Unit of competency Outline

Date retreived
22/07/2026 1:20 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Analyse cyber security insider risks and threats and devise recommendations

Analyse cyber security insider risks and threats and devise recommendations

Unit of competency
National Code
ICTCYS614
State Code
ODC07
TGA Status
Current
DTWD Status
Approved
Current Release Number
1.00
Current Release Date
09/04/2021
State Implementation and Classification
Approved Date
18/06/2021
Field of Education
029901 - Security Science
Original Release Date
18/06/2021
Nominal Hours
70
Description
This unit describes the skills and knowledge required to analyse intentional and unintentional cyber security insider risks and threats, devise recommendations to minimise those risks and threats, and recommend organisational training responses to them.The unit applies to those who work in information technology security roles, including cyber security analysts and specialists, cyber risk and assurance managers, and other related roles that are responsible for analysing cyber security insider risks and threats.No licensing, legislative or certification requirements apply to this unit at the time of publication.
Notes
Elements and Performance Criteria
1. Determine cyber security insider risks and threats in organisation or workplace context
  • 1.1 Obtain work details and scope from required personnel and arrange for access to required technology in compliance with organisational security arrangements and required legislation, codes, regulations and standards
  • 1.2 Evaluate and apply privacy requirements according to organisational policies and procedures
  • 1.3 Identify systems of critical nature to business and key data logs for detection of cyber security insider risk and threat activity
  • 1.4 Determine high-risk data using organisational risk framework
  • 1.5 Monitor organisational behaviour patterns to identify cyber security insider risks and threats
2. Complete model-based analysis of cyber security insider risks and threats
  • 2.1 Identify model required to analyse cyber security insider risks and threats
  • 2.2 Analyse sensors and data logs and perform risk assessment to identify high-risk users and behaviours
  • 2.3 Perform a model-based analysis of cyber security insider risks and threats
3. Devise and distribute recommendations arising from analysis
  • 3.1 Prioritise risks and threats based on analysis according to organisational policies and procedures
  • 3.2 Develop recommendations to minimise or eliminate insider risks and threats based on analysis findings
  • 3.3 Seek and integrate feedback of required personnel on draft recommendations
  • 3.4 Distribute information and documentation to required personnel according to legislative requirements and organisational policies and procedures
4. Review organisational training response to cyber security insider risks and threats
  • 4.1 Review identified cyber security insider risks and threats to identify training requirements
  • 4.2 Develop recommendations for training to address cyber security insider risks and threats
  • 4.3 Seek feedback on training recommendations from required personnel
  • 4.4 Finalise and distribute training recommendations according to organisational policies and procedures
No information
No information
No information