NTISthis.com

Evidence Guide: BSBXCS405 - Contribute to cyber security incident responses

Student: __________________________________________________

Signature: _________________________________________________

Tips for gathering evidence to demonstrate your skills

The important thing to remember when gathering evidence is that the more evidence the better - that is, the more evidence you gather to demonstrate your skills, the more confident an assessor can be that you have learned the skills not just at one point in time, but are continuing to apply and develop those skills (as opposed to just learning for the test!). Furthermore, one piece of evidence that you collect will not usualy demonstrate all the required criteria for a unit of competency, whereas multiple overlapping pieces of evidence will usually do the trick!

From the Wiki University

 

BSBXCS405 - Contribute to cyber security incident responses

What evidence can you provide to prove your understanding of each of the following citeria?

Confirm cyber security incident and contribute to its containment

  1. Confirm nature and location of cyber security incident according to organisational policies and procedures
  2. Estimate risk, likelihood and potential consequence of incident according to organisational response procedures
  3. Assist in ensuring that cyber incident is contained according to legislative requirements and organisational cyber security incident response plan
  4. Assist in confirming no further risks according to legislative requirements and organisational response procedures
Confirm nature and location of cyber security incident according to organisational policies and procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Estimate risk, likelihood and potential consequence of incident according to organisational response procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assist in ensuring that cyber incident is contained according to legislative requirements and organisational cyber security incident response plan

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assist in confirming no further risks according to legislative requirements and organisational response procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Communicate information on cyber security incident

  1. Escalate cyber security incident with required workplace personnel according to organisational policies and procedures
  2. Consult with required internal and external stakeholders on communication needs relating to cyber security incident
  3. Assist in alerting required external parties according to legislative requirements and organisational procedures
Escalate cyber security incident with required workplace personnel according to organisational policies and procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Consult with required internal and external stakeholders on communication needs relating to cyber security incident

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assist in alerting required external parties according to legislative requirements and organisational procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Contribute to post-incident activities

  1. Support post-breach review and reporting
  2. Assist in identifying lessons learnt from incident response and recommended changes to cyber security response plan
  3. Assist in updating cyber security response plan to reflect review outcomes according to organisational policies and procedures
  4. Communicate lessons learnt and recommendations to required personnel
Support post-breach review and reporting

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assist in identifying lessons learnt from incident response and recommended changes to cyber security response plan

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assist in updating cyber security response plan to reflect review outcomes according to organisational policies and procedures

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Communicate lessons learnt and recommendations to required personnel

Completed
Date:

Teacher:
Evidence:

 

 

 

 

 

 

 

Assessed

Teacher: ___________________________________ Date: _________

Signature: ________________________________________________

Comments:

 

 

 

 

 

 

 

 

Instructions to Assessors

Required Skills and Knowledge

The candidate must demonstrate the ability to complete the tasks outlined in the elements, performance criteria and foundation skills of this unit, including evidence of the ability to assist in:

responding to two different cyber security incidents in a work area

conducting one post-breach review.

The candidate must be able to demonstrate knowledge to complete the tasks outlined in the elements, performance criteria and foundation skills of this unit, including knowledge of:

legislative requirements relating to contributing to cyber security incident responses, including:

data protection

implications of notifiable data breach legislation on an organisation and other associated Australian privacy laws

established international legislation

procedures for developing communications plans

organisational policies and procedures relating to cyber security incident response, including procedures for:

confirming nature and location of incidents

determining risk, likelihood, and consequence of incidents

containing incidents

notifying internal and external stakeholders of incident

internal and external communications

conducting post-breach reviews

reporting methods for cyber security incidents, including official government channels

key features of cyber security incident response plan

risk mitigation strategies and procedures relating to cyber security

internal and external stakeholders involved in responding to cyber security incidents.