date retreived
23/07/2026 4:59 PM AWST
23/07/2026 4:59 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Assess security vulnerabilities of assets
Assess security vulnerabilities of assets
Unit of competency
National Code
CPPSEC4012
CPPSEC4012
State Code
OBI74
OBI74
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
20/05/2020
Field of Education
099905 - Security Services
Original Release Date
20/05/2020
Nominal Hours
50
Description
This unit specifies the skills and knowledge required to assess the security vulnerabilities of client assets based an analysis of asset types, use, ownership and value. It includes auditing security risk control mechanisms and incident reporting measures and testing their operational effectiveness to identify failures and recommend treatment options.This unit is suitable for those using specialised knowledge to complete routine and non-routine tasks and using their own judgement to deal with predictable and sometimes unpredictable problems.Legislative, regulatory or certification requirements apply in some states and territories to the provision of advice on security solutions, strategies, protocols and procedures. For further information, check with the relevant regulatory authority.
Notes
Elements and Performance Criteria
1 List client assets and confirm status.
- 1.1 Access and interpret key requirements of legislation, regulations and workplace policies and procedures and apply to work instructions to ensure compliance.
- 1.2 Consult with relevant persons to confirm the location and nature of all assets and clarify client security objectives in relation to each asset.
- 1.3 Source valid and reliable information to confirm the value of all client assets in consultation with relevant persons.
- 1.4 Document listing of client assets and valuations in a format suitable for analysis.
- 1.5 Conduct analysis to confirm asset types, use, ownership and value.
- 1.6 Recognise own limitations in assessing asset security vulnerabilities of client and access specialist resources or advice to meet client requirements.
2 Assess security risk control mechanisms to identify asset vulnerabilities.
- 2.1 Identify and assess methods for accessing client assets.
- 2.2 Conduct audit of existing and planned security risk control mechanisms and incident reporting measures.
- 2.3 Obtain and review operating parameters for identified risk control mechanisms to plan testing methods.
- 2.4 Test operational effectiveness of risk control mechanisms to identify actual and potential failures and report the results to relevant persons.
3 Finalise and present asset security vulnerability assessment.
- 3.1 Finalise asset security vulnerability assessment including recommendations to treat identified security risks, and check to ensure findings and recommendations are supported by verifiable information.
- 3.2 Use information technologies to document and present asset security vulnerability assessment in a format and style to meet workplace requirements.
- 3.3 Present final asset security vulnerability assessment to relevant persons for feedback within agreed timeframes.
- 3.4 Use questioning and active listening to explain identified security vulnerabilities and recommended treatments.
- 3.5 Complete and secure asset assessment documentation in a manner that facilitates future retrieval and maintains confidentiality according to workplace and regulatory requirements.
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| D1462 | CPPSEC4012A | Identify and assess security of assets | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| BEW8 | CPP41519 | Certificate IV in Security Risk Analysis | Qualification |