Unit of competency Outline
Date retreived
23/07/2026 5:10 PM AWST
23/07/2026 5:10 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Implement security risk management plan
Implement security risk management plan
Unit of competency
National Code
CPPSEC5005A
CPPSEC5005A
State Code
D1476
D1476
TGA Status
Replaced
Replaced
DTWD Status
Replaced
Replaced
State Implementation and Classification
Approved Date
11/10/2011
Field of Education
099905 - Security Services
Original Release Date
11/10/2011
Nominal Hours
40
Description
This unit of competency specifies the outcomes required to facilitate implementation of a security risk management plan. It requires the ability to allocate roles and responsibilities, coordinate and monitor implementation procedures, and evaluate the effectiveness of treatment options. This unit may form part of the licensing requirements for persons engaged in risk assessment operations in those states and territories where these are regulated activities.
Notes
Elements and Performance Criteria
1Organise functions and tasks.
- 1.1 Applicable provisions of legislative and organisational requirements, and relevant standards for risk assessment activities are identified and complied with.
- 1.2 Roles and responsibilities associated with the implementation of the security risk management plan are clearly defined and articulated to relevant persons.
- 1.3 Activities and targets are linked to achievement of milestones and outcomes in project action plans.
- 1.4 Resources, equipment and materials to assist plan implementation are suitable to project purposes and available within specified timelines.
- 1.5 Information related to the implementation of the plan is accurately and promptly distributed using established communication channels.
- 1.6 Confidentiality requirements are confirmed and maintained in accordance with client and organisational requirements.
2Monitor risk context.
- 2.1 Emerging risks or threats to assets are monitored and assessed to maintain ongoing suitability of implemented security risk treatment options.
- 2.2 Changes to operating environment are monitored and corrective measures determined and incorporated into the plan as required.
- 2.3 Targets and outcomes are regularly reviewed and evaluated to ensure achievement of project aims based on relevant standards.
- 2.4 Existence and occurrence of risks are accurately and comprehensively documented providing an assessment of the type, nature and cause.
- 2.5 Application of contingencies and corrective measures are accurately documented.
3Review effectiveness of treatment options.
- 3.1 Long and short-term options are costed to ensure an accurate estimate of resources is allocated to support the plans.
- 3.2 Discrepancies between treatment options and risk incidence are monitored and addressed through appropriate modifications to plans.
- 3.3 Stages of implementation are identified and resources and options are coordinated to ensure access and availability.
- 3.4 Corrective measures are developed, tested and incorporated into the risk management plan.
- 3.5 Feedback on effectiveness of treatment options is sought and provided to relevant personnel.
RANGE STATEMENT
The range statement relates to the unit of competency as a whole. It allows for different work environments and situations that may affect performance. Bold italicised wording, if used in the performance criteria, is detailed below. Essential operating conditions that may be present with training and assessment (depending on the work situation, needs of the candidate, accessibility of the item, and local industry and regional contexts) may also be included.
Legislative requirements may relate to:
apprehension and powers of arrest
Australian standards and quality assurance requirements
cabling
counter-terrorism
crowd control and control of persons under the influence of intoxicating substances
Force continuum, use of force guidelines
general 'duty of care' responsibilities
inspection of people and property, and search and seizure of goods
licensing or certification requirements
privacy and confidentiality
relevant commonwealth, state and territory legislation, codes and national standards for:
anti-discrimination
cultural and ethnic diversity
environmental issues
equal employment opportunity
industrial relations
Occupational Health and Safety (OHS)
relevant industry codes of practice
surveillance
telecommunications
trespass and the removal of persons
use of listening and recording devices
use of restraints and weapons:
batons
firearms
handcuffs
spray.
Organisational requirements may relate to:
access and equity policies, principles and practices
business and performance plans
client service standards
code of conduct, code of ethics
communication and reporting procedures
complaint and dispute resolution procedures
emergency and evacuation procedures
employer and employee rights and responsibilities
OHS policies, procedures and programs
own role, responsibility and authority
personal and professional development
privacy and confidentiality of information
quality assurance and continuous improvement processes and standards
resource parameters and procedures
roles, functions and responsibilities of security personnel
storage and disposal of information.
Relevant standards:
must include AS/NZS 4360: 2004 Risk management
may relate to:
AS2630-1983 Guide to the selection and application of intruder alarm systems for domestic and business premises
HB 167:2006 Security Risk Management
HB 436 Risk Management Guidelines - Companion to AS/NZS 4360
HB 231:2000 Information security risk management guidelines.
Riskrelates to:
the chance of something happening that will have an impact on objectives.
Security risks may relate to:
biological hazards
chemical spills
client contact
electrical faults
explosives
financial viability
injury to personnel
noise, light, heat, smoke
persons carrying weapons
persons causing a public nuisance
persons demonstrating suspicious behaviour
persons suffering from emotional or physical distress
persons under the influence of intoxicating substances
persons with criminal intent
persons, vehicles and equipment in unsuitable locations
property or people
security systems
suspicious packages or substances
systems or process failures
terrorism
violence or physical threats.
Roles and responsibilities may relate to:
administrative support
backup operational role
decision-making
frontline role
team leadership
team membership.
Relevant persons may include:
client
colleagues
human resources personnel
management
security personnel.
Activities may include:
advising
field work
monitoring
organising
report preparation
reporting.
Resources, equipment and materials may relate to:
consumables
equipment
funding
personnel
time
vehicles.
Treatment optionsmay relate to:
controlled interruptions to normal operations
exercises
information collation and analysis
simulations
surveillance
verification requirements.
Targets and outcomesmay relate to:
client support times
effective security risk management
incident reports
level of feedback from clients
number of new sales
police liaison
response times.
Project aimsmay relate to:
key outcomes
milestones
personnel involvement
resources
tasks
timelines.
The range statement relates to the unit of competency as a whole. It allows for different work environments and situations that may affect performance. Bold italicised wording, if used in the performance criteria, is detailed below. Essential operating conditions that may be present with training and assessment (depending on the work situation, needs of the candidate, accessibility of the item, and local industry and regional contexts) may also be included.
Legislative requirements may relate to:
apprehension and powers of arrest
Australian standards and quality assurance requirements
cabling
counter-terrorism
crowd control and control of persons under the influence of intoxicating substances
Force continuum, use of force guidelines
general 'duty of care' responsibilities
inspection of people and property, and search and seizure of goods
licensing or certification requirements
privacy and confidentiality
relevant commonwealth, state and territory legislation, codes and national standards for:
anti-discrimination
cultural and ethnic diversity
environmental issues
equal employment opportunity
industrial relations
Occupational Health and Safety (OHS)
relevant industry codes of practice
surveillance
telecommunications
trespass and the removal of persons
use of listening and recording devices
use of restraints and weapons:
batons
firearms
handcuffs
spray.
Organisational requirements may relate to:
access and equity policies, principles and practices
business and performance plans
client service standards
code of conduct, code of ethics
communication and reporting procedures
complaint and dispute resolution procedures
emergency and evacuation procedures
employer and employee rights and responsibilities
OHS policies, procedures and programs
own role, responsibility and authority
personal and professional development
privacy and confidentiality of information
quality assurance and continuous improvement processes and standards
resource parameters and procedures
roles, functions and responsibilities of security personnel
storage and disposal of information.
Relevant standards:
must include AS/NZS 4360: 2004 Risk management
may relate to:
AS2630-1983 Guide to the selection and application of intruder alarm systems for domestic and business premises
HB 167:2006 Security Risk Management
HB 436 Risk Management Guidelines - Companion to AS/NZS 4360
HB 231:2000 Information security risk management guidelines.
Riskrelates to:
the chance of something happening that will have an impact on objectives.
Security risks may relate to:
biological hazards
chemical spills
client contact
electrical faults
explosives
financial viability
injury to personnel
noise, light, heat, smoke
persons carrying weapons
persons causing a public nuisance
persons demonstrating suspicious behaviour
persons suffering from emotional or physical distress
persons under the influence of intoxicating substances
persons with criminal intent
persons, vehicles and equipment in unsuitable locations
property or people
security systems
suspicious packages or substances
systems or process failures
terrorism
violence or physical threats.
Roles and responsibilities may relate to:
administrative support
backup operational role
decision-making
frontline role
team leadership
team membership.
Relevant persons may include:
client
colleagues
human resources personnel
management
security personnel.
Activities may include:
advising
field work
monitoring
organising
report preparation
reporting.
Resources, equipment and materials may relate to:
consumables
equipment
funding
personnel
time
vehicles.
Treatment optionsmay relate to:
controlled interruptions to normal operations
exercises
information collation and analysis
simulations
surveillance
verification requirements.
Targets and outcomesmay relate to:
client support times
effective security risk management
incident reports
level of feedback from clients
number of new sales
police liaison
response times.
Project aimsmay relate to:
key outcomes
milestones
personnel involvement
resources
tasks
timelines.
EVIDENCE GUIDE
The evidence guide provides advice on assessment and must be read in conjunction with the performance criteria, required skills and knowledge, range statement and the Assessment Guidelines for the Training Package.
Critical aspects for assessment and evidence required to demonstrate competency in this unit
A person who demonstrates competency in this unit must be able to provide evidence of:
monitoring emerging risks to ensure ongoing suitability of risk management plan based on principles of AS/NZS 4360: 2004
efficient allocation of resources to support risk management plan
effectively communicating designated roles, responsibilities and work schedules to security personnel
preparing documentation and guidelines with a clear explanation of the incidence, nature and causes of risks and appropriate contingency arrangements
systematically reviewing the effectiveness of treatment options and making appropriate modifications as required to address any discrepancies between treatment options and risk incidence.
Context of and specific resources for assessment
Context of assessment includes:
a setting in the workplace or environment that simulates the conditions of performance described in the elements, performance criteria and range statement.
Resource implications for assessment include:
access to a registered provider of assessment services
access to a suitable venue and equipment
access to plain English version of relevant statutes and procedures
assessment instruments including personal planner and assessment record book
work schedules, organisational policies and duty statements.
Reasonable adjustments must be made to assessment processes where required for people with disabilities. This could include access to modified equipment and other physical resources, and the provision of appropriate assessment support.
Method of assessment
This unit of competency should be assessed using questioning of underpinning knowledge and skills.
Guidance information for assessment
Assessment processes and techniques must be culturally appropriate and suitable to the language, literacy and numeracy capacity of the candidate and the competency being assessed. In all cases where practical assessment is used, it should be combined with targeted questioning to assess the underpinning knowledge.
Oral questioning or written assessment may be used to assess underpinning knowledge. In assessment situations where the candidate is offered a choice between oral questioning and written assessment, questions are to be identical.
Supplementary evidence may be obtained from relevant authenticated correspondence from existing supervisors, team leaders or specialist training staff.
The evidence guide provides advice on assessment and must be read in conjunction with the performance criteria, required skills and knowledge, range statement and the Assessment Guidelines for the Training Package.
Critical aspects for assessment and evidence required to demonstrate competency in this unit
A person who demonstrates competency in this unit must be able to provide evidence of:
monitoring emerging risks to ensure ongoing suitability of risk management plan based on principles of AS/NZS 4360: 2004
efficient allocation of resources to support risk management plan
effectively communicating designated roles, responsibilities and work schedules to security personnel
preparing documentation and guidelines with a clear explanation of the incidence, nature and causes of risks and appropriate contingency arrangements
systematically reviewing the effectiveness of treatment options and making appropriate modifications as required to address any discrepancies between treatment options and risk incidence.
Context of and specific resources for assessment
Context of assessment includes:
a setting in the workplace or environment that simulates the conditions of performance described in the elements, performance criteria and range statement.
Resource implications for assessment include:
access to a registered provider of assessment services
access to a suitable venue and equipment
access to plain English version of relevant statutes and procedures
assessment instruments including personal planner and assessment record book
work schedules, organisational policies and duty statements.
Reasonable adjustments must be made to assessment processes where required for people with disabilities. This could include access to modified equipment and other physical resources, and the provision of appropriate assessment support.
Method of assessment
This unit of competency should be assessed using questioning of underpinning knowledge and skills.
Guidance information for assessment
Assessment processes and techniques must be culturally appropriate and suitable to the language, literacy and numeracy capacity of the candidate and the competency being assessed. In all cases where practical assessment is used, it should be combined with targeted questioning to assess the underpinning knowledge.
Oral questioning or written assessment may be used to assess underpinning knowledge. In assessment situations where the candidate is offered a choice between oral questioning and written assessment, questions are to be identical.
Supplementary evidence may be obtained from relevant authenticated correspondence from existing supervisors, team leaders or specialist training staff.
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| S3809 | PRSSM505A | Implement security risk management plan | Unit of competency |
Replaced By
| State Code | National Code | Title | Type |
|---|---|---|---|
| OBI58 | CPPSEC5005 | Implement security risk management plans | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| D577 | ICA60211 | Advanced Diploma of Network Security | Qualification |
| AVX6 | ICT60215 | Advanced Diploma of Network Security | Qualification |
| D231 | CPP50607 | Diploma of Security and Risk Management | Qualification |
| W979 | CPP50611 | Diploma of Security and Risk Management | Qualification |