Unit of competency Outline
Date retreived
23/07/2026 12:27 AM AWST
23/07/2026 12:27 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Perform cyber security risk assessments
Perform cyber security risk assessments
Unit of competency
National Code
ICTCYS608
ICTCYS608
State Code
OBV03
OBV03
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
35
Description
This unit describes the skills and knowledge required to conduct a risk assessment and analysis in a business environment. The risk assessment requires the identity and alignment of an organisation’s operating environment to their required risk register and the realignment of their operations.It applies to those who work in risk functions of an organisation, including ICT risk managers, cyber security engineers, network engineers, DevOps engineers and cyber security solutions architects, and are responsible for designing security solutions.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Prepare to perform risk assessment
- 1.1 Analyse organisations risk culture and document findings according to organisational requirements
- 1.2 Research and document legislative and organisational cyber security risk requirements
- 1.3 Obtain and analyse organisation’s risk register and determine its currency against organisational legislative requirements
- 1.4 Develop and document risk assessment plan according to organisational requirements
- 1.5 Communicate risk assessment plan with required personnel and seek and respond to feedback
2. Perform risk assessment
- 2.1 Initiate risk assessment according to plan
- 2.2 Document process and outcomes of risk assessment according to organisational policies and procedures
3. Finalise risk assessment
- 3.1 Analyse and document findings against risk register and determine operations outside of organisation’s risk appetite
- 3.2 Develop and document operational measures to align operations against risk register requirements
- 3.3 Communicate risk assessment findings to required personnel and highlight areas of non-compliance and solutions
- 3.4 Lodge documentation according to organisational requirements
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| AE715 | ICTSS00126 | Advanced Cyber Incident Threat Detection and Prevention Skill Set | Skill set |
| AE700 | ICTSS00160 | Cyber Security for Advanced Roles Skill Set | Skill set |
| AE195 | ICTSS00103 | Cyber Security Strategy and Governance Skill Set | Skill set |
| BGJ5 | ICT60220 | Advanced Diploma of Information Technology | Qualification |
| BFF8 | ICT60120 | Advanced Diploma of Information Technology | Qualification |