Unit of competency Outline
Date retreived
22/07/2026 10:01 AM AWST
22/07/2026 10:01 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Run vulnerability assessments for an organisation
Run vulnerability assessments for an organisation
Unit of competency
National Code
ICTCYS404
ICTCYS404
State Code
OBV13
OBV13
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
55
Description
This unit describes the skills and knowledge required to run vulnerability assessments and basic penetration tests to identify potential threats to an organisation. It includes the ability to minimise risk and remediate vulnerabilities to confirm that the security of an organisation is maintained.It applies to individuals who work as penetration tester and security consultants in any business environment.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare to run vulnerability assessment
- 1.1 Obtain work details and scope from required personnel and arrange for site access in compliance with required security arrangements, legislation, codes, regulations and standards
- 1.2 Discuss and evaluate scanning tools and select according to vulnerability assessment requirements
- 1.3 Establish testing regime and schedule, and documentation requirements according to organisational needs
2. Run vulnerability assessment and penetration test
- 2.1 Perform vulnerability assessment according to organisational procedures
- 2.2 Identify and document vulnerabilities arising from vulnerability assessment according to organisational procedures
- 2.3 Run a simple penetration test according to organisational procedures
- 2.4 Identify and document potential threats arising from penetration test according to organisational procedures
- 2.5 Contribute and develop ideas in addressing vulnerabilities
3. Finalise vulnerability assessment process
- 3.1 Discuss vulnerabilities identified in vulnerability assessment and penetration testing with required personnel
- 3.2 Contribute ideas with required personnel and remediate vulnerabilities identified according to organisational procedures
- 3.3 Escalate unresolved vulnerabilities to required personnel
- 3.4 Document identified vulnerabilities and work performed according to organisational procedures
- 3.5 Report to management and confirm vulnerability assessment with required personnel
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| AE197 | ICTSS00102 | Cyber Incident Threat Detection and Prevention Skill Set | Skill set |
| BFF9 | ICT40120 | Certificate IV in Information Technology | Qualification |