Unit of competency Outline

Date retreived
23/07/2026 12:51 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Manage information security compliance of cloud service deployment

Manage information security compliance of cloud service deployment

Unit of competency
National Code
ICTCLD602
State Code
OBV17
TGA Status
Current
DTWD Status
Approved
Current Release Number
1.00
Current Release Date
21/07/2020
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
35
Description
This unit describes the skills and knowledge required to manage cloud security controls, privacy and legal compliance when implementing cloud services for an enterprise.It applies to those with managerial responsibility of a business’ IT infrastructure, including cloud engineers, systems engineers and experienced security technical specialists, security analysts, security consultants.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Identify information security risks for cloud service
  • 1.1 Identify cloud security risks for different cloud delivery and deployment models
  • 1.2 Identify and review legal, privacy and contractual issues, organisational policies, procedures and requirements
  • 1.3 Map responsibilities between organisation and cloud vendor
  • 1.4 Review compliance controls of cloud vendor
  • 1.5 Identify risks and identify risks that are organisation’s responsibility
2. Manage cloud security controls
  • 2.1 Identify security controls provided by the cloud vendor for cloud service
  • 2.2 Map security controls to organisation risks
  • 2.3 Configure security controls to mitigate risk according to business needs
  • 2.4 Document configuration of security control and risk mitigation
3. Manage cloud privacy compliance
  • 3.1 Identify required data storage compliance regulations
  • 3.2 Determine data privacy risks associated with cloud service
  • 3.3 Determine and implement business continuity and data recovery plan requirements
  • 3.4 Review user access policies and configuration to data
  • 3.5 Identify, secure and maintain, logs and audit trails according to business requirements
  • 3.6 Document data privacy risk mitigation
4. Implement information security compliance enhancements
  • 4.1 Implement and integrate required changes into organisations risk register and business continuity plans (BCP)
  • 4.2 Establish and document performance measurement program and evaluate security effectiveness of implemented security controls
  • 4.3 Submit documentation changes to required personnel
  • 4.4 Obtain final task sign of from required personnel
No information
No information
Replaces
State Code National Code Title Type
AUX08 ICTNWK616 Manage security, privacy and compliance of cloud service deployment Unit of competency