workplace cyber security awareness
Assessment Manual
BSBXCS402 Promote workplace cyber security awareness and best practices
Objective of assessments
We are committed to your learning by providing a training and assessment framework that ensures the knowledge gained through training is translated into practice in your work in the workplace with consistent and competent work performance. The purpose of the assessment process is to assess your ability:
to apply skills and knowledge using written and demonstration activities that apply to tasks and activities of a workplace.
to translate your learning into your work performance in a workplace through demonstration.
to apply skills and knowledge actively, correctly, and consistently for work in a workplace.
Assessment process
The assessment process is known as competency-based assessment. This means that evidence of your current skills and knowledge will be measured against national standards, not against the learning you have undertaken either recently or in the past. Some of the assessment will be concerned with how you apply your skills and knowledge in a workplace, and some in the training room as required by each unit. The assessment tasks have been designed to enable you to demonstrate skills and knowledge application and produce the critical evidence to successfully demonstrate competency at the required standard.
Your assessor will ensure that you are ready for assessment and will explain the assessment process. Your assessment tasks will outline the evidence to be collected and how it will be collected, for example, a written activity, case study, or demonstration and observation. The assessor will also have determined if you have any special needs to be considered during assessment. Changes can be made to the way assessment is undertaken to account for special needs and this is called making Reasonable Adjustment provided to you in the assessment guide separately.
|
Assessment Task |
Assessment Method |
Evidence Gathering Techniques (Document and methods used to assess you) |
Where? (Assessment location) |
When? (Due date) |
|
Assessment Task 1 |
Written Task (Questioning) |
Written answers of consistent application of knowledge |
Training Room |
Refer to timetable |
|
Assessment Task 2 |
Case study |
Written Solutions Observation of your consistent application of skills and knowledge in performance and demonstration |
Training Room (Simulated workplace environment) |
Refer to timetable |
|
Assessment Task 3 |
Project |
Written Solutions Observation of your consistent application of skills and knowledge in performance and demonstration |
Training Room (Simulated workplace environment) |
Refer to timetable |
Assessment guide
Your assessment guide that is provided to you will explain the following. Please refer to assessment guide for the following information before commencing your written work and demonstration:
Your responsibilities during the assessment.
Assessor responsibilities during the conduct of assessment.
Your rights to appeal if the assessment outcome appears as “Not Yet Competent” for one or more assessment tasks.
The process to apply if you already possess the knowledge and skills to be able to demonstrate competence in this unit.
The formats and structure of the written assessment work for submission.
The length, breath and the quantity of your written work, plagiarism, collusion, cheating and how to use references for sources of information.
How to achieve a satisfactory outcome against the criteria for each type of assessment task.
Application of reasonable adjustments where necessary.
Requirements for demonstration, performance for practical assessment tasks and activities.
Your assessment performance with commitment, consistency, clarity, capacity, capability, correctness, and completeness.
Instructions
Each assessment task provides you with assessment information that includes answers to what, why, how, when, in what condition, what materials, resources and equipment to use and evidence requirements.
Read the applicable information and if unsure seek clarification from your assessor.
Before and during assessment demonstration and interacting with others, ensure you follow simulated workplace policies and procedures.
Ensure you follow hygiene procedures, social distancing rules and ethics before, during and after assessment tasks and activities.
Undertake your preparation activities and demonstration activities as specified and directed by your assessor.
In any situation during the assessment, if you find that you are unable to perform due to any condition (health or safety), stop your work and inform the assessor of the condition.
Ensure you are obligated with your rights as a candidate and respects the rights of your assessor during the assessment performance.
For interactive and role-play activities, organise role-play settings and individuals for role-play in collaboration with assessor and training mates.
Submit your written work when it becomes due and avoid the requirements of extensions.
Use provided self-assessment checklists by checking as you progress in assessment to ensure you do not miss anything that may lead to unsatisfactory outcomes.
Submission specifications
Fill your submission details in the front page and attach any additional documents and any other evidence as specified and required by your assessor.
Follow the institution submission requirements of assessment. I.e., electronic submission (LMS) or hard copy submission or as specified by your assessor for differing assessment situations.
ASSESSMENT GUIDELINES FOR WRITTEN TASK
|
QUESTION TYPE |
HOW LONG YOUR ANSWER MUST BE (LENGTH OF ANSWER) |
|
Define |
Length approximately 4 typed lines = 50 words, or 5 lines of handwritten text for each question. |
|
Identify |
Write dot points of the number of items to identify according to the question. |
|
Outline |
Summarise in a line or set of lines the required number of items or develop appropriate meaningful answers according to the question but not in detail. |
|
Identify and briefly describe |
Identify in dot points and provide a description of each with a minimum of 4 typed lines = 50 words, or 5 lines of handwritten text for each question. |
|
Describe |
Provide a description with minimum 8 typed lines = 100 – 150 words, or 10 – 15 lines of handwritten text or appropriately described to provide a meaningful answer with consistent knowledge application in length according to the question. |
|
Explain |
Explain the procedure with minimum 8 typed lines = 100 – 150 words, or 10 – 15 lines of handwritten text or appropriately explain to provide a meaningful answer with consistent knowledge application in length according to the question. |
|
Distinguish / differentiate |
Distinguish means recognise or treat (someone or something) as different. To differentiate is to show or find the difference between things which are compared. It simply means that they are not the same but does not qualify them as being unique and possibly not related. Length approximately 4 – 8 typed lines = 50 – 100 words, or 5 – 10 lines of handwritten text for each question. |
|
What |
This is to assess your knowledge of something related to the subject area asking you to specify one or more things related to what is being asked in the question. This is generally asking for a short answer for which you need to provide a short description answering the question where the reader understands the answer to the question. |
|
How |
This method of question is to assess your ability to explain or describe the ways, methods, manner, procedure or process of something related to the question being asked. You need to provide sufficient description of how (ways, methods, manner, procedure or process) it can be performed for the reader to understand the ways or procedure. |
|
Why |
This question is to assess your knowledge of something and the purpose of it. You need to provide sufficient description of why (the purpose/objective or aims) it is used for the reader to understand why. |
ASSESSMENT TASK 1
Written Questioning
You are required to read the following assessment information, requirements, and instructions before commencing. This task is about written questioning for you to provide written answers as evidence of your knowledge application. Ensure you follow the terms and conditions applied in undertaking written task during the assessment as specified and facilitated by your assessor.
|
Assessment Information |
Description |
|
|
1 |
Assessment method |
Written questioning |
|
2 |
Assessment type |
Summative |
|
3 |
Assessment description (What?) |
This assessment task is a written task for which you are required to provide written answer solutions to promote cyber security in a work area. Read the following information related to your assessment to prepare and perform to provide evidence of your knowledge. |
|
4 |
Purpose (objective) of the assessment (Why?) |
To gather evidence of your ability to apply knowledge consistently to promote cyber security in a work area. |
|
5 |
Assessment Instructions (How?) |
Read the theoretical component of the learner workbook. Conduct research and review literature relevant to the unit. Provide answer solutions to each question using your own words. Note: do not just copy past the answers from other materials. You may refer to learning materials and other sources of information as agreed by your assessor. You may word-process your answers using MS Word /Mac document. The assessment is due for completion on the date/s and time/s. specified by your assessor. Any variations to this arrangement must be approved in writing by your assessor. Submit your work with any required evidence attached. See the specifications below for details of submission requirements. Read the following requirements for this assessment completion: |
|
6 |
Assessment date/s and timing/s (When?) |
This assessment will be conducted according to the training delivery session plan. Assessor will specify the timings of assessment and submission of evidence. Time allowed for the assessment is 3 hours within 20 hours of training delivery of week 2. |
|
7 |
Specifications (What structure, format and demonstration)
|
Write answer solutions to all the questions using word-processed documents. Provide specified length and numbers mentioned in each question. Submit the answers with a cover page that includes your name, student ID, unit name/code, date of submission and assessor name. If a separate word-process document is used for your responses, include header (unit name/code) and footer (page no. student name and ID). |
|
8 |
Assessment context (Where and in what condition) |
Assessment is conducted in the training room and safe environment where you are required to provide answer solutions to the questions in a word-processed document with evidence that demonstrates consistent knowledge application. |
|
9 |
Required resources (What resources, equipment, tools and materials) |
Assessment task with instruction and assessment information Learner workbook and other training handouts if or as allowed by your assessor. Computer with Internet access. Word-process software (MS Word/Mac). Workspace, table, chair, and stationery. |
|
10 |
Evidence requirements/ (What assessor is looking for) |
To complete the unit requirements safely and effectively, you must prove application of knowledge consistently relevant to vocational contexts and: Provide answers to all the questions Answers must be with appropriate and sufficient length by following assessment guidelines for written tasks above. Answers must be relevant to the question and its sub parts. Your assessor may verbally assess to confirm your knowledge application in case your answer is not correct or not clear to one or more questions. |
Your Task – Write answers (Knowledge Application)
The following is a set of knowledge-based questions. Read the text section ‘introduction’ in the learner workbook, refer to training undertaken and provide your answer solutions to the following questions using your own words to demonstrate your consistent knowledge application.
Note: Ensure you answer all the following questions using the length guidelines above and quantity requirements applicable in following relevant questions.
Questions
Outline 5 legislative requirements for each, relating to cyber security context of performance evidence, including:
data protection.
implications of Notifiable Data Breach legislation on an organisation and other associated Australian privacy laws.
established international legislation.
Describe the following organisational policies and procedures relating to:
securely storing, sharing and managing information
data classification and management
acceptable use.
Outline the organisational policies and procedures relating to data governance.
Briefly explain the organisational policies and procedures relating to bringing your own device.
Outline the organisational policies and procedures relating to encryption.
Outline the organisational policies and procedures relating to media/document labelling.
List out 5 Australian government sources of information on current threats.
Outline 10 risks that are associated with workplace cyber security.
List 5 techniques for promoting workplace cyber security training that promotes cyber security awareness.
Describe strategies for promoting workplace cyber security techniques for promoting workplace cyber security awareness.
—End of Written Task Activities—
Assessment Task 2 – Case Study
(Includes role-plays)
Develop, support, and review cyber security practices in work area
You are required to read the following assessment information, requirements, and instructions before commencing. This task has simulated workplace reference. Ensure you access the simulated workplace resources (planning documents, policies, and procedures etc.), equipment, applicable legislation, regulation, standards, and code of conduct during the assessment as specified and facilitated by your assessor.
|
Assessment Information |
Description |
|
|
1 |
Assessment Method |
Case study (simulated workplace) |
|
2 |
Assessment Type |
Summative |
|
3 |
Assessment Description (What?) |
This assessment task is a case study for you to consult with stakeholders to Promote workplace cyber security awareness and best practices. You are required to analyse the case scenario and provide written solutions to task activities by demonstrating applicable foundation skills and knowledge. You must also provide performance solutions to specific role-play activities relevant to case study in role-plays as agreed by your assessor. You must read the following information related to your assessment to prepare and perform in order to provide evidence of your skills and knowledge related to the unit of competency. |
|
4 |
Purpose (objective) of the Assessment (Why?) |
To gather evidence of your ability to apply skills and knowledge consistently to Promote workplace cyber security awareness and best practices. |
|
|
||
|
6 |
Assessment Date/s and Timing/s (When?)
|
This assessment will be conducted according to the training delivery session plan. Assessor will specify the timings for assessment and evidence submission date/s and timing/s. Time allowed for the assessment completion is 4 hours within 20 hours of training delivery of the week 4. |
|
7 |
Specifications (What structure, format, and demonstration) |
Provide written solutions to all the case study activities and questions using word-processed documents. You may use this MS Word /Mac document for your answering. Provide specified length and numbers mentioned in each written activity. For role-play activities, play the role as specified by your assessor demonstrating foundation skills and knowledge application while being observed by your assessor. Submit the written activities with a cover page that includes your name, student ID, unit name unit code, date of submission and assessor name. Include header (unit name/code) and footer (page number, student name and student ID number) |
|
8 |
Assessment Context (Where and in what condition) |
Assessment is conducted in the training room simulated and safe environment where you must perform consistently applying skills and knowledge. You must also provide written solutions to the activities in a word-processed document with evidence that demonstrates consistent skills and knowledge application in various conditions specified in the assessment task. Assessed in a simulated off-the-job situation that reflects the real workplace. |
|
9 |
Required Resources (What resources, equipment, tools, and materials) |
Assessment task with instruction and assessment information Learner workbook and other training handouts. Access to simulated workplace business equipment and resources. Access to simulated workplace policies and procedures. Computer with Internet access word-process software (MS Word/Mac). Workspace, table/s, chair/s and stationery as required. Case study and/or real workplace scenario Access to relevant legislation, regulations, standards, and code of practice Specified timing for assessment |
|
10 |
Evidence Requirements (What assessor is looking for) |
To complete the unit requirements safely and effectively, you must demonstrate consistent performance and provide evidence of your ability to provide leadership for a program of work.
In the course of above, you must: Provide written solutions to all the case study activities reflecting vocational application, Demonstrate performance and role-play activities consistently applying foundation skills and, Demonstrate consultation and communication effectively with relevant stakeholders (assessor and fellow trainees in role-plays). |
Case Study (Skills and Knowledge Application)
Using the simulated workplace and the scenario in the appendix or your own workplace referring to the scenario in the appendix as agreed by your assessor, provide solutions to consult with stakeholders to Promote workplace cyber security awareness and best practices.
Whatever the workplace you select, the policies and procedure manual of simulated workplace must be used as the policies and procedures of the workplace to undertake the following task. In case you select your own workplace or any other workplace you have access to information, provide a brief description of the workplace such as the industry, operation, personnel, and teams.
Your role
You work as the Team leader and plays the role of Sam for the simulated workplace with job role that support policies, procedures and practice within an organisation that promote cyber security in the organisation.
Your Task
Complete the following workplace activities demonstrating skills and knowledge promote cyber security in a work area:
Access Tech Dynamics (Simulated workplace) policies and procedures and use the appropriate technology platforms to assist with promoting cyber security within work area.
Read the case study in appendix, identify your role (Sam’s role), and analyse current level of awareness in work area relating to cyber security.
Develop a cyber security awareness program that reflects organisation-wide best practice and include the strategies to maintain cyber security awareness program.
Read the cyber security policy in appendix, identify, and develop a set of policies and procedures for a work area that promote cyber security awareness and practices.
Role-play activity. Meet with your supervisor (your assessor) in a role-play one on one consultation meeting to discuss procedure to develop set of cyber security policies and procedures.
Review the simulated workplace cyber security practices according to Tech Dynamics policies and procedures in appendix.
Role-play activity. Refer to next page for details. Organise role-play settings to participate in a meeting with managers and supervisors At least two fellow trainees) including your supervisor (your assessor) as agreed and facilitated by your assessor. Discuss the cyber security awareness in the workplace related to cyber security threats.
Prepare a report to maintain records relating to cyber security training in the Workplace.
Using computer and internet, conduct research on latest cyber security trends and threats impacting organisations and record findings using the template provided in appendix 2.
Write an email using technology to communicate review outcomes and cyber security improvement requirements to your work team using the email template provided in appendix 2. Ensure you review cyber security according to organisational policies and procedures.
—End of Case Study Task Activities—
Role-play – Lead solution development process
(This refers to following activity 5 and 7).
Instructions
This part is a role-play where you must organise role-play settings as agreed and facilitated by your assessor for an ideation session with relevant stakeholders as describe below including training room place, tables, chairs, a computer with Internet, papers, pens, and any other resources as required.
| Details of the task being observed |
You undertake the active part of the task participating and using oral communication skills in an ideation session with relevant manager. |
| Assumptions to be made |
You play the role of Sam – the team leader. Your assessor plays the role of James – the program manager of the simulated workplace work area. For the purpose of role-play and practical ability, you select only two team members (E.g., Tom or Tanya and Barry or Tanya.) |
| Persons involved |
You (Candidate), assessor, and other two trainees selected by your assessor |
| Participant’s involvement |
Respond to the candidate according to the information provided in the case study. |
| Equipment and resources |
Computer, projector, Internet, whiteboard, and markers etc. (This is an option for you to develop policies and procedures, training program using main features and functions of digital tools to complete work tasks and access information. |
|
Timing for the role-play: |
7 – 10 minutes per candidate per role-play plus your assessor will decide any additional time required based on your participation, behaviour, and ability to perform satisfactorily. |
|
Conditions under which the observation is conducted |
Skills in this assessment are demonstrated by the candidate and observed by assessor in a simulated environment where the conditions are typical of those in a working environment in this industry. This includes access to: Workplace or simulated workplace policies and procedures AssignmentTutorOnline relevant legislation, regulations, standards, and codes workplace documentation and resources relevant to required performance evidence. |
|
Observable behaviour |
Effective oral communication Participation in discussions interacting with others Application of decision-making skills Application of problem solving skills. |
Activities to perform in the role-play (Required performance and behaviour)
Meet with the manager (your assessor) and other team members in a role-play meeting to discuss the cyber security awareness in the workplace related to cyber security threats according to case study scenarios.
Explain latest cyber security threats and trends impacting organisations
Explain the current level of awareness in work area relating to cyber security
Explain and seek feedback on cyber security awareness program that reflects organisation-wide best practice.
Explain the new set of cyber security policies you have developed in activity 4.
|
Self-Assessment Checklist |
Note: The following checklist is for you to confirm your work completion as well as performance and demonstration of skills. Ensure you carefully check, and tick as completed and performed before submitting written evidence and while demonstrating skills during performing the task.
|
Assessment Task Activity |
Completed as required |
||
|
Case Study |
Yes |
No |
|
|
1 |
Access Tech Dynamics (Simulated workplace) policies and procedures and use the appropriate technology platforms to assist with promoting cyber security within work area. |
☐ |
☐ |
|
2 |
Read the case study in appendix, identify your role (Sam’s role), and analyse current level of awareness in work area relating to cyber security. |
☐ |
☐ |
|
3 |
Develop a cyber security awareness program that reflects organisation-wide best practice and include the strategies to maintain cyber security awareness program. |
☐ |
☐ |
|
4 |
Read the cyber security policy in appendix, identify, and develop a set of policies and procedures for a work area that promote cyber security awareness and practices. |
☐ |
☐ |
|
5 |
Role-play activity. Meet with your supervisor (your assessor) in a role-play one on one consultation meeting to discuss procedure to develop set of cyber security policies and procedures. |
☐ |
☐ |
|
6 |
Review the simulated workplace cyber security practices according to Tech Dynamics policies and procedures in appendix. |
☐ |
☐ |
|
7 |
Role-play activity. Refer to next page for details. Organise role-play settings to participate in a meeting with managers and supervisors At least two fellow trainees) including your supervisor (your assessor) as agreed and facilitated by your assessor. Discuss the cyber security awareness in the workplace related to cyber security threats. |
☐ |
☐ |
|
8 |
Prepare a report to maintain records relating to cyber security training in the Workplace. |
☐ |
☐ |
|
9 |
Using computer and internet, conduct research on latest cyber security trends and threats impacting organisations and record findings using the template provided in appendix 2. |
☐ |
☐ |
|
10 |
Write an email using technology to communicate review outcomes and cyber security improvement requirements to your work team using the email template provided in appendix 2. Ensure you review cyber security according to organisational policies and procedures. |
☐ |
☐ |
Assessment Task 3 – Project
(Includes role-plays)
Develop cyber security practices in work area and provide training
You are required to read the following assessment information, requirements, and instructions before commencing. This task has simulated workplace reference. Ensure you access the simulated workplace resources (planning documents, policies, and procedures etc.), equipment, applicable legislation, regulation, standards, and code of conduct during the assessment as specified and facilitated by your assessor.
|
Assessment Information |
Description |
|
|
1 |
Assessment Method |
Project (simulated workplace) |
|
2 |
Assessment Type |
Summative |
|
3 |
Assessment Description (What?) |
This assessment task is a project for you to promote workplace cyber security awareness and best practices. You are required to analyse the case scenario and provide written solutions to task activities by demonstrating applicable foundation skills and knowledge. You must also provide performance solutions to specific role-play activities relevant to case study in role-plays as agreed by your assessor. You must read the following information related to your assessment to prepare and perform in order to provide evidence of your skills and knowledge related to the unit of competency. |
|
4 |
Purpose (objective) of the Assessment (Why?) |
To gather evidence of your ability to apply skills and knowledge consistently to Promote workplace cyber security awareness and best practices. |
|
|
||
|
6 |
Assessment Date/s and Timing/s (When?)
|
This assessment will be conducted according to the training delivery session plan. Assessor will specify the timings for assessment and evidence submission date/s and timing/s. Time allowed for the assessment completion is 4 hours within 20 hours of training delivery of the week 4. |
|
7 |
Specifications (What structure, format and demonstration) |
Provide written solutions to all the case study activities and questions using word-processed documents. You may use this MS Word /Mac document for your answering. Provide specified length and numbers mentioned in each written activity. For role-play activities, play the role as specified by your assessor demonstrating foundation skills and knowledge application while being observed by your assessor. Submit the written activities with a cover page that includes your name, student ID, unit name unit code, date of submission and assessor name. Include header (unit name/code) and footer (page number, student name and student ID number) |
|
8 |
Assessment Context (Where and in what condition) |
Assessment is conducted in the training room simulated and safe environment where you must perform consistently applying skills and knowledge. You must also provide written solutions to the activities in a word-processed document with evidence that demonstrates consistent skills and knowledge application in various conditions specified in the assessment task. Assessed in a simulated off-the-job situation that reflects the real workplace. |
|
9 |
Required Resources (What resources, equipment, tools and materials) |
Assessment task with instruction and assessment information Learner workbook and other training handouts. Access to simulated workplace business equipment and resources. Access to simulated workplace policies and procedures. Computer with Internet access word-process software (MS Word/Mac). Workspace, table/s, chair/s and stationery as required. Case study and/or real workplace scenario Access to relevant legislation, regulations, standards, and code of practice Specified timing for assessment |
|
10 |
Evidence Requirements (What assessor is looking for) |
To complete the unit requirements safely and effectively, you must demonstrate consistent performance and provide evidence of your ability to provide leadership for a program of work.
In the course of above, you must: Provide written solutions to all the case study activities reflecting vocational application, Demonstrate performance and role-play activities consistently applying foundation skills and, Demonstrate consultation and communication effectively with relevant stakeholders (assessor and fellow trainees in role-plays). |
Case Study (Skills and Knowledge Application)
Using the simulated workplace and the scenario in the appendix or your own workplace referring to the scenario in the appendix as agreed by your assessor, provide solutions to consult with stakeholders to Promote workplace cyber security awareness and best practices.
Whatever the workplace you select, the policies and procedure manual of simulated workplace must be used as the policies and procedures of the workplace to undertake the following task. In case you select your own workplace or any other workplace you have access to information, provide a brief description of the workplace such as the industry, operation, personnel, and teams.
Your role
You work as the manager for the simulated workplace with job role that support policies, procedures and practice within an organisation that promote cyber security in the organisation.
Your Task
Complete the following workplace activities demonstrating skills and knowledge:
Access Tech Dynamics (Simulated workplace) policies and procedures and use the appropriate technology platforms to assist with promoting cyber security within work area.
Read the case study in appendix and analyse current level of awareness in work area relating to cyber security.
Develop a set of policies and procedures for a work area that promote cyber security awareness and practices.
Identify two different cyber security matters from the case study.
Conduct research using computer and Internet and analyse cyber security trends and record your findings for documentation relating to cyber security protection in the workplace.
Arrange a training program for work team on cyber security awareness on those two matters.
Develop a training plan using computer and software technology and using the template provided in appendix 2.
—End of Project Task Activities—
|
Self-Assessment Checklist |
Note: The following checklist is for you to confirm your work completion as well as performance and demonstration of skills. Ensure you carefully check, and tick as completed and performed before submitting written evidence and while demonstrating skills during performing the task.
|
Assessment Task Activity |
Completed as required |
||
|
Case Study |
Yes |
No |
|
|
1 |
Access Tech Dynamics (Simulated workplace) policies and procedures and use the appropriate technology platforms to assist with promoting cyber security within work area. |
☐ |
☐ |
|
2 |
Read the case study in appendix and analyse current level of awareness in work area relating to cyber security. |
☐ |
☐ |
|
3 |
Develop a set of policies and procedures for a work area that promote cyber security awareness and practices. |
☐ |
☐ |
|
4 |
Identify two different cyber security matters from the case study. |
☐ |
☐ |
|
5 |
Conduct research using computer and Internet and analyse cyber security trends and record your findings for documentation relating to cyber security protection in the workplace. |
☐ |
☐ |
|
6 |
Arrange a training program for work team on cyber security awareness on those two matters. |
☐ |
☐ |
|
7 |
Develop a training plan using computer and software technology and using the template provided in appendix 2. |
☐ |
☐ |
|
References (For task 2) A reference list lists only the sources you refer to in your writing. The purpose of the reference list is to allow your sources to be found by your reader (assessor). It also gives credit to authors you have consulted for their ideas. It helps you to avoid plagiarism by making it clear which ideas are your own and which are someone else’s, shows your understanding of the topic, gives supporting evidence for your ideas, arguments and opinions. allows others to identify the sources you have used. For example, Website with an author – Author surname, initials (Year), article title, website name, Available at: http://website url.com.au/article, Accessed 10 March 2021. Website without author and no date – Article title (n.d.), website name, Available at: http://website url.com.au/article, Accessed 10 March 2021. Book with no author – Title of book, edition (edn), Volume number or number of volumes, Publisher, Place of publication, page number(s) if applicable. Book with one author – Author, A (Year), Title of book, Publisher, Place of publication. Book with two or three authors – Authors, AA, Author, BB & Author, CC (Year), Title of book, Publisher, Place of publication. |
|
List all references used for assessment task 2 below (if any)
|
Appendix
Case Study (Simulated Workplace)
Tech Dynamics Pty Ltd
Tech Dynamics Pty Ltd (TD) is (simulated workplace) a leader in Business IT Support, mobile strategy, design, development, and promotion based in Melbourne, Australia. The main Director and Promoter Mr. John Smith has been in this business for over 15 years and have delivered hundreds of apps to satisfied customers. Tech Dynamics Pty Ltd started operations in 2018 year and Director were semi-actively working on the business, now, he wants to engage himself full-time in the business and actively wants to develop the business model. Tech Dynamics Pty Ltd is a business providing technology services and solutions to both large and small companies, optimizing organizational performance by mapping strategic goals and objectives to IT initiatives.
Work area
Software development and Corporate IT support
Work Team
Jason – Program Manager
Sam – Team leader
Tom, Sue, Natali, Michelle, Rob, Tony – Software/App Developers
Barry, Tanya, Robin, Lin, Lucy – Desktop Support/Engineers
Mary – Assistant
Cybersecurity awareness at Tech Dynamics
Cybersecurity awareness entails being vigilant in everyday situations. Being aware of the dangers associated with web browsing, email checking, and online interaction are all components of cybersecurity awareness. As the team leader, it is Sam’s responsibility to ensure that cybersecurity is a critical component of everyone’s role. While not every employee needs to understand concepts such as SPF records and DNS cache poisoning, arming each employee with information pertinent to their role helps them stay safe online—both at work and at home. The best way to prepare technical and non-technical staff for the right cybersecurity threats is through role-based training. Cybersecurity awareness may have a slightly different meaning for his general workforce than it does for technical teams. Data management, permissions, and regulations are all topics that your IT team should be familiar with but are not always relevant to the rest of your organisation. It is critical to provide appropriate training to each team to develop a cybersecurity awareness programme that motivates long-lasting behaviour change.
What is the importance of cybersecurity awareness?
As with safety incidents, cybersecurity incidents can be extremely costly. If you’re having difficulty allocating budget for cybersecurity training, tools, or talent, you should consider risk management. With the number of cyberattacks increasing year after year, the risk of not educating your employees about cybersecurity awareness only increases. Cybercriminals are constantly devising new ways to circumvent the most advanced defensive tools and technologies, infiltrating your employees’ inboxes and browsers. In 2021 alone, 85 percent of data breaches were caused by humans, and 94 percent of malware was distributed via email.
Almost always, these email attacks involve some form of phishing. Phishing is the fraudulent act of sending emails purporting to be from a legitimate source to coerce victims into disclosing sensitive information such as passwords and credit card numbers. You may have encountered phishing emails in the past, offering you a free television or requesting that you change your password. While most of these will be caught by an email spam filter, some will occasionally make it to your inbox. Not only is phishing a straightforward attack to execute, but it is also easily accessible via a Google search. Anyone with access to the dark web can purchase a phishing kit in the same way they would an Amazon book. Your employees will eventually encounter a cyber incident, and you’ll want them to be prepared to respond appropriately by notifying your IT or security team of threats. Fortunately, cybersecurity awareness training can act as a strong deterrent to phishing attacks.
Defending against phishing and social engineering attacks boils down to understanding your adversary. These attacks can take a variety of forms, but the most common are phishing emails that request usernames, passwords, and personally identifiable information (PII). A good rule of thumb is to exercise healthy scepticism whenever an email requests personal information, particularly when the sender is unknown.
This may seem like a daunting task for any business, let alone a small one. The reality is that the opportunity cost of ignoring employee training is far too high to ignore. IBM estimates that the average cost of a data breach was $4.24 million last year. 38% of businesses lost business because of a breach, accounting for more than half of all financial losses. By training your employees to recognise these attacks, you can significantly reduce the likelihood of experiencing a security incident or breach. This can mean the difference between a costly ransomware infection and a message to your IT department that reads, “This email appeared suspicious, so I did not open it.”
The following top 10 challenges of cyber security situations are faced by the company:
Ransomware attacks
IoT attacks
Cloud attacks
Phishing attacks
Blockchain and cryptocurrency attacks
Software vulnerabilities
Machine learning and AI attacks
BYOD policies
Insider attacks
Outdated hardware.
1. Attacks by ransomware
Ransomware attacks have grown in popularity in recent years and will be one of India’s primary Cyber Security challenges in 2020. According to cyber security firm Sophos, approximately 82% of Indian organisations have been impacted by ransomware in the last six months. Ransomware attacks encrypt a user’s data and prevent them from accessing it until a ransom is paid. Ransomware attacks are critical for individual users, but even more so for businesses that are unable to access data necessary for day-to-day operations. However, in most ransomware attacks, the attackers refuse to release the data even after payment is made, preferring to extort additional money.
2. Attacks by IoT
By 2021, IoT Analytics predicts that there will be approximately 11.6 billion IoT devices. The Internet of Things (IoT) refers to computing, digital, and mechanical devices that are capable of transmitting data autonomously over a network. Desktops, laptops, mobile phones, and smart security devices are all examples of IoT devices. As the adoption of IoT devices accelerates, so do the cyber security challenges. By attacking IoT devices, sensitive user data can be compromised. Protecting IoT devices is a significant challenge in Cyber Security, as gaining access to these devices can facilitate the launch of additional malicious attacks.
3. Attacks from the cloud
Today, most of us rely on cloud services for personal and professional purposes. Additionally, hacking cloud-based platforms to steal user data is a challenge for businesses’ Cyber Security. We are all familiar with the infamous iCloud hack, which exposed celebrities’ private photos. If such an attack is launched against enterprise data, it poses a significant threat to the organisation and may even result in its demise.
4. Attacks by phishers
Phishing is a form of social engineering attack that is frequently used to steal user data, such as usernames and passwords and credit card numbers. Unlike ransomware attacks, the hacker does not immediately delete the user’s confidential data upon gaining access. Rather than that, they use it for their own gain, such as online shopping and unauthorised money transfers. Phishing attacks are popular among hackers because they allow them to exploit a user’s data until the user discovers it. Phishing attacks continue to be a major source of concern for cyber security in India, as the demographic is unfamiliar with handling confidential data.
5. Attacks on blockchain and cryptocurrency
While blockchain and cryptocurrency may be unfamiliar to the average internet user, they are critical to businesses. Thus, attacks on these frameworks’ present significant challenges for businesses in terms of Cyber Security, as they can compromise customer data and business operations. These technologies have progressed beyond their infancy but have not yet reached an advanced stage of security. As a result, several attacks have occurred, including DDOS, Sybil, and Eclipse, to name a few. Organizations must be aware of the security risks associated with these technologies and ensure that no security gaps exist for intruders to exploit.
6. Vulnerabilities in software
Even the most sophisticated software contains vulnerabilities that could pose significant challenges to Cyber Security in 2020, given the increased adoption of digital devices. Individuals and businesses generally avoid updating the software on these devices because they believe it is unnecessary. However, updating the software on your device to the latest version should be a priority. An older version of software may contain patches for security vulnerabilities that have been addressed by the developers in a subsequent version. Attacks on unpatched software versions are a significant source of concern for cyber security. These attacks, such as the Windows zero-day attacks, are typically carried out on many people.
7. Machine learning and artificial intelligence attacks
While Machine Learning and Artificial Intelligence technologies have been shown to be extremely beneficial for massive development in a variety of sectors, they do have their limitations. These technologies can be used to perpetrate cyberattacks and pose a threat to businesses. These technologies enable the identification of high-value targets within a large dataset. Machine Learning and artificial intelligence (AI) attacks are another major source of concern in India. A sophisticated attack may prove impossible to counter due to our country’s lack of cyber security expertise.
8. Bring your own device policies
Most businesses have a Bring-Your-Own-Device policy in place for their employees. Having such systems introduces a slew of complications into Cyber Security. To begin, if the device is running an out-of-date or pirated version of the software, it is already a prime target for hackers. Because the method is used for both personal and professional purposes, hackers can easily obtain sensitive business data. Second, if these devices’ security is compromised, it becomes easier to gain access to your private network. Thus, organisations should abandon BYOD policies in favour of providing secure devices to employees, as such systems pose enormous security and network compromise risks.
9. Intellectual attacks
While the majority of Cyber Security challenges confront businesses on an external level, there are instances of an inside job. Employees acting maliciously may divulge or export confidential information to competitors or other individuals. This can result in significant financial and reputational damage to the business. Computer Security challenges can be overcome by monitoring data and inbound and outbound network traffic. Installing firewall devices that route data through a centralised server or restricting access to files based on job roles can assist in reducing the risk of insider attacks.
10. Outdated hardware
To be honest, you shouldn’t be surprised. Not all cyber security threats take the form of software attacks. Recognizing the risk of software vulnerabilities, software developers provide a periodic update. However, these new updates may be incompatible with the device’s hardware. This results in obsolete hardware, which is incapable of running the latest software versions. As a result, these devices are running an older version of the software, making them extremely vulnerable to cyberattacks.
To safeguard your devices and data from cyber threats, you can take simple precautions such as upgrading your hardware and software to meet your digital needs. Additionally, you will need to implement advanced security measures such as installing a firewall to add an additional layer of security. We hope that this blog, which highlights ten major cyber security challenges, has increased your awareness of the dangers and motivated you to take corrective action on an individual and organisational level to safeguard against such security threats. Assume you’re considering a career as a Cyber Security Specialist. In that case, you can peruse our Master Certificate in Cyber Security (Blue Team), a 520-hour programme that prepares students for seven globally recognised certifications.
Cyber security policy
Policy statement
Cybersecurity is a critical concern for IT departments and C-level executives alike. Security, on the other hand, should be a concern for every employee in an organisation, not just IT professionals and top executives. A cybersecurity policy that outlines everyone’s responsibilities for protecting IT systems and data is an effective way to educate employees about the critical nature of security. A cybersecurity policy establishes standards of behaviour for activities such as email attachment encryption and social media usage restrictions.
Policy
Cybersecurity policies are critical due to the potential financial cost of cyberattacks and data breaches. Simultaneously, employees are frequently the weakest link in an organization’s security chain. Employees share passwords, click on malicious URLs and attachments, access cloud applications that are not approved, and fail to encrypt sensitive files.
These policies are particularly critical for publicly traded companies and organisations operating in regulated industries such as healthcare, finance, or insurance. These organisations face significant fines if their security procedures are deemed insufficient.
Even small businesses that are not subject to federal regulations are expected to adhere to minimum IT security standards and may face prosecution for a cyberattack those results in the loss of consumer data if the organisation is found to be negligent. Certain states, such as California and New York, have enacted legislation requiring organisations conducting business in their jurisdictions to adhere to information security standards.
Cybersecurity policies are also critical to an organization’s public image and credibility. Customers, partners, shareholders, and prospective employees all want to know that an organisation can safeguard their sensitive data. An organisation may be unable to provide such evidence in the absence of a cybersecurity policy.
Cybersecurity practices include:
Rules for using email encryption
Steps for accessing work applications remotely
Guidelines for creating and safeguarding passwords
Rules on use of social media
A cyber security policy entails the following:
Threats to the technology and information assets that you need to protect rules and controls for protecting those assets and your business
It’s critical for your business to develop a cyber security policy – even more so if you have employees. It teaches your employees about their role in safeguarding your business’s technology and information assets. When drafting your policy, ensure that it instructs your employees on the following:
the types of business information that can be shared and the circumstances under which the use of devices and online materials is acceptable
Consider the following steps when developing your cyber security policy.
Procedure
1. Establish minimum password requirements
Your cyber security policy should include the following:
requirements for creating secure passwords
how to properly store passphrases how frequently you should update passphrases
the critical nature of having distinct passwords for various logins
Learn how to create and manage strong passwords.
2. Describe the security measures associated with email.
Include guidelines on the following:
When it is appropriate to share your work email address, do so only with trusted contacts and businesses.
preventing junk, spam, and phishing emails
identifying, deleting, and reporting emails that appear to be suspicious
3. Describe how sensitive data should be handled.
When it comes to handling sensitive data, the following guidelines apply:
When staff may share sensitive data with others, there are several ways they should store physical files containing sensitive data, such as in a locked room or drawer.
methods for securely destroying any sensitive data that is no longer required
4. Establish guidelines for the proper use of technology.
Among the rules governing technology should be the following:
Where employees can access their work devices, such as a business laptop, when they are not in use How to report a theft or loss of a work device
how security patches and spam filter updates will be distributed to employee devices
When to physically shut down computers and mobile devices when not in use When to lock screens when computers and devices are left unattended
restrictions on the use of removable devices to prevent the installation of malware
the requirement to scan all removable media for viruses prior to connecting them to your business systems
5. Establish guidelines for social media use and internet access
Social media and internet access standards may include the following:
What type of business information is appropriate to share on social media channels?
What should employees sign when using their work email account? What websites and social media channels should employees’ access during work hours?
6. Anticipate an incident
If a cyber security incident occurs, you should mitigate the damage and resume normal operations as quickly as possible. You’ll want to consider the following:
how to handle a cyber-attack
what actions should be taken by staff members and what their roles and responsibilities are in the event of a cyber attack
Create a plan for responding to cyber security incidents
A cyber incident response plan assists you in anticipating and responding to a cyber incident. It details the procedures that you and your staff must follow. When developing a plan, keep the following stages in mind.
Prepare and avoid
Prepare your business and employees to deal with cyber-attacks.
Create policies and procedures to assist employees in preventing attacks and identifying potential incidents.
Determine the critical assets to your business – financial, information, and technological assets.
Consider the risks associated with these and the steps necessary to mitigate the effects of an incident.
Establish roles and responsibilities so that everyone understands who to contact in the event of an incident and what to do next.
Examine and detect
Conduct a risk assessment and identify any unusual activity that could jeopardise your business’s information and systems. Unusual behaviour may include the following:
Accounts and your network are inaccessible; passwords are no longer working; data is missing or altered; your hard drive is running low on space; your computer is constantly crashing; your customers receive spam from your business account; and you receive numerous pop-up advertisements.
Recognize and evaluate
Determine the incident’s initial cause and assess its impact so that it can be contained quickly.
Determine the incident’s impact on your business.
Determine the impact on your business and assets if it is not contained immediately.
Respond
Isolate the affected systems to prevent further damage from the cyber incident. Disconnect from the network and power down your computer if necessary to prevent the threat from spreading.
Eliminate the danger.
Rebuild your systems following the incident by repairing and restoring them to normal operation.
Review
Determine which systems and processes require improvement and implement the necessary changes.
Evaluate the incident both before and after it occurred, as well as any lessons learned.
Update your cyber security incident response plan in light of the lessons learned so that your business can respond more effectively.
Appendix 2
Assessment Templates
Training Plan
-
Training needs Training method Trainees Timeframe By whom