Implement security risk management plan

Formats and tools

Unit Description
Reconstruct the unit from the xml and display it as an HTML page.
Assessment Tool
an assessor resource that builds a framework for writing an assessment tool
Assessment Template
generate a spreadsheet for marking this unit in a classroom environment. Put student names in the top row and check them off as they demonstrate competenece for each of the unit's elements and performance criteria.
Assessment Matrix
a slightly different format than the assessment template. A spreadsheet with unit names, elements and performance criteria in separate columns. Put assessment names in column headings to track which performance criteria each one covers. Good for ensuring that you've covered every one of the performance criteria with your assessment instrument (all assessement tools together).
Wiki Markup
mark up the unit in a wiki markup codes, ready to copy and paste into a wiki page. The output will work in most wikis but is designed to work particularly well as a Wikiversity learning project.
Evidence Guide
create an evidence guide for workplace assessment and RPL applicants
Competency Mapping Template
Unit of Competency Mapping – Information for Teachers/Assessors – Information for Learners. A template for developing assessments for a unit, which will help you to create valid, fair and reliable assessments for the unit, ready to give to trainers and students
Observation Checklist
create an observation checklist for workplace assessment and RPL applicants. This is similar to the evidence guide above, but a little shorter and friendlier on your printer. You will also need to create a seperate Assessor Marking Guide for guidelines on gathering evidence and a list of key points for each activity observed using the unit's range statement, required skills and evidence required (see the unit's html page for details)

Self Assessment Survey
A form for students to assess thier current skill levels against each of the unit's performance criteria. Cut and paste into a web document or print and distribute in hard copy.
Moodle Outcomes
Create a csv file of the unit's performance criteria to import into a moodle course as outcomes, ready to associate with each of your assignments. Here's a quick 'how to' for importing these into moodle 2.x
Registered Training Organisations
Trying to find someone to train or assess you? This link lists all the RTOs that are currently registered to deliver CPPSEC5005A, 'Implement security risk management plan'.
Google Links
links to google searches, with filtering in place to maximise the usefulness of the returned results
Books
Reference books for 'Implement security risk management plan' on fishpond.com.au. This online store has a huge range of books, pretty reasonable prices, free delivery in Australia *and* they give a small commission to ntisthis.com for every purchase, so go nuts :)


Elements and Performance Criteria

ELEMENT

PERFORMANCE CRITERIA

1Organise functions and tasks.

1.1 Applicable provisions of legislative and organisational requirements, and relevant standards for risk assessment activities are identified and complied with.

1.2 Roles and responsibilities associated with the implementation of the security risk management plan are clearly defined and articulated to relevant persons.

1.3 Activities and targets are linked to achievement of milestones and outcomes in project action plans.

1.4 Resources, equipment and materials to assist plan implementation are suitable to project purposes and available within specified timelines.

1.5 Information related to the implementation of the plan is accurately and promptly distributed using established communication channels.

1.6 Confidentiality requirements are confirmed and maintained in accordance with client and organisational requirements.

2Monitor risk context.

2.1 Emerging risks or threats to assets are monitored and assessed to maintain ongoing suitability of implemented security risk treatment options.

2.2 Changes to operating environment are monitored and corrective measures determined and incorporated into the plan as required.

2.3 Targets and outcomes are regularly reviewed and evaluated to ensure achievement of project aims based on relevant standards.

2.4 Existence and occurrence of risks are accurately and comprehensively documented providing an assessment of the type, nature and cause.

2.5 Application of contingencies and corrective measures are accurately documented.

3Review effectiveness of treatment options.

3.1 Long and short-term options are costed to ensure an accurate estimate of resources is allocated to support the plans.

3.2 Discrepancies between treatment options and risk incidence are monitored and addressed through appropriate modifications to plans.

3.3 Stages of implementation are identified and resources and options are coordinated to ensure access and availability.

3.4 Corrective measures are developed, tested and incorporated into the risk management plan.

3.5 Feedback on effectiveness of treatment options is sought and provided to relevant personnel.


Qualifications and Skillsets

CPPSEC5005A appears in the following qualifications:

  • CPP50611 - Diploma of Security and Risk Management
  • ICA60211 - Advanced Diploma of Network Security
  • ICT60215 - Advanced Diploma of Network Security