Unit of competency Outline
Date retreived
23/07/2026 3:05 PM AWST
23/07/2026 3:05 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Protect cloud infrastructure and data
Protect cloud infrastructure and data
Unit of competency
National Code
ICTCLD511
ICTCLD511
State Code
ODT30
ODT30
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
25/05/2022
Field of Education
029901 - Security Science
Original Release Date
25/05/2022
Nominal Hours
55
Description
This unit describes the skills and knowledge required to protect networks and resources, and compute both at rest and in transit data in cloud environments.The unit applies to individuals who may work in roles such as security engineers, cloud developers and architects, and information security officers. It also includes individuals responsible for managing operational concerns, including automation and maintaining cloud resources.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Review cloud usage and risks
- 1.1 Confirm work brief and tasks according to organisational policies and procedures
- 1.2 Locate sensitive and regulated data identified in work brief
- 1.3 Assess data sensitivity and potential risk to organisation
- 1.4 Review existing data processing services and assess potential risk to organisation
- 1.5 Review data processing service configuration and identify opportunities to improve security and reduce risk to organisation
- 1.6 Document findings according to organisational policies and procedures, and prioritise recommendations.
2. Implement resource protection controls
- 2.1 Confirm work brief for network security controls
- 2.2 Access cloud platform and implement change to environment
- 2.3 Test security controls and confirm resources are being protected as expected
- 2.4 Confirm functionality of network resources and rectify any issues
- 2.5 Document configuration changes according to organisational policies and procedures
3. Implement data encryption at rest
- 3.1 Confirm work brief for data encryption controls
- 3.2 Generate and secure encryption key in cloud platform according to organisational policies and procedures
- 3.3 Encrypt sensitive data with encryption key
- 3.4 Where practical, demonstrate that data is unreadable without access and use of encryption key
- 3.5 Demonstrate that encryption key is only accessible by required personnel and services in cloud environment
- 3.6 Document configuration changes according to organisational policies and procedures
4. Implement data protection controls
- 4.1 Confirm work brief related to data protection controls
- 4.2 Identify cloud-based data loss protection (DLP) service
- 4.3 Enable and configure DLP across organisation’s storage and identify sensitive information
- 4.4 Review DLP reports, document findings and recommend system improvements
- 4.5 Document configuration changes according to organisational policies and procedures
5. Recommend updates to organisational policies and procedures
- 5.1 Summarise required changes for organisational policies and procedures
- 5.2 Present summary to required personnel
- 5.3 Obtain approval from required personnel
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| AE701 | ICTSS00125 | Cloud Security Skill Set | Skill set |
| BGJ4 | ICT50220 | Diploma of Information Technology | Qualification |