Module Outline
Date retreived
23/07/2026 5:19 AM AWST
23/07/2026 5:19 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Manage penetration testing processes for an organisation
Manage penetration testing processes for an organisation
Module
National Code
VU23301
VU23301
State Code
AZ593
AZ593
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to manage the Vulnerability and Penetration Testing (VPEN) for an organisation.
It requires the ability to compile information on the existing information technology (IT) and security infrastructure design, evaluate and select testing tools and establish a vulnerability baseline.
The unit applies to cyber security practitioners who are required to test an organisations’ security infrastructure for vulnerabilities.
No licensing or certification requirements apply to this unit at the time of accreditation.
It requires the ability to compile information on the existing information technology (IT) and security infrastructure design, evaluate and select testing tools and establish a vulnerability baseline.
The unit applies to cyber security practitioners who are required to test an organisations’ security infrastructure for vulnerabilities.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Compile information on the organisation’s technology
- Information regarding the organisation’s IT security infrastructure, web systems, cloud services and security infrastructure is sourced
- Information on the function and operation on each item of the IT infrastructure, web systems, cloud services and security infrastructure is collated
- Design of the IT infrastructure, web systems, cloud services, and security infrastructure is evaluated
- Secure Development Lifecycle (SDLC) and the importance of integrating it with security during all phases of development is established
Evaluate and select tools to test the security infrastructure
- Tools used to perform Vulnerability and Penetration (VPEN) testing on the organisation’s IT infrastructure, web systems and cloud services are sourced and evaluated
- Tools to perform VPEN testing are selected
- Testing environment is setup and configured
- Web site testing frameworks are evaluated and selected
- Vulnerabilities within a testing environment are identified
Develop penetration testing skills
- Familiarity with the function and configuration of the VPEN testing tools is developed
- Skills in using the VPEN testing tools for detecting vulnerabilities in security infrastructure are developed
- Familiarity with sources of information for vulnerabilities, threat intelligence and exploits is developed
- Differences between infrastructure vulnerability scanning, web vulnerability scanning, cloud security assessment, and penetration testing are articulated
- Familiarity with identifying and using sources of threat intelligence and exploit information is developed
Identify tools to establish a vulnerability baseline
- Locations and devices where vulnerability information comes from within the organisation are identified and documented
- Tools to determine the vulnerability baseline within the organisation are identified and documented
- Regular procedures and processes for VPEN testing for the organisation are proposed
Research new security technology developments
- Current developments in cyber security infrastructure testing developments are sourced and reviewed
- New tools for VPEN testing are researched
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AX659 | VU22253 | Undertake penetration testing of the security infrastructure for an organisation | Unit of competency |
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |