Module Outline
Date retreived
23/07/2026 6:42 AM AWST
23/07/2026 6:42 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Design security architecture for an organisation
Design security architecture for an organisation
Module
National Code
VU23306
VU23306
State Code
AZ611
AZ611
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to utilise tools and methodologies to design the security architecture for an organisation that addresses it’s business requirements, IT applications and end user expectations.
It requires the ability to implement a process for reviewing the existing security architecture, conduct of a security design audit and recommend improvements.
The unit applies to cyber security practitioners responsible for an organisation’s security infrastructure.
No licensing or certification requirements apply to this unit at the time of accreditation.
It requires the ability to implement a process for reviewing the existing security architecture, conduct of a security design audit and recommend improvements.
The unit applies to cyber security practitioners responsible for an organisation’s security infrastructure.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Evaluate current security architecture frameworks and methodologies
- Existing security architecture frameworks and methodologies are identified and evaluated
- In consultation with appropriate personnel the outcomes of the standards and frameworks evaluation are examined for suitability and implementation
- Business goals and objectives are identified and translated to security goals and objectives
Collate network security design documentation
- Existing network security logical architecture is reviewed and updated as required
- Existing network security physical architecture is reviewed and updated as required
Conduct a security assessment on the security devices and components
- Network trust security assessment to reflect zero trust network architectures as the benchmark for secure networks is conducted
- Existing security infrastructure diagram for the organisation is sourced
- Template for security assessments including business impact is developed or sourced
- Risk and threat modelling for the organisation is developed
- Security metrics covering control objectives, warning thresholds and control thresholds is developed
Collate and review security policies for the organisation
- Current security policy documents for the organisation are collated
- In consultation with appropriate personnel, security policies are reviewed and updated where appropriate
- Change management process strategies to improve cyber security working practices within the organisation are developed
Evaluate methodologies for security architecture
- In consultation with appropriate personnel a layered model of security architecture is evaluated and selected
- Issues around implementing a layered model of security architecture are prioritised
- Different types of security technical designs are defined
- Key development principles of a sound security architecture are investigated
- Process to address special security architecture challenges are investigated
Determine existing security architecture vulnerabilities
- Models and methodologies to identify security architecture vulnerabilities are collated, evaluated and selected
- An audit to detect vulnerabilities for the security architecture is performed
- In consultation with appropriate personnel, strategies to mitigate detected security architecture vulnerabilities are developed and deployed
Communicate design options for security architecture to the organisation
- Engaging strategies for different stakeholder groups are developed
- Communication strategies for different stakeholder groups are developed
- Reports to different stakeholder groups are written and presented utilising developed strategies
- Tools to develop security architecture documentation are selected and sourced
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AX665 | VU22259 | Utilise design methodologies for security architecture | Unit of competency |
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |