Unit of competency Outline

Date retreived
23/07/2026 12:27 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Ensure dynamic website security

Ensure dynamic website security

Unit of competency
National Code
ICTWEB423
State Code
AUP93
TGA Status
Replaced
DTWD Status
Replaced
Current Release Number
1.00
Current Release Date
25/03/2015
State Implementation and Classification
Approved Date
16/09/2015
Field of Education
029901 - Security Science
Original Release Date
16/09/2015
Nominal Hours
25
Description
This unit describes the skills and knowledge required to ensure, and maintain, the security of a dynamic commercial website.It applies to individuals working as website developers responsible for security of dynamic websites, who are proficient communicators and can analyse technical data capably and with efficiency.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Undertake the risk assessment
  • 1.1 Identify the functionality and features of the website, and confirm these with the client
  • 1.2 Identify security threats, with reference to the functionality of the site and organisational security policy, legislation and standards
  • 1.3 Complete a risk analysis to prioritise the security threats, and identify system vulnerabilities
  • 1.4 Identify resource and budget constraints, and validate with the client as required
  • 1.5 Source the appropriate products, security services and equipment, according to enterprise purchasing policies
2. Secure the operating systems
  • 2.1 Identify operating system (OS) and cross-platform vulnerabilities
  • 2.2 Make the appropriate scripting or configuration adjustments, with reference to the functionality of the site and the security policy
  • 2.3 Identify and rectify weaknesses specific to the OS
3. Secure the site server
  • 3.1 Configure the web server securely, with reference to the required functionality and the security policy
  • 3.2 Review and analyse, server-side scripting with reference to the required functionality and the security policy
  • 3.3 Install firewalls as required
  • 3.4 Establish access control permissions to the server and database
4. Secure data transactions
  • 4.1 Identify data transactions, with reference to the functionality and features of the website
  • 4.2 Identify and apply, the channel protocols related to the requirements
  • 4.3 Install and configure, the payment systems
5. Monitor and document the security framework
  • 5.1 Develop a program of selective independent audits and penetration tests
  • 5.2 Determine the performance benchmarks
  • 5.3 Implement audit and test programs, and record, analyse and report the results
  • 5.4 Make security framework changes based on the test results
  • 5.5 Develop the site-security plan, with reference to the security policy and requirements
  • 5.6 Develop and distribute, related policy and procedures to the client
No information
No information
Replaces
State Code National Code Title Type
D8146 ICAWEB423A Ensure dynamic website security Unit of competency
Replaced By
State Code National Code Title Type
ODT26 ICTNWK435 Create secure virtual private networks Unit of competency