Unit of competency Outline
Date retreived
23/07/2026 1:25 AM AWST
23/07/2026 1:25 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Identify and assess cyber security insider threats and risks
Identify and assess cyber security insider threats and risks
Unit of competency
National Code
BSBXCS305
BSBXCS305
State Code
ODR66
ODR66
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
27/04/2022
Field of Education
080399 - Business And Management, N.e.c.
Original Release Date
27/04/2022
Nominal Hours
40
Description
This unit describes the skills and knowledge required to contribute to business operations by identifying and assessing cyber security insider threats and risks. This includes reviewing and applying organisational processes for identifying and documenting insider threats.The unit covers insider threats and risks that relate to individuals in an organisation who commit an act, intentionally or unintentionally, that causes harm.The unit applies to individuals who identify and communicate identified insider threats and risks to required management and information technology (IT) personnel. No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare to identify insider threats and risks in workplace
- 1.1 Identify common types of insider threats and risks
- 1.2 Determine organisational process for identifying and assessing insider threats and risks
2. Identify and assess insider threats and risks
- 2.1 Review organisational processes and identify gaps that may allow for insider threats and risks to occur
- 2.2 Monitor work activities and identify digital and behavioural indicators of insider threats and risks in organisation
- 2.3 Analyse identified indicators and confirm existence of insider threats and risks
- 2.4 Identify potential impact and probability of identified threats and risks
3. Complete identification and assessment of threats and risks
- 3.1 Document identified insider threats and risks according to organisational policies and procedures
- 3.2 Communicate identified insider threats and risks to required management and information technology (IT) personnel within scope of own role
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| BFS5 | BSB30120 | Certificate III in Business | Qualification |
| AE661 | BSBSS00130 | Workplace Cyber Security Foundations Skill Set | Skill set |