Cybersecurity Governance, Risk and Compliance

Unit Outline (Higher Education)

   
?   Display Outline Guidelines      


Effective Term: 2027/05
Institute / School :Institute of Innovation, Science & Sustainability
Unit Title: Cybersecurity Governance, Risk and Compliance
Unit ID: ITECH2506
Credit Points: 15.00
Prerequisite(s): (ITECH1502)
Co-requisite(s): Nil
Exclusion(s): Nil
ASCED: 029999
Other Change:  
Brief description of the Unit

Cybersecurity Governance, Risk, and Compliance (GRC) are essential components of any organisation's approach to managing its digital security posture. In this unit, these components will be covered in detail. In the governance part, students will learn about frameworks, policies, procedures, and processes that guide the overall management of cybersecurity within an organisation, e.g., establishing roles and responsibilities, defining goals and objectives, and ensuring that cybersecurity efforts align with the organisation's strategic objectives. The risk management part will cover aspects like identifying, assessing, and prioritising potential cybersecurity threats and vulnerabilities that could affect the organisation, such as ongoing monitoring, evaluation, and adjustment of security measures to address evolving threats and changes in the business environment. Finally, the compliance part will cover relevant laws, regulations, standards, and industry best practices related to cybersecurity, such as data protection regulations, industry-specific standards, and internal policies and procedures.

Grade Scheme: Graded (HD, D, C, P, MF, F, XF)
Work Experience Indicator:
No work experience
Placement Component:
Supplementary Assessment:Yes
Where supplementary assessment is available a student must have failed overall in the Unit but gained a final mark of 45 per cent or above, has completed all major assessment tasks (including all sub-components where a task has multiple parts) as specified in the Unit Description and is not eligible for any other form of supplementary assessment
Course Level:
Level of Unit in CourseAQF Level(s) of Course
5678910
Introductory                                                
Intermediate                                                
Advanced                                                
Learning Outcomes:
Knowledge:
Skills:
Application of knowledge and skills:
Other outcomes:
O1.

Explain governance frameworks, principles, and their role in aligning cybersecurity with organisational strategy.

O2.

Assess and prioritise cybersecurity risks using recognised methodologies and propose mitigation strategies.

O3.

Interpret and apply relevant laws, regulations, and industry standards to ensure organisational compliance.

O4.

Integrate GRC practices into organisational processes and policies to support strategic objectives.

O5.

Evaluate and recommend improvements for continuous monitoring and enhancement of GRC programs.

Unit Content:

Topics may include:

1. GRC Foundations and Governance Frameworks

2. Information Security Policy and Organisational Governance

3. AI Governance and Emerging Technology Risk

4. Cybersecurity Risk Assessment and Management

5. Risk Treatment and Control Mapping

6. Risk Monitoring and Key Risk Indicators

7. Regulatory Compliance and Obligations Mapping

8. Industry Standards, Regulations, Frameworks, and Best Practices Gap Analysis and Audit

9. Compliance Reporting and Remediation

10. GRC Programme Integration

Graduate Attributes:
 Learning Outcomes AssessedAssessment TasksAssessment TypeWeightingProfessional Standards
1. 1, 2, 3

Students act as cybersecurity governance consultants engaged to review a realistic organisational case study and provide practical solutions to a range of problems.

GRC Risk Analysis and Compliance Investigation

30 - 35%

1.1, 1.2, 1.5, 1.6, 1.8, 2.1, 2.5

2. 1, 3, 4, 5

Students develop a cybersecurity governance, risk and compliance improvement strategy for a simulated organisation.

Organisational GRC Improvement Project

35 - 45%

1.1, 1.2, 1.5, 1.6, 1.8, 2.1, 2.5

3. 1, 2, 3, 4, 5

Students individually respond to an unseen cybersecurity governance and compliance scenario identifying governance issues, assess risks, explain compliance obligations, recommend mitigation approaches, and defend decisions.

Professional Validation Interview / Scenario Defence

10 - 30%

1.6, 1.8, 2.5

Adopted Reference Style:
IEEE  ()

Professional Standards / Competencies:
 Standard / Competency