Unit of competency Outline
Date retreived
22/07/2026 8:20 AM AWST
22/07/2026 8:20 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Contribute to cyber security risk management
Contribute to cyber security risk management
Unit of competency
National Code
BSBXCS404
BSBXCS404
State Code
OBO73
OBO73
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
14/05/2020
Field of Education
029901 - Security Science
Original Release Date
14/05/2020
Nominal Hours
25
Description
This unit describes the skills and knowledge required to contribute to cyber security risk management, which includes assisting in developing and managing associated risk management strategies. It applies to those working in a broad range of industries and job roles who work alongside technical experts to develop cyber security risk-management strategies.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Contribute to recommending risk management strategies that mitigate cyber security risk
- 1.1 Consult with stakeholders to determine scope of risk management appropriate to organisation and industry
- 1.2 Review relevant critical cyber risk management strategies appropriate to level of risk
- 1.3 Assist in developing suitable cyber security response options according to organisational policies and procedures
- 1.4 Present options for risk management strategies for approval within scope of own role
- 1.5 Document approved risk management strategies
2. Support implementation of approved risk management strategies in response to risk
- 2.1 Support communication of approved risk management strategies to required personnel
- 2.2 Contribute to monitoring cyber security risk according to selected risk management strategies
- 2.3 Assist in determining compliance with implemented cyber risk mitigation strategies
- 2.4 Address non-compliance within scope of own role and escalate where required according to organisational policies and procedures
- 2.5 Assist in establishing feedback processes that provide warning of potential new risks according to organisational requirements
3. Review and revise implemented risk management strategies
- 3.1 Identify benchmarks to track effectiveness of risk management strategies
- 3.2 Support evaluation of effectiveness of implemented strategies
- 3.3 Update risk management strategies with new information as required
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| BFR1 | BSB40120 | Certificate IV in Business | Qualification |
| AE728 | ICTSS00132 | Core Technical IT Skills for Introductory Roles Skill Set | Skill set |
| AE096 | BSBSS00093 | Cyber Security Threat Assessment and Risk Management Skill Set | Skill set |
| BFF9 | ICT40120 | Certificate IV in Information Technology | Qualification |
| BFF7 | ICT30120 | Certificate III in Information Technology | Qualification |
| AVR3 | BSB42015 | Certificate IV in Leadership and Management | Qualification |
| AVR2 | BSB41515 | Certificate IV in Project Management Practice | Qualification |