Unit of competency Outline
Date retreived
24/07/2026 6:13 AM AWST
24/07/2026 6:13 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Determine security and access rules and procedures
Determine security and access rules and procedures
Unit of competency
National Code
BSBRKG604
BSBRKG604
State Code
AUM02
AUM02
TGA Status
Replaced
Replaced
DTWD Status
Transition (Replaced)
Transition (Replaced)
State Implementation and Classification
Approved Date
15/09/2015
Field of Education
080307 - Organisation Management
Original Release Date
15/09/2015
Nominal Hours
60
Description
This unit describes the skills and knowledge required to determine and establish the rules for access and use of records in an organisation, including classifications and procedures for managing access over time.It applies to experienced individuals who use specialist knowledge of business and record-keeping operations and apply analytical and problem- solving skills relevant to organisational risk. The individual may have responsibility for a team or sole responsibility for their work within the business system.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Analyse access risks, rules and responsibilities
- 1.1 Establish, analyse and describe the impact of the legal and regulatory framework on access to records for the unit or the entire organisation
- 1.2 Analyse organisational documentation and information, copies of appraisal reports and access conditions for records of comparable organisations
- 1.3 Review risk analyses and existing access rules for currency, and determine and document any necessary modifications
- 1.4 Analyse usage patterns of records taking into account identified risks and existing access rules
- 1.5 Determine specific restrictions and other responses to regulatory obligations for records and activities
- 1.6 Determine responsibility for reviewing access decisions from collected organisational documentation and information
2. Develop access strategy, classifications and rules
- 2.1 Consider factors impacting on access rights in developing an access strategy from collected information, based on established responsibilities for access to records, and in response to identified difficulties and risks
- 2.2 Determine broad access classifications and reasons for access restrictions from regulatory requirements, identified risks and usage patterns of records within the jurisdiction
- 2.3 Compile criteria for applying access classifications to records, based on collected information and performed analyses
- 2.4 Develop rules for applying classifications
- 2.5 Circulate access classifications and draft rules to users of the business or records system for comment, identifying and analysing exceptions, and modifying classifications where appropriate
- 2.6 Determine compliance regime and jurisdictional access regime
- 2.7 Seek authorisation from appropriate body for access classifications and procedures
3. Develop procedures to integrate into business or records system
- 3.1 Determine access permissions and restrictions for records by applying access rules
- 3.2 Establish and document categories of users using analyses of access rules and records usage
- 3.3 Document access permissions and restrictions in relation to categories of users
- 3.4 Establish mechanisms to control user access applying to records and to users
- 3.5 Develop and document specifications for recording authorised use of records
- 3.6 Integrate authorised access procedures into business or records system rules and procedures, and document changes
4. Review and amend access classifications and rules
- 4.1 Develop procedures for reviewing access decisions and for responding to exceptions
- 4.2 Identify a hierarchy of responsibility for reviewing access decisions to comply with jurisdictional access regime
- 4.3 Communicate changes to access rules and procedures to all users
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| D0990 | BSBRKG604B | Determine security and access rules and procedures | Unit of competency |
Replaced By
| State Code | National Code | Title | Type |
|---|---|---|---|
| OCG04 | BSBINS512 | Monitor business records systems | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| AVT9 | BSB60815 | Advanced Diploma of Recordkeeping | Qualification |