Unit of competency Outline
Date retreived
22/07/2026 2:07 PM AWST
22/07/2026 2:07 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Develop security risk management plans
Develop security risk management plans
Unit of competency
National Code
CPPSEC5004
CPPSEC5004
State Code
OBI59
OBI59
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
20/05/2020
Field of Education
099905 - Security Services
Original Release Date
20/05/2020
Nominal Hours
40
Description
This unit specifies the skills and knowledge required to develop comprehensive security risk management plans based on the principles of ISO31000:2018 Risk management - Guidelines (ISO31000). It includes identifying and evaluating security risks and existing control measures, developing action plans to identify and manage risks, designing risk treatment options and testing them in the field as part of a security risk management strategy.This unit is suitable for those using a broad range of cognitive, technical and communication skills to select and apply methods and technologies to analyse information and provide solutions to sometimes complex problems.Legislative, regulatory or certification requirements apply in some states and territories to the provision of advice on security solutions, strategies, protocols and procedures. For further information, check with the relevant regulatory authority.
Notes
Elements and Performance Criteria
1 Evaluate security risks and controls.
- 1.1 Access and interpret key requirements of legislation, regulations and Australian standard ISO31000 to understand and comply with requirements for developing security risk management plans.
- 1.2 Clarify client security requirements and operating environment in consultation with relevant persons.
- 1.3 Source and review information to identify security risks.
- 1.4 Clearly distinguish and confirm acceptable and unacceptable security risks.
- 1.5 Set priorities for risk treatment and assurance of controls.
- 1.6 Highlight and specify risks that are high priority to ensure appropriate controls are developed.
- 1.7 Evaluate existing controls to determine impact on risk occurrence and implement required modifications.
2 Plan risk management strategies.
- 2.1 Develop and document action plans that identify tasks, activities and resources required to achieve security risk management objectives.
- 2.2 Select security risk control measures based on assessed type, nature, cause and degree of risk associated with identified security risks.
- 2.3 Incorporate actions to respond to contingencies when planning risk management strategies.
- 2.4 Establish communication and reporting arrangements to maintain currency of action plans in consultation with relevant persons.
3 Design security risk treatment options.
- 3.1 Assess client’s operating environment to confirm potential and real security risks.
- 3.2 Select feasible risk treatment options and conduct research to confirm implications for controlling whole or part of security risks.
- 3.3 Document and cost recommended risk treatment options to ensure compatibility with nature of risk and client requirements.
- 3.4 Consult with relevant persons to verify suitability of recommended risk treatment options and obtain required approvals.
- 3.5 Test risk treatment options in the field and analyse results to verify effectiveness of treatments in the security context.
4 Finalise and present security risk management plan.
- 4.1 Finalise and document comprehensive security risk management plan in the required format according to workplace requirements.
- 4.2 Check security risk management plan to ensure analysis and recommendations are clear, coherent and consistent with client requirements, and based on the principles of ISO 31000.
- 4.3 Present risk management plan to relevant persons within agreed timeframes and explain identified security risks and treatments to enhance understanding and acceptance of recommendations.
- 4.4 Implement procedures to monitor and review security risk management activities to ensure continuous improvement.
- 4.5 Complete and secure risk management plan in a manner that facilitates future retrieval and maintains client confidentiality according to workplace and regulatory requirements.
No information
No information
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| D1475 | CPPSEC5004A | Prepare security risk management plan | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGJ5 | ICT60220 | Advanced Diploma of Information Technology | Qualification |
| BFF8 | ICT60120 | Advanced Diploma of Information Technology | Qualification |
| BEW8 | CPP41519 | Certificate IV in Security Risk Analysis | Qualification |
| BEX1 | CPP50619 | Diploma of Security Risk Management | Qualification |