Unit of competency Outline
Date retreived
23/07/2026 10:00 AM AWST
23/07/2026 10:00 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Undertake information technology security audits
Undertake information technology security audits
Unit of competency
National Code
PSPSEC004
PSPSEC004
State Code
AWT41
AWT41
TGA Status
Deleted
Deleted
DTWD Status
Deleted
Deleted
State Implementation and Classification
Approved Date
21/07/2016
Field of Education
029901 - Security Science
Original Release Date
21/07/2016
Nominal Hours
30
Description
This unit describes the skills required to plan and conduct an information technology security audit and report on security findings.This unit applies to those working in a role where they have responsibilities under the organisation's security plan.The skills and knowledge described in this unit must be applied within the legislative, regulatory and policy environment in which they are carried out. Organisational policies and procedures must be consulted and adhered to.Those undertaking this unit would generally work independently and as part of a team using support resources as required. They would perform complex tasks in a range of familiar and unfamiliar contexts.No licensing, legislative or certification requirements apply to unit at the time of publication.
Notes
Elements and Performance Criteria
1. Plan security audit
- 1.1 Identify the scope and objectives of the audit and prepare an audit plan to meet the objectives.
- 1.2 Identify the organisation’s information systems to be included in the audit plan.
- 1.3 Advise appropriate personnel of the audit plan and its requirements.
- 1.4 Identify and prioritise possible sources of security risk and prepare an audit checklist.
2. Conduct security audit
- 2.1 Identify and analyse systems, procedures, records and documents.
- 2.2 Conduct audit in accordance with the audit plan.
- 2.3 Record audit activities.
- 2.4 Identify situations requiring specialist input or referral to other areas and act on referral.
3. Report on security findings
- 3.1 Maintain audit records and prepare audit reports.
- 3.2 Produce report including background, scope, outcomes and recommendations.
- 3.3 Use language and style to suit the audience and in line with organisational requirements for accuracy and timeliness.
- 3.4 Support recommendations with evidence and highlight actions identifying person/s responsible for implementation.
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| C8316 | PSPSEC304A | Undertake information technology security audits | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| AZX1 | PSP30116 | Certificate III in Government | Qualification |