Unit of competency Outline
Date retreived
23/07/2026 10:26 AM AWST
23/07/2026 10:26 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Design and implement a security system
Design and implement a security system
Unit of competency
National Code
ICANWK601A
ICANWK601A
State Code
D7980
D7980
TGA Status
Replaced
Replaced
DTWD Status
Replaced
Replaced
State Implementation and Classification
Approved Date
11/10/2011
Field of Education
099905 - Security Services
Original Release Date
11/10/2011
Nominal Hours
90
Description
This unit describes the performance outcomes, skills and knowledge required to use software tools, equipment and protocols to implement a security system.
Notes
Elements and Performance Criteria
1. Assess the security threats facing network Infrastructure
- 1.1 Evaluate mitigation methods for network attacks and different types of malware
- 1.2 Propose a methodical concept of defending network architecture
2. Secure edge devices (routers)
- 2.1 Secure network routers using software tools
- 2.2 Secure administration access to routers using the router operating system (OS)
- 2.3 Secure router OS and its configuration file(s)
3. Implement authentication, authorisation and accounting (AAA) and secure access control system (ACS)
- 3.1 Evaluate and implement the functions and importance of authentication, authorisation and accounting
- 3.2 Configure the router using AAA
- 3.3 Analyse and compare the features of TACACS+ and RADIUS AAA protocols for securing the network
4. Mitigate threats to routers and networks using access control lists (ACLs)
- 4.1 Assess the functionality of access control lists and document the caveats to be considered when building them
- 4.2 Configure and verify IP ACLs to mitigate threats and to prevent IP address spoofing using tools
5. Implement secure network management and reporting
- 5.1 Configure secure shell (SSH) on routers to enable secure management
- 5.2 Configure routers to send log messages to a log server with tools
6. Mitigate common layer 2 attacks
- 6.1 Document how to prevent layer 2 attacks by configuring basic switch security and features
- 6.2 Configure switch to prevent layer 2 attacks
7. Implement the router OS firewall-feature set
- 7.1 Evaluate and compare the operational strategies and weaknesses of the different firewall technologies
- 7.2 Implement zone-based firewall to strategically secure group of interfaces
8. Implement the intrusion detection and prevention system (IDPS) feature set in the router OS using secure device manager (SDM)
- 8.1 Evaluate and compare network based versus host based IDPS to identify malicious activity, log information, attempt to block/stop activity, and report activity
- 8.2 Explain IDPS technologies, attack responses and monitoring options
- 8.3 Configure the router OS IDPS operations using secure device manager to monitor network and system activities for malicious activity
9. Implement site-to-site virtual private networks (VPNs) using SDM
- 9.1 Assess the different methods used in cryptography
- 9.2 Evaluate internet key exchange (IKE) protocol functionality and phases to support authentication and define the binding blocks of IPSec and the security functions it provides
- 9.3 Configure and verify an IPSec site-to-site VPN with pre-shared key (PSK) authentication to provide a secure channel between the two parties
The range statement relates to the unit of competency as a whole. It allows for different work environments and situations that may affect performance. Bold italicised wording, if used in the performance criteria, is detailed below. Essential operating conditions that may be present with training and assessment (depending on the work situation, needs of the candidate, accessibility of the item, and local industry and regional contexts) may also be included.
Network may include:
data
internet
protocol
large and small LANs
virtual LAN (VLAN)
WANs.
Tools may include:
Cisco security device manager (SDM)
command line interface (CLI)
web interface.
Administration access may include:
multiple privilege levels
role-based CLI
strong-encrypted passwords.
Features of TACACS+ and RADIUS AAA protocols may include:
remote authentication dial-in user service (RADIUS):
combines authentication and authorisation
does not allow users to control which commands can be executed on a router
does not support ARA access, NetBIOS Frame Protocol Control Protocol, NASI, and X.25 PAD connections
encrypts only the password in the access-request packet
uses industry standard
uses UDP
TACACS+:
encrypts the entire body of the packet
is Cisco proprietary
offers multiprotocol support
provides two ways to control the authorisation of router commands on a per-user or per-group basis
uses transmission control protocol (TCP)
uses the AAA architecture, which separates authentication, authorisation and accounting.
Access control lists may include:
extended
named
standard.
Network may include:
data
internet
protocol
large and small LANs
virtual LAN (VLAN)
WANs.
Tools may include:
Cisco security device manager (SDM)
command line interface (CLI)
web interface.
Administration access may include:
multiple privilege levels
role-based CLI
strong-encrypted passwords.
Features of TACACS+ and RADIUS AAA protocols may include:
remote authentication dial-in user service (RADIUS):
combines authentication and authorisation
does not allow users to control which commands can be executed on a router
does not support ARA access, NetBIOS Frame Protocol Control Protocol, NASI, and X.25 PAD connections
encrypts only the password in the access-request packet
uses industry standard
uses UDP
TACACS+:
encrypts the entire body of the packet
is Cisco proprietary
offers multiprotocol support
provides two ways to control the authorisation of router commands on a per-user or per-group basis
uses transmission control protocol (TCP)
uses the AAA architecture, which separates authentication, authorisation and accounting.
Access control lists may include:
extended
named
standard.
The evidence guide provides advice on assessment and must be read in conjunction with the performance criteria, required skills and knowledge, range statement and the Assessment Guidelines for the Training Package.
Overview of assessment
Critical aspects for assessment and evidence required to demonstrate competency in this unit
Evidence of the ability to:
evaluate network security system threats and requirements
mitigate attacks and configure firewalls
design and implement network security systems
implement VPN using SDM.
Context of and specific resources for assessment
Assessment must ensure access to:
site where network security may be evaluated and tightened
hardware and software
organisational guidelines, procedures and policies
computers
LAN or WLAN internet work technologies (hardware and software)
security technologies (hardware and software)
appropriate learning and assessment support when required
modified equipment for people with special needs.
Method of assessment
A range of assessment methods should be used to assess practical skills and knowledge. The following examples are appropriate for this unit:
direct observation of the candidate installing, configuring and testing a new or updated network
evaluation of documentation outlining testing procedures, test results, recommendation to network changes and completion records
verbal or written questioning of required knowledge.
Guidance information for assessment
Holistic assessment with other units relevant to the industry sector, workplace and job role is recommended, where appropriate.
Assessment processes and techniques must be culturally appropriate, and suitable to the communication skill level, language, literacy and numeracy capacity of the candidate and the work being performed.
Indigenous people and other people from a non-English speaking background may need additional support.
In cases where practical assessment is used it should be combined with targeted questioning to assess required knowledge.
Overview of assessment
Critical aspects for assessment and evidence required to demonstrate competency in this unit
Evidence of the ability to:
evaluate network security system threats and requirements
mitigate attacks and configure firewalls
design and implement network security systems
implement VPN using SDM.
Context of and specific resources for assessment
Assessment must ensure access to:
site where network security may be evaluated and tightened
hardware and software
organisational guidelines, procedures and policies
computers
LAN or WLAN internet work technologies (hardware and software)
security technologies (hardware and software)
appropriate learning and assessment support when required
modified equipment for people with special needs.
Method of assessment
A range of assessment methods should be used to assess practical skills and knowledge. The following examples are appropriate for this unit:
direct observation of the candidate installing, configuring and testing a new or updated network
evaluation of documentation outlining testing procedures, test results, recommendation to network changes and completion records
verbal or written questioning of required knowledge.
Guidance information for assessment
Holistic assessment with other units relevant to the industry sector, workplace and job role is recommended, where appropriate.
Assessment processes and techniques must be culturally appropriate, and suitable to the communication skill level, language, literacy and numeracy capacity of the candidate and the work being performed.
Indigenous people and other people from a non-English speaking background may need additional support.
In cases where practical assessment is used it should be combined with targeted questioning to assess required knowledge.
Replaced By
| State Code | National Code | Title | Type |
|---|---|---|---|
| AUV14 | ICTNWK601 | Design and implement a security system | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| D576 | ICA60111 | Advanced Diploma of Information Technology | Qualification |
| D578 | ICA60311 | Advanced Diploma of Information Technology Business Analysis | Qualification |
| D577 | ICA60211 | Advanced Diploma of Network Security | Qualification |