Unit of competency Outline
Date retreived
23/07/2026 1:29 AM AWST
23/07/2026 1:29 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Develop, implement and evaluate systems and applications security
Develop, implement and evaluate systems and applications security
Unit of competency
National Code
ICTNWK545
ICTNWK545
State Code
OBT55
OBT55
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
020113 - Networks And Communications
Original Release Date
15/01/2021
Nominal Hours
55
Description
This unit describes the skills and knowledge required to develop, implement and evaluate information security in an Information and Communications Technology (ICT) system or application during the system development life cycle (SDLC) and prior to the operations and maintenance phase.It applies to individuals who work as network managers and required to handle system and application security from the development phase through implementation to evaluation. No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Develop system and application security
- 1.1 Identify organisational ICT system and application security requirements
- 1.2 Determine and document ICT system and application security plan according to organisational requirements
- 1.3 Identify risk-based audit performance criteria against the ICT system or application
- 1.4 Develop and document required mitigation of vulnerabilities processes and procedures
- 1.5 Integrate information security requirements, controls, processes and procedures into ICT system and application design specifications
2. Implement system and application security
- 2.1 Execute and verify operational compliance according to technical and organisational requirements
- 2.2 Perform required configuration management practices and mitigate introduction of vulnerabilities
- 2.3 Validate and re-engineer ICT system and application security controls and operations phase vulnerabilities
- 2.4 Document ICT system and application security controls according to organisational policies and procedures
3. Evaluate system and application security
- 3.1 Assess effectiveness of information system controls against required risk management practices and procedures
- 3.2 Assess and evaluate system compliance against organisational requirements
- 3.3 Assess system maturation and readiness for promotion to production stage according to organisational requirements
- 3.4 Document assessment findings and submit to required personnel
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AUV01 | ICTNWK510 | Develop, implement and evaluate system and application security | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| BFG0 | ICT50120 | Diploma of Information Technology | Qualification |
| BGJ4 | ICT50220 | Diploma of Information Technology | Qualification |