Unit of competency Outline

Date retreived
22/07/2026 5:48 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Respond to cyber security incidents

Respond to cyber security incidents

Unit of competency
National Code
ICTCYS406
State Code
OBV11
TGA Status
Current
DTWD Status
Approved
Current Release Number
2.00
Current Release Date
02/10/2020
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
35
Description
This unit describes the skills and knowledge required to establish and respond to cyber security incidents in an organisation, and evaluate actions performed to mitigate risk of future incidents.It applies to individuals who work in information technology security, including network specialists and security, to support all business functions responding to cyber incidents. These individuals have a broad range of knowledge and skills in cyber security, networks and systems. In this context, the individual works as an internal function for an organisation, however, the same can be applied in the context of an external security specialist advising and implementing the response and action items of a cyber-attack to an external client.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Establish cyber security incident
  • 1.1 Establish and confirm occurrence and nature of cyber security incident
  • 1.2 Identify legislative requirements, organisational policies and procedures and cyber security incident response plans
  • 1.3 Analyse and assess source, impact and consequences of incident according to organisational response plans
  • 1.4 Notify and explain cyber incident to required personnel according to legislative requirements and communications plans
2. Activate cyber security incident response plan
  • 2.1 Activate incident response plan and confirm cyber incident is contained
  • 2.2 Escalate and involve third party services and specialists as required according to organisational policies and procedures
  • 2.3 Confirm no further risks exist according to legislative requirements and organisational response procedures
  • 2.4 Discuss solutions with required personnel and action accordingly
  • 2.5 Test solution implemented, and escalate as required according to organisational security procedures
3. Perform post cyber security incident response procedures
  • 3.1 Evaluate actions taken and confirm incident is fixed and secure according to organisational procedures
  • 3.2 Document cyber security incident, actions performed and solution, according to organisational policies and procedures
  • 3.3 Discuss and document lessons learnt with required personnel
  • 3.4 Discuss and implement preventative measures and mitigation methods as required
  • 3.5 Amend incident response plan accordingly
  • 3.6 Share documentation and communicate with required personnel according to organisational communications plan
No information
No information
No information