CPPSEC5004 — Develop security risk management plans
Generate a complete, audit-ready assessment tool for this unit in minutes: candidate assessment, assessor guide with model answers, and a coverage matrix mapped to every component below. Reviewed and approved by your qualified person, exported under your branding.
Every new account includes a free credit — no card, no subscription.
What an assessment for CPPSEC5004 must cover
58 assessable components: 4 elements (21 performance criteria), 1 performance evidence and 33 knowledge evidence requirements, plus 3 foundation skills. An audit-defensible tool maps every question and task back to these — that mapping is the coverage matrix Auditori generates alongside the assessment.
Elements & performance criteria
1 Evaluate security risks and controls.
- 1.1Access and interpret key requirements of legislation, regulations and Australian standard ISO 31000 to understand and comply with requirements for developing security risk management plans.
- 1.2Clarify client security requirements and operating environment in consultation with relevant persons.
- 1.3Source and review information to identify security risks.
- 1.4Clearly distinguish and confirm acceptable and unacceptable security risks.
- 1.5Set priorities for risk treatment and assurance of controls.
- 1.6Highlight and specify risks that are high priority to ensure appropriate controls are developed.
- 1.7Evaluate existing controls to determine impact on risk occurrence and implement required modifications.
2 Plan risk management strategies.
- 2.1Develop and document action plans that identify tasks, activities and resources required to achieve security risk management objectives.
- 2.2Select security risk control measures based on assessed type, nature, cause and degree of risk associated with identified security risks.
- 2.3Incorporate actions to respond to contingencies when planning risk management strategies.
- 2.4Establish communication and reporting arrangements to maintain currency of action plans in consultation with relevant persons.
3 Design security risk treatment options.
- 3.1Assess client’s operating environment to confirm potential and real security risks.
- 3.2Select feasible risk treatment options and conduct research to confirm implications for controlling whole or part of security risks.
- 3.3Document and cost recommended risk treatment options to ensure compatibility with nature of risk and client requirements.
- 3.4Consult with relevant persons to verify suitability of recommended risk treatment options and obtain required approvals.
- 3.5Test risk treatment options in the field and analyse results to verify effectiveness of treatments in the security context.
4 Finalise and present security risk management plan.
- 4.1Finalise and document comprehensive security risk management plan in the required format according to workplace requirements.
- 4.2Check security risk management plan to ensure analysis and recommendations are clear, coherent and consistent with client requirements, and based on the principles of ISO 31000.
- 4.3Present risk management plan to relevant persons within agreed timeframes and explain identified security risks and treatments to enhance understanding and acceptance of recommendations.
- 4.4Implement procedures to monitor and review security risk management activities to ensure continuous improvement.
- 4.5Complete and secure risk management plan in a manner that facilitates future retrieval and maintains client confidentiality according to workplace and regulatory requirements.
Performance evidence
- To demonstrate competency, a candidate must meet the performance criteria of this unit by developing and documenting two security risk management plans that meet the requirements of clients with different risk management requirements.
Knowledge evidence
- legislative and regulatory requirements that apply when developing security risk management plans:
- key requirements of legislation, regulations and codes of conduct for security risk management in the jurisdiction of operation
- legal rights and responsibilities of employers, supervisors and employees associated with work health and safety and duty of care
- licensing requirements in the security industry
- trespass and removal of persons
- use of force
- application of integrated security measures including physical security, manpower, security technologies and security of personnel and information
- distinction between information and intelligence and methods for validating information sources
- activities to be included in action plans for security risk management
- implications for security risk management arising from:
- National Guidelines for the Protection of Places of Mass gathering from Terrorism
- Active Armed Offender Guidelines for Crowded Places
- Improvised Explosive Device Guidelines for Crowded Places
- Chemical Weapon Guidelines for Crowded Places
- Hostile Vehicle Guidelines for Crowded Places
- methods for determining the type, nature and causes of potential and actual security risks
- methods for distinguishing between acceptable and unacceptable security risks
- methods for prioritising security risks and treatment options based on degree of risk
- methods for testing treatment options in the field
- process and application of dynamic risk assessment and risk management methods
- purpose of Australia’s Strategy for Protecting Crowded Places from Terrorism and understanding of:
- definition of crowded places
- key security issues for crowded places
- objectives, characteristics and identification of active armed offenders
- definition of hostile vehicles and methods of attack
- signs of chemical weapons attack and recommend response
- general features of improvised explosive devices and recommended incident response
- recognised industry practice and application of ISO 31000:2018 Risk management – Guidelines (ISO 31000) when designing security risk management strategies and treatment options
- types of treatment options appropriate to the range of security risks and threats to various client operating environments:
- assets
- buildings
- crowded places
- mass gatherings.
Foundation skills
- oral communication skills: to negotiate client agreement
- writing skills: to prepare succinct and logically structured security risk management plans
- numeracy skills: to apply statistical methods and present statistical data.
Unit content sourced from training.gov.au — © Commonwealth of Australia, licensed under CC BY 4.0. Auditori is not affiliated with the Department of Employment and Workplace Relations.
See what you get before you start
Real, unedited Auditori output (RIIHAN201E shown), branded for a sample RTO:
Questions about assessing CPPSEC5004
What does an assessment tool for CPPSEC5004 need to cover?
To satisfy the Principles of Assessment and Rules of Evidence, an assessment for CPPSEC5004 needs to address all 58 unit components: 4 elements with 21 performance criteria, 1 performance evidence requirements, 33 knowledge evidence requirements, and the foundation skills. A coverage matrix mapping each question and task to these components is what an auditor looks for.
How does Auditori generate an assessment tool for CPPSEC5004?
Auditori pulls the current release of CPPSEC5004 from training.gov.au and generates a complete package: candidate assessment, assessor guide with model answers and observation criteria, and a coverage matrix mapping every component. A suitably qualified person then reviews and approves the draft in a built-in workflow — consistent with ASQA's guidance on AI use in VET — before export as branded PDF and editable Word.
Is the first assessment tool really free?
Yes. Every new account includes one free credit — enough to generate the complete assessment tool for CPPSEC5004 — with no card and no subscription required. After that it's pay-as-you-go per unit.
Can I check my existing CPPSEC5004 assessment instead of generating a new one?
Yes — upload your existing assessment or learner guide and Auditori maps it against every element, performance criterion, PE and KE of CPPSEC5004, showing exactly what's covered and what's missing. Mapping costs a quarter of a credit.
Related units
- CPPSEC2021 — Install security equipment and systems
- CPPSEC2022 — Install electronic locks and locking systems
- CPPSEC2023 — Install video surveillance systems and equipment
- CPPSEC2024 — Monitor and respond to electronic information from security equipment and systems
- CPPSEC2025 — Sell security products and services
- CPPSEC2026 — Perform routine maintenance on security equipment and systems
- CPPSEC2101 — Apply effective communication skills to maintain security
- CPPSEC2102 — Apply legal and procedural requirements to work effectively within a security team
- CPPSEC2103 — Apply WHS, emergency response and evacuation procedures to maintain security
- CPPSEC2104 — Apply risk assessment to select and carry out response to security risk situations
- CPPSEC2105 — Provide quality services to a range of security clients
- CPPSEC2106 — Protect self and others using basic defensive techniques
Your CPPSEC5004 assessment tool, in minutes.
First unit free. No card, no RTO registration, no subscription.
Generate CPPSEC5004 free