NTISthis.com

Evidence Guide: BSBRKG604 - Determine security and access rules and procedures

Student: __________________________________________________

Signature: _________________________________________________

Tips for gathering evidence to demonstrate your skills

The important thing to remember when gathering evidence is that the more evidence the better - that is, the more evidence you gather to demonstrate your skills, the more confident an assessor can be that you have learned the skills not just at one point in time, but are continuing to apply and develop those skills (as opposed to just learning for the test!). Furthermore, one piece of evidence that you collect will not usualy demonstrate all the required criteria for a unit of competency, whereas multiple overlapping pieces of evidence will usually do the trick!

From the Wiki University

 

BSBRKG604 - Determine security and access rules and procedures

What evidence can you provide to prove your understanding of each of the following citeria?

Analyse access risks, rules and responsibilities

  1. Establish, analyse and describe the impact of the legal and regulatory framework on access to records for the unit or the entire organisation
  2. Analyse organisational documentation and information, copies of appraisal reports and access conditions for records of comparable organisations
  3. Review risk analyses and existing access rules for currency, and determine and document any necessary modifications
  4. Analyse usage patterns of records taking into account identified risks and existing access rules
  5. Determine specific restrictions and other responses to regulatory obligations for records and activities
  6. Determine responsibility for reviewing access decisions from collected organisational documentation and information
Establish, analyse and describe the impact of the legal and regulatory framework on access to records for the unit or the entire organisation

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Analyse organisational documentation and information, copies of appraisal reports and access conditions for records of comparable organisations

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Review risk analyses and existing access rules for currency, and determine and document any necessary modifications

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Analyse usage patterns of records taking into account identified risks and existing access rules

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Determine specific restrictions and other responses to regulatory obligations for records and activities

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Determine responsibility for reviewing access decisions from collected organisational documentation and information

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Develop access strategy, classifications and rules

  1. Consider factors impacting on access rights in developing an access strategy from collected information, based on established responsibilities for access to records, and in response to identified difficulties and risks
  2. Determine broad access classifications and reasons for access restrictions from regulatory requirements, identified risks and usage patterns of records within the jurisdiction
  3. Compile criteria for applying access classifications to records, based on collected information and performed analyses
  4. Develop rules for applying classifications
  5. Circulate access classifications and draft rules to users of the business or records system for comment, identifying and analysing exceptions, and modifying classifications where appropriate
  6. Determine compliance regime and jurisdictional access regime
  7. Seek authorisation from appropriate body for access classifications and procedures
Consider factors impacting on access rights in developing an access strategy from collected information, based on established responsibilities for access to records, and in response to identified difficulties and risks

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Determine broad access classifications and reasons for access restrictions from regulatory requirements, identified risks and usage patterns of records within the jurisdiction

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Compile criteria for applying access classifications to records, based on collected information and performed analyses

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Develop rules for applying classifications

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Circulate access classifications and draft rules to users of the business or records system for comment, identifying and analysing exceptions, and modifying classifications where appropriate

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Determine compliance regime and jurisdictional access regime

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Seek authorisation from appropriate body for access classifications and procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Develop procedures to integrate into business or records system

  1. Determine access permissions and restrictions for records by applying access rules
  2. Establish and document categories of users using analyses of access rules and records usage
  3. Document access permissions and restrictions in relation to categories of users
  4. Establish mechanisms to control user access applying to records and to users
  5. Develop and document specifications for recording authorised use of records
  6. Integrate authorised access procedures into business or records system rules and procedures, and document changes
Determine access permissions and restrictions for records by applying access rules

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Establish and document categories of users using analyses of access rules and records usage

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Document access permissions and restrictions in relation to categories of users

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Establish mechanisms to control user access applying to records and to users

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Develop and document specifications for recording authorised use of records

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Integrate authorised access procedures into business or records system rules and procedures, and document changes

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Review and amend access classifications and rules

  1. Develop procedures for reviewing access decisions and for responding to exceptions
  2. Identify a hierarchy of responsibility for reviewing access decisions to comply with jurisdictional access regime
  3. Communicate changes to access rules and procedures to all users
Develop procedures for reviewing access decisions and for responding to exceptions

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Identify a hierarchy of responsibility for reviewing access decisions to comply with jurisdictional access regime

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Communicate changes to access rules and procedures to all users

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assessed

Teacher: ___________________________________ Date: _________

Signature: ________________________________________________

Comments:

 

 

 

 

 

 

 

 

Instructions to Assessors

Evidence Guide

ELEMENT

PERFORMANCE CRITERIA

Elements describe the essential outcomes.

Performance criteria describe the performance needed to demonstrate achievement of the element.

1. Analyse access risks, rules and responsibilities

1.1 Establish, analyse and describe the impact of the legal and regulatory framework on access to records for the unit or the entire organisation

1.2 Analyse organisational documentation and information, copies of appraisal reports and access conditions for records of comparable organisations

1.3 Review risk analyses and existing access rules for currency, and determine and document any necessary modifications

1.4 Analyse usage patterns of records taking into account identified risks and existing access rules

1.5 Determine specific restrictions and other responses to regulatory obligations for records and activities

1.6 Determine responsibility for reviewing access decisions from collected organisational documentation and information

2. Develop access strategy, classifications and rules

2.1 Consider factors impacting on access rights in developing an access strategy from collected information, based on established responsibilities for access to records, and in response to identified difficulties and risks

2.2 Determine broad access classifications and reasons for access restrictions from regulatory requirements, identified risks and usage patterns of records within the jurisdiction

2.3 Compile criteria for applying access classifications to records, based on collected information and performed analyses

2.4 Develop rules for applying classifications

2.5 Circulate access classifications and draft rules to users of the business or records system for comment, identifying and analysing exceptions, and modifying classifications where appropriate

2.6 Determine compliance regime and jurisdictional access regime

2.7 Seek authorisation from appropriate body for access classifications and procedures

3. Develop procedures to integrate into business or records system

3.1 Determine access permissions and restrictions for records by applying access rules

3.2 Establish and document categories of users using analyses of access rules and records usage

3.3 Document access permissions and restrictions in relation to categories of users

3.4 Establish mechanisms to control user access applying to records and to users

3.5 Develop and document specifications for recording authorised use of records

3.6 Integrate authorised access procedures into business or records system rules and procedures, and document changes

4. Review and amend access classifications and rules

4.1 Develop procedures for reviewing access decisions and for responding to exceptions

4.2 Identify a hierarchy of responsibility for reviewing access decisions to comply with jurisdictional access regime

4.3 Communicate changes to access rules and procedures to all users

Required Skills and Knowledge

ELEMENT

PERFORMANCE CRITERIA

Elements describe the essential outcomes.

Performance criteria describe the performance needed to demonstrate achievement of the element.

1. Analyse access risks, rules and responsibilities

1.1 Establish, analyse and describe the impact of the legal and regulatory framework on access to records for the unit or the entire organisation

1.2 Analyse organisational documentation and information, copies of appraisal reports and access conditions for records of comparable organisations

1.3 Review risk analyses and existing access rules for currency, and determine and document any necessary modifications

1.4 Analyse usage patterns of records taking into account identified risks and existing access rules

1.5 Determine specific restrictions and other responses to regulatory obligations for records and activities

1.6 Determine responsibility for reviewing access decisions from collected organisational documentation and information

2. Develop access strategy, classifications and rules

2.1 Consider factors impacting on access rights in developing an access strategy from collected information, based on established responsibilities for access to records, and in response to identified difficulties and risks

2.2 Determine broad access classifications and reasons for access restrictions from regulatory requirements, identified risks and usage patterns of records within the jurisdiction

2.3 Compile criteria for applying access classifications to records, based on collected information and performed analyses

2.4 Develop rules for applying classifications

2.5 Circulate access classifications and draft rules to users of the business or records system for comment, identifying and analysing exceptions, and modifying classifications where appropriate

2.6 Determine compliance regime and jurisdictional access regime

2.7 Seek authorisation from appropriate body for access classifications and procedures

3. Develop procedures to integrate into business or records system

3.1 Determine access permissions and restrictions for records by applying access rules

3.2 Establish and document categories of users using analyses of access rules and records usage

3.3 Document access permissions and restrictions in relation to categories of users

3.4 Establish mechanisms to control user access applying to records and to users

3.5 Develop and document specifications for recording authorised use of records

3.6 Integrate authorised access procedures into business or records system rules and procedures, and document changes

4. Review and amend access classifications and rules

4.1 Develop procedures for reviewing access decisions and for responding to exceptions

4.2 Identify a hierarchy of responsibility for reviewing access decisions to comply with jurisdictional access regime

4.3 Communicate changes to access rules and procedures to all users