Unit of competency Outline

Date retreived
23/07/2026 1:29 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Develop, implement and evaluate systems and applications security

Develop, implement and evaluate systems and applications security

Unit of competency
National Code
ICTNWK545
State Code
OBT55
TGA Status
Current
DTWD Status
Approved
Current Release Number
1.00
Current Release Date
21/07/2020
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
020113 - Networks And Communications
Original Release Date
15/01/2021
Nominal Hours
55
Description
This unit describes the skills and knowledge required to develop, implement and evaluate information security in an Information and Communications Technology (ICT) system or application during the system development life cycle (SDLC) and prior to the operations and maintenance phase.It applies to individuals who work as network managers and required to handle system and application security from the development phase through implementation to evaluation. No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Develop system and application security
  • 1.1 Identify organisational ICT system and application security requirements
  • 1.2 Determine and document ICT system and application security plan according to organisational requirements
  • 1.3 Identify risk-based audit performance criteria against the ICT system or application
  • 1.4 Develop and document required mitigation of vulnerabilities processes and procedures
  • 1.5 Integrate information security requirements, controls, processes and procedures into ICT system and application design specifications
2. Implement system and application security
  • 2.1 Execute and verify operational compliance according to technical and organisational requirements
  • 2.2 Perform required configuration management practices and mitigate introduction of vulnerabilities
  • 2.3 Validate and re-engineer ICT system and application security controls and operations phase vulnerabilities
  • 2.4 Document ICT system and application security controls according to organisational policies and procedures
3. Evaluate system and application security
  • 3.1 Assess effectiveness of information system controls against required risk management practices and procedures
  • 3.2 Assess and evaluate system compliance against organisational requirements
  • 3.3 Assess system maturation and readiness for promotion to production stage according to organisational requirements
  • 3.4 Document assessment findings and submit to required personnel
No information
No information
Replaces
State Code National Code Title Type
AUV01 ICTNWK510 Develop, implement and evaluate system and application security Unit of competency
State Code National Code Title Type
BFG0 ICT50120 Diploma of Information Technology Qualification
BGJ4 ICT50220 Diploma of Information Technology Qualification