Unit of competency Outline
Date retreived
22/07/2026 7:10 AM AWST
22/07/2026 7:10 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Manage security, privacy and compliance of cloud service deployment
Manage security, privacy and compliance of cloud service deployment
Unit of competency
National Code
ICANWK616A
ICANWK616A
State Code
WG950
WG950
TGA Status
Replaced
Replaced
DTWD Status
Replaced
Replaced
State Implementation and Classification
Approved Date
09/12/2013
Field of Education
029901 - Security Science
Original Release Date
09/12/2013
Nominal Hours
35
Description
This unit describes the performance outcomes, skills and knowledge required to manage cloud security controls, and privacy and legal compliance when implementing cloud services for an enterprise.
Notes
Elements and Performance Criteria
1. Manage enterprise cloud security controls
- 1.1. Identify cloud security issues faced by different delivery and deployment models relevant to enterprise
- 1.2. Determine specific enterprise areas of security responsibility
- 1.3. Implement most relevant security controls and measures to protect identified areas of responsibility
2. Manage enterprise cloud privacy and compliance
- 2.1. Identify relevant compliance regulations relating to data storage
- 2.2. Determine most relevant business continuity and data recovery plans
- 2.3. Identify, secure and maintain relevant logs and audit trails
- 2.4. Investigate and review legal, privacy and contractual issues to ensure they meet enterprise policy
3. Review, implement and document cloud security, privacy and compliance enhancements
- 3.1. Implement appropriate changes and integrate into current enterprise’s continuity of operation program (COOP)
- 3.2. Establish a performance measurement program to evaluate security effectiveness of implemented security controls
- 3.3. Provide relevant documentation as part of COOP for audit tracking purposes
The range statement relates to the unit of competency as a whole. It allows for different work environments and situations that may affect performance. Bold italicised wording, if used in the performance criteria, is detailed below. Essential operating conditions that may be present with training and assessment (depending on the work situation, needs of the candidate, accessibility of the item, and local industry and regional contexts) may also be included.
Security issues may include:
applications security
data security
enterprise continuity
infrastructure security
platform security
virtualisation security.
Delivery models may include:
infrastructure as a service (IaaS)
platform as a service (PaaS)
software as a service (SaaS).
Deployment models may include:
community cloud
hybrid cloud
private cloud
public cloud.
Security responsibility may include:
clients:
applications (if not part of licence)
client employee access
data (if not part of licence)
physical client site security
enterprise (depending on licensing agreement):
application
data
identity management systems
infrastructure
physical enterprise site security
platform.
Security controls and measures may include:
security management, including:
corrective controls
detective controls
deterrent controls
preventative controls.
Compliance regulations may include:
international regulations
internet or web regulations
local regulations
regional regulations.
Business continuity may include:
undertaking analysis of:
business impact analysis
threat and risk analysis
impact scenarios
solution design
developing solution implementation strategies
testing and enterprise acceptance
implementing suitable maintenance options.
Data recovery may include:
logical damage recovery:
corrupt partitions
overwritten data
physical damage recovery
virus infections.
Legal, privacy and contractual issues may include:
critical data masked
digital identities protected
end-of-service: return of data and applications
intellectual property: ownership of data
liability of data loss
unauthorised on-selling of information.
Continuity of operations program may include:
COOP plan execution
COOP plan revision and updating
COOP program implementation
identification of functional requirements:
mission impact analysis
mitigation strategies and plan
plan design and development
project initiation
risk assessment
training, testing and drills.
Documentation may include:
applicable network-based documents
audits and management reviews
communications protocols
contingency plans and activities
evaluation reports
incident management program, processes and procedures
management reports
network security and telecommunications program
performance measurement program
reviews and improvements records
security classification and data management policies
security incident records.
Security issues may include:
applications security
data security
enterprise continuity
infrastructure security
platform security
virtualisation security.
Delivery models may include:
infrastructure as a service (IaaS)
platform as a service (PaaS)
software as a service (SaaS).
Deployment models may include:
community cloud
hybrid cloud
private cloud
public cloud.
Security responsibility may include:
clients:
applications (if not part of licence)
client employee access
data (if not part of licence)
physical client site security
enterprise (depending on licensing agreement):
application
data
identity management systems
infrastructure
physical enterprise site security
platform.
Security controls and measures may include:
security management, including:
corrective controls
detective controls
deterrent controls
preventative controls.
Compliance regulations may include:
international regulations
internet or web regulations
local regulations
regional regulations.
Business continuity may include:
undertaking analysis of:
business impact analysis
threat and risk analysis
impact scenarios
solution design
developing solution implementation strategies
testing and enterprise acceptance
implementing suitable maintenance options.
Data recovery may include:
logical damage recovery:
corrupt partitions
overwritten data
physical damage recovery
virus infections.
Legal, privacy and contractual issues may include:
critical data masked
digital identities protected
end-of-service: return of data and applications
intellectual property: ownership of data
liability of data loss
unauthorised on-selling of information.
Continuity of operations program may include:
COOP plan execution
COOP plan revision and updating
COOP program implementation
identification of functional requirements:
mission impact analysis
mitigation strategies and plan
plan design and development
project initiation
risk assessment
training, testing and drills.
Documentation may include:
applicable network-based documents
audits and management reviews
communications protocols
contingency plans and activities
evaluation reports
incident management program, processes and procedures
management reports
network security and telecommunications program
performance measurement program
reviews and improvements records
security classification and data management policies
security incident records.
The evidence guide provides advice on assessment and must be read in conjunction with the performance criteria, required skills and knowledge, range statement and the Assessment Guidelines for the Training Package.
Overview of assessment
Critical aspects for assessment and evidence required to demonstrate competency in this unit
Evidence of the ability to:
identify, manage and implement cloud security controls according to legal and privacy requirements
integrate cloud security plans into the enterprise’s existing security plans
develop an ongoing performance measurement and evaluation review process.
Context of and specific resources for assessment
Assessment must ensure access to:
cloud information and communications technology (ICT) business specifications
cloud ICT security assurance specifications
management-related scenarios
a cloud focused security environment, including the threats to security that are, or are held to be, present in the environment
information on the security environment, including:
laws or legislation
existing enterprise security policies
enterprise expertise
risk analysis tools and methodologies currently used in industry
appropriate learning and assessment support when required
modified equipment for people with special needs.
Method of assessment
A range of assessment methods should be used to assess practical skills and knowledge. The following examples are appropriate for this unit:
direct observation of candidate managing cloud-related networks and telecommunications security
direct observation of candidate managing cloud ICT security incidents
verbal or written questioning to assess candidate’s knowledge of enterprise policies and procedures that impact on cloud ICT security
review of documentation prepared by candidate, including programs to manage compliance, privacy and risk.
Guidance information for assessment
Holistic assessment with other units relevant to the industry sector, workplace and job role is recommended, where appropriate.
Assessment processes and techniques must be culturally appropriate, and suitable to the communication skill level, language, literacy and numeracy capacity of the candidate and the work being performed.
Indigenous people and other people from a non-English speaking background may need additional support.
In cases where practical assessment is used it should be combined with targeted questioning to assess required knowledge.
Overview of assessment
Critical aspects for assessment and evidence required to demonstrate competency in this unit
Evidence of the ability to:
identify, manage and implement cloud security controls according to legal and privacy requirements
integrate cloud security plans into the enterprise’s existing security plans
develop an ongoing performance measurement and evaluation review process.
Context of and specific resources for assessment
Assessment must ensure access to:
cloud information and communications technology (ICT) business specifications
cloud ICT security assurance specifications
management-related scenarios
a cloud focused security environment, including the threats to security that are, or are held to be, present in the environment
information on the security environment, including:
laws or legislation
existing enterprise security policies
enterprise expertise
risk analysis tools and methodologies currently used in industry
appropriate learning and assessment support when required
modified equipment for people with special needs.
Method of assessment
A range of assessment methods should be used to assess practical skills and knowledge. The following examples are appropriate for this unit:
direct observation of candidate managing cloud-related networks and telecommunications security
direct observation of candidate managing cloud ICT security incidents
verbal or written questioning to assess candidate’s knowledge of enterprise policies and procedures that impact on cloud ICT security
review of documentation prepared by candidate, including programs to manage compliance, privacy and risk.
Guidance information for assessment
Holistic assessment with other units relevant to the industry sector, workplace and job role is recommended, where appropriate.
Assessment processes and techniques must be culturally appropriate, and suitable to the communication skill level, language, literacy and numeracy capacity of the candidate and the work being performed.
Indigenous people and other people from a non-English speaking background may need additional support.
In cases where practical assessment is used it should be combined with targeted questioning to assess required knowledge.
Replaced By
| State Code | National Code | Title | Type |
|---|---|---|---|
| AUX08 | ICTNWK616 | Manage security, privacy and compliance of cloud service deployment | Unit of competency |
| State Code | National Code | Title | Type |
|---|---|---|---|
| D580 | ICA60511 | Advanced Diploma of Computer Systems Technology | Qualification |
| D576 | ICA60111 | Advanced Diploma of Information Technology | Qualification |
| D577 | ICA60211 | Advanced Diploma of Network Security | Qualification |