Unit of competency Outline
Date retreived
22/07/2026 7:36 AM AWST
22/07/2026 7:36 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Securely manage personally identifiable information and workplace information
Securely manage personally identifiable information and workplace information
Unit of competency
National Code
BSBXCS303
BSBXCS303
State Code
OBO70
OBO70
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
14/05/2020
Field of Education
029901 - Security Science
Original Release Date
14/05/2020
Nominal Hours
35
Description
This unit describes the skills and knowledge required to securely manage personally identifiable information (PII) and workplace information. It applies to those working in a broad range of industries and job roles under some supervision and guidance who manage large amounts of PII and workplace information.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Handle PII and workplace information responsibly
- 1.1 Review current standards, practices and procedures relating to workplace information
- 1.2 Identify sensitive data in own workplace environment according to organisational policies and procedures and within scope of own role
- 1.3 Classify workplace information types according to organisational procedures
- 1.4 Apply privacy policies to all data devices that require confidentiality
2. Store and share PII and workplace information securely
- 2.1 Organise obtained data sets in an easily retrievable format
- 2.2 Implement required access control protocols for identified sensitive data
- 2.3 Confirm that data is accurate, up-to-date, and comprehensive
- 2.4 Identify and report malfunctioning infrastructure and attacks on infrastructure that pose a threat to data integrity
3. Apply information protection protocols
- 3.1 Conduct back-up of on-site and off-site data according to organisational policies and procedures
- 3.2 Conduct privacy impact assessments on data
- 3.3 Confirm adherence to data protection compliance standards
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGJ3 | ICT20120 | Certificate II in Applied Digital Technologies | Qualification |
| BFS5 | BSB30120 | Certificate III in Business | Qualification |
| AE098 | BSBSS00094 | Cyber Security Awareness Skill Set | Skill set |
| AE225 | ICTSS00108 | Digital Skills for Small Business Skill Set | Skill set |
| BFS3 | BSB30220 | Certificate III in Entrepreneurship and New Business | Qualification |
| AE226 | ICTSS00109 | Entry to Tech Skill Set | Skill set |
| BFF7 | ICT30120 | Certificate III in Information Technology | Qualification |
| AE781 | Introduction to Cyber Security | Skill set | |
| BFS4 | BSB30420 | Certificate III in Library and Information Services | Qualification |
| AVT8 | BSB30315 | Certificate III in Micro Business Operations | Qualification |