Unit of competency Outline
Date retreived
23/07/2026 2:24 AM AWST
23/07/2026 2:24 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Manage risks involving ICT systems and technology
Manage risks involving ICT systems and technology
Unit of competency
National Code
ICTSAS409
ICTSAS409
State Code
AUW37
AUW37
TGA Status
Deleted
Deleted
DTWD Status
Deleted
Deleted
State Implementation and Classification
Approved Date
16/09/2015
Field of Education
029999 - Information Technology, N.e.c.
Original Release Date
16/09/2015
Nominal Hours
20
Description
This unit describes the skills and knowledge required to implement procedures that identify, analyse, evaluate and monitor risks involving information and communications technology (ICT) systems and technology. This includes the development and management of contingency plans.It applies to individuals who provide high level technical skills and knowledge, and systematic approaches to manage risk in ICT systems.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Establish risk context
- 1.1 Review and document organisational and technical environment
- 1.2 Establish and document risk boundaries according to business operating and strategic environment
2. Identify risk factors
- 2.1 Develop or acquire a measurement scale for project risk, which includes importance, complexity, time and resources required
- 2.2 Identify project risks based on the measurement scale developed and document according to business requirements
- 2.3 Identify business impact of changes and document according to current and future business directions
3. Implement contingency plans
- 3.1 Classify each risk and create contingency plans that address how the risk will be monitored and overcome, if possible
- 3.2 Identify measurable benchmarks to track the treatment of risks to the new system
- 3.3 Identify risk management intervention points according to benchmarked performance tolerances
- 3.4 Demonstrate use of phased implementation and piloting to reduce risk factors
4. Monitor, update and report risk profile
- 4.1 Conduct regular risk updates to add new risks and remove old ones
- 4.2 Update contingency plans when appropriate to incorporate new information
- 4.3 Conduct risk reviews at major project milestones and document outcomes
- 4.4 Establish feedback processes to provide warning of potential new risks according to business requirements
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| D8071 | ICASAS409A | Manage risks involving ICT systems and technology | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| BCY61 | 22334VIC | Certificate IV in Cyber Security | Accredited course |
| BEH4 | ICT40118 | Certificate IV in Information Technology | Qualification |
| AWB5 | ICT40115 | Certificate IV in Information Technology | Qualification |
| BGO69 | 22519VIC | Certificate IV in Integrated Technologies | Accredited course |
| AZI7 | ICT60615 | Advanced Diploma of Telecommunications Network Engineering | Qualification |