Unit of competency Outline

Date retreived
22/07/2026 4:00 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Detect and respond to cyber security insider risks and threats

Detect and respond to cyber security insider risks and threats

Unit of competency
National Code
ICTCYS615
State Code
ODC06
TGA Status
Current
DTWD Status
Approved
Current Release Number
1.00
Current Release Date
09/04/2021
State Implementation and Classification
Approved Date
18/06/2021
Field of Education
029901 - Security Science
Original Release Date
18/06/2021
Nominal Hours
70
Description
This unit describes the skills and knowledge required to detect and respond to intentional and unintentional cyber security insider risks and threats, including the configuration of tools.The unit applies to those who work in information technology security roles, including cyber security analysts and specialists, cyber risk and assurance managers, and other related roles that are responsible for detecting and responding to cyber security insider risks and threats.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare to detect organisational cyber security insider risks and threats
  • 1.1 Obtain work details from required personnel
  • 1.2 Evaluate and apply privacy requirements according to organisational policies and procedures, legislation, codes, regulations, standards and security arrangements
  • 1.3 Analyse type of behaviours that indicate cyber security insider risks and threats
  • 1.4 Analyse sources of sensitive data and business processes that are vulnerable to cyber security insider risks and threats
  • 1.5 Select required cyber security insider risk and threat detection tools according to organisational policies and procedures
2. Configure and monitor cyber security insider risk and threat detection tools
  • 2.1 Configure cyber security insider risk and threat detection tools into organisation’s operations and infrastructure
  • 2.2 Use behavioural analysis and cyber security insider risk and threat detection tools
  • 2.3 Monitor potential breaches identified by tool and abnormal outputs from behavioural analysis
  • 2.4 Locate source of breaches and determine extent of cyber security insider risks, threats and their organisational impact
  • 2.5 Maintain custody chain according to legislative requirements and organisational security procedures
3. Respond to cyber security insider risks and threats
  • 3.1 Consult with required personnel to determine suitable course of action to mitigate identified risks and threats, and restrict user access where required
  • 3.2 Implement determined course of action according to organisational policies and procedures
  • 3.3 Test course of action according to organisational security procedures and escalate test findings to required personnel, where required
4. Finalise response to cyber security insider risks and threats
  • 4.1 Evaluate course of action taken and confirm that risks and threats have been contained
  • 4.2 Document exposed data and implemented course of action according to organisational requirements
  • 4.3 Gather feedback on risk and threat detection and response process from personnel involved in the incident
  • 4.4 Develop and submit report on threat detection and response according to legislative requirements and organisational policies and procedures
No information
No information
No information