Unit of competency Outline
Date retreived
22/07/2026 5:25 AM AWST
22/07/2026 5:25 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Implement security for applications
Implement security for applications
Unit of competency
National Code
ICTPRG537
ICTPRG537
State Code
OBT04
OBT04
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
020103 - Programming
Original Release Date
15/01/2021
Nominal Hours
50
Description
This unit describes the skills and knowledge required to implement security for software applications, including code access security, security access control, cryptographic and secure, input and output handling.It applies to individuals who work as software developers, software engineers, system and security administrators and testers, and responsible for coding secure software applications.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Implement policy-based code-access security
- 1.1 Identify purpose of application security in software development
- 1.2 Configure required platform security configuration files using security configuration tools
- 1.3 Define required restriction custom code access permission and restrict access to protected resources
- 1.4 Define required access restriction custom code access and run protected operations
2. Implement security access control
- 2.1 Plan and document authentication and authorisation strategy according to organisational policies and procedures
- 2.2 Develop and document required application authentication and authorisation strategy
3. Write encrypt and decrypt code data
- 3.1 Determine and document required standard cryptographic algorithms
- 3.2 Encrypt, and decrypt, data using standard cryptographic algorithms
4. Protect application against injections
- 4.1 Plan and document secure input and output handling and prevent vulnerabilities related to code injections
- 4.2 Use secure input and output handling according to task requirements
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AUV80 | ICTPRG507 | Implement security for applications | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| AC942 | ICTSS00031 | Application Development Specialist Skill Set | Skill set |
| AE742 | ICTSS00166 | Application Development Specialist Skill Set | Skill set |
| BFG0 | ICT50120 | Diploma of Information Technology | Qualification |
| BGJ5 | ICT60220 | Advanced Diploma of Information Technology | Qualification |
| BGJ4 | ICT50220 | Diploma of Information Technology | Qualification |
| BFF8 | ICT60120 | Advanced Diploma of Information Technology | Qualification |
| AE693 | ICTSS00162 | Programming Skills for Advanced Roles Skill Set | Skill set |