Unit of competency Outline
Date retreived
22/07/2026 10:52 PM AWST
22/07/2026 10:52 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Develop employee cyber security risk profiles
Develop employee cyber security risk profiles
Unit of competency
National Code
BSBXCS408
BSBXCS408
State Code
ODR59
ODR59
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
27/04/2022
Field of Education
080301 - Business Management
Original Release Date
27/04/2022
Nominal Hours
45
Description
This unit describes the skills and knowledge required to contribute to business operations and risk mitigation by developing employee cyber security risk profiles. This includes identifying the organisational risk landscape, assessing compliant employee characteristics, and documenting employee risk characteristics.The unit applies to individuals with specialist skills who contribute to employee cyber security risk mitigation in an organisation.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare to develop employee risk profiles
- 1.1 Consult with key stakeholders on common employee cyber security risks faced by organisation
- 1.2 Assess probability and cost of employee cyber security risks faced by organisation
- 1.3 Identify and evaluate existing organisational strategies to mitigate risk for current and future employees
- 1.4 Identify relationship between frequency of employee cyber security risk events and existing organisational strategies to mitigate employee risk
- 1.5 Determine current level of workplace awareness regarding employee cyber security risk
- 1.6 Consult with key stakeholders to determine scope of employee cyber security risk management appropriate to organisation
2. Assess individual employee risk characteristics
- 2.1 Consult with key stakeholders to determine characteristics of an employee compliant with organisational policies and procedures
- 2.2 Consult with key stakeholders to determine high risk characteristics of employees in organisation
- 2.3 Identify and document high risk characteristics of employees and potential candidates, and of different demographics in organisation
3. Finalise employee cyber security risk profile
- 3.1 Assess organisational priorities in maintaining cyber security safety
- 3.2 Document employee and potential candidate cyber security risks in a risk profile against identified priorities according to organisational policies and procedures and legislative requirements
- 3.3 Update employee cyber security risk profile with new information as required and according to organisational policies and procedures and legislative requirements
- 3.4 Inform required personnel of key employee cyber security risks
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| BIX0 | MEM40222 | Certificate IV in Boating Services | Qualification |
| BFR2 | BSB40520 | Certificate IV in Leadership and Management | Qualification |
| AE663 | BSBSS00131 | Workplace Cyber Security Threat and Risk Prevention Skill Set | Skill set |