Unit of competency Outline
Date retreived
22/07/2026 10:54 AM AWST
22/07/2026 10:54 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Plan and implement information security strategies for an organisation
Plan and implement information security strategies for an organisation
Unit of competency
National Code
ICTCYS403
ICTCYS403
State Code
OBV14
OBV14
TGA Status
Current
Current
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
15/01/2021
Field of Education
029901 - Security Science
Original Release Date
15/01/2021
Nominal Hours
35
Description
This unit describes the skills and knowledge required to develop an information security and risk management strategy (ISRM) within an organisation that supports business processes.It applies to individuals who work in information technology security and have the knowledge and skills in cyber security to support business functions in planning and implementing information security strategies. In this instance, the individual may work internally within an organisation, or be engaged externally in supporting organisations with their development of information security strategies. No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Plan information security strategies
- 1.1 Discuss implementation opportunities for organisational information security strategies with required personnel
- 1.2 Gain management buy in and approval in planning and implementing information security strategy
- 1.3 Identify and confirm organisational policies including password policies, bring your own device (BYOD) and on boarding processes with required personnel
- 1.4 Analyse organisational environments, processes and risk profile requirements
- 1.5 Identify legislation and industry requirements to implement information security strategies in an organisation
2. Design and implement information security strategy
- 2.1 Develop action plan with specific goals and objectives of information security strategy according to organisational needs
- 2.2 Design secure network infrastructure and security strategy according to organisational needs
- 2.3 Analyse data classifications and levels of access in operational processes and integrate with strategy
- 2.4 Document designed information security strategy according to organisational procedures
- 2.5 Implement information security strategy according to design and organisational needs
3. Test and finalise information security strategy
- 3.1 Establish security baselines and metrics according to organisational needs
- 3.2 Perform testing procedures and confirm information security strategy addresses organisational needs
- 3.3 Record and compare test results to established metrics and benchmarks
- 3.4 Finalise documentation and report information security strategy outcomes to required personnel
- 3.5 Obtain feedback from required personnel and amend information security strategy accordingly
- 3.6 Review final information security strategy and obtain sign-off from required personnel
No information
No information
No information
| State Code | National Code | Title | Type |
|---|---|---|---|
| AE196 | ICTSS00101 | Cyber Incident Response Skill Set | Skill set |
| BFF9 | ICT40120 | Certificate IV in Information Technology | Qualification |