Unit rationale, description and aim

Cybersecurity practice extends beyond technical controls to include organisational governance, risk management, legal compliance and ethical decision-making. Contemporary organisations require cybersecurity professionals who can evaluate cyber risk, interpret regulatory and standards-based requirements, and design governance responses that are technically informed, ethically defensible and strategically aligned. This unit complements the technical cybersecurity units in the course by developing advanced capability in cyber risk, governance and ethics, and supports professional preparation in areas aligned with industry.

This unit examines the principles and practices of cyber risk management, governance and ethics in organisational contexts. Students critically analyse cyber risk using contemporary frameworks and standards, including ISO/IEC 27001, ISO/IEC 27005, ISO 31000, the NIST Cybersecurity Framework, COBIT 2019 framework and the Australian Cyber Security Centre Essential Eight. The unit also considers cyber policy, regulatory obligations, ethical leadership, human-centred security, and governance issues associated with emerging technologies, including AI-assisted development and automated decision-making in cybersecurity.

The aim of this unit is to develop students’ capacity to critically evaluate cyber risk and governance challenges, and to design ethically informed governance and policy responses aligned with contemporary standards, regulations and organisational needs.

2027 10

Campus offering

No unit offerings are currently available for this unit.

Prerequisites

ITEC642 Secure Software Engineering

Learning outcomes

To successfully complete this unit you will be able to demonstrate you have achieved the learning outcomes (LO) detailed in the below table.

Each outcome is informed by a number of graduate capabilities (GC) to ensure your work in this, and every unit, is part of a larger goal of graduating from ACU with the attributes of insight, empathy, imagination and impact.

Explore the graduate capabilities.

Critically evaluate cyber risk in organisational a...

Learning Outcome 01

Critically evaluate cyber risk in organisational and societal contexts using established cyber risk and assurance frameworks.
Relevant Graduate Capabilities: GC2, GC7

Analyse cybersecurity governance models, standards...

Learning Outcome 02

Analyse cybersecurity governance models, standards and regulatory obligations relevant to organisational practice.
Relevant Graduate Capabilities: GC1, GC9

Design cyber risk management and security policy r...

Learning Outcome 03

Design cyber risk management and security policy responses aligned with industry standards and good governance principles
Relevant Graduate Capabilities: GC2, GC8

Critically evaluate ethical issues in cybersecurit...

Learning Outcome 04

Critically evaluate ethical issues in cybersecurity decision-making, including those arising from emerging technologies such as AI-assisted development.
Relevant Graduate Capabilities: GC2, GC12

Content

Topics will include:

Cyber Risk & Assurance

  • Risk identification, analysis and treatment
  • ISO 27001 / ISO 27005
  • NIST Cybersecurity Framework
  • ASD Essential Eight
  • Enterprise risk reporting

Cyber Governance

  • IT governance principles (COBIT overview)
  • Security policy development
  • Security architecture governance
  • Board-level cybersecurity oversight

Legal & Regulatory Frameworks

  • Australian Privacy Act
  • Notifiable Data Breach Scheme
  • International regulatory comparisons (e.g., GDPR)
  • Compliance management

Ethical & Human-Centred Cybersecurity

  • Ethical decision-making in cyber incidents
  • Human factors and organisational behaviour
  • Privacy vs surveillance
  • Security and vulnerable populations

Governance of Emerging Technologies

  • AI governance and accountability
  • Risks of AI-assisted development tools

Assessment strategy and rationale

The assessment strategy is designed to progressively develop students’ capability from analysis to design and critical judgement, aligned with AQF Level 9 expectations. Assessment 1 requires students to analyse the cyber risk profile of an organisation using recognised frameworks (e.g., ISO 27005, NIST CSF), developing foundational skills in risk identification and evaluation. Assessment 2 builds on this by requiring students to design a cybersecurity governance and policy framework aligned with standards and regulatory requirements, demonstrating applied knowledge in organisational contexts. Assessment 3 requires students to critically evaluate a complex ethical scenario (e.g., AI governance or breach response) and justify an ethically informed decision, integrating risk, governance and societal considerations. Together, these assessments provide a coherent progression from analytical understanding to applied design and advanced critical evaluation, supporting the achievement of all learning outcomes. To pass this unit, students must demonstrate competence in all learning outcomes and achieve an aggregate mark of at least 50%.

Overview of assessments

Task 1: Cyber Risk Analysis Report Students anal...

Task 1: Cyber Risk Analysis Report

Students analyse and evaluate the cyber risk profile of a real or realistic organisation using recognised frameworks (e.g., ISO/IEC 27005, NIST Cybersecurity Framework). They identify key assets, threats and vulnerabilities, assess likelihood and impact, and evaluate and prioritise risks based on organisational context and risk appetite. Students are required to justify their risk ratings, assess potential consequences, and propose appropriate risk treatment strategies aligned with industry standards. This assessment develops capability in both systematic risk analysis and critical evaluation of cyber risk in organisational settings.

Submission Type: Individual

Assessment Method: Written report

Artefact: report (1000 words)

Weighting

30%

Learning Outcomes LO1, LO2
Graduate Capabilities GC1, GC2, GC7, GC9

Task 2: Governance and Policy Design Students de...

Task 2: Governance and Policy Design

Students design a cybersecurity governance and policy response for an organisation, demonstrating alignment with standards, governance principles and compliance requirements.


Submission Type: individual

Assessment Method: Presentation

Artefact: Live / Recorded with face-overlay Presentation (7 minutes) + Online Viva

Weighting

30%

Learning Outcomes LO2, LO3
Graduate Capabilities GC1, GC2, GC8, GC9

Task 3: Ethics and Emerging Technology Case Stud...

Task 3: Ethics and Emerging Technology Case Study

Students critically evaluate an ethical cybersecurity scenario involving issues such as surveillance, breach response, AI-assisted development, or automated cyber decision-making, and justify an ethically informed course of action.

Submission Type: Individual

Assessment Method: Written Report and Presentation

Artefact: Written report (1000 words) + Live / Recorded with face-overlay Presentation (7 minutes) + Online Viva

Weighting

40 %

Learning Outcomes LO1, LO2, LO3, LO4
Graduate Capabilities GC1, GC2, GC7, GC9, GC12

Learning and teaching strategy and rationale

This unit is delivered in online mode and uses a combination of guided learning materials, recorded lectures, case-based learning, discussion activities and applied tasks. The learning and teaching strategy is designed to support AQF Level 9 learning through critical analysis, evaluation of complex contemporary issues, and design of contextually appropriate governance responses. Learning activities are structured to progressively build students’ ability to interpret standards, analyse authentic cyber scenarios and justify governance decisions in professional contexts.

Students should plan to commit approximately 150 hours to this unit over the semester, including completing in learning activities, independent study, readings and assessment preparation.

Representative texts and references

Representative texts and references

Kim, D., & Solomon, M. G. (2021). Fundamentals of information systems security (4th ed.). Jones & Bartlett Learning.

Whitman, M. E., & Mattord, H. J. (2022). Principles of information security (7th ed.). Cengage.Anderson, R. (2020). Security engineering: A guide to building dependable distributed systems (3rd ed.). Wiley.

Australian Cyber Security Centre. (2024). Essential Eight assessment process guide. Australian Signals Directorate.

Dubber, M. D., Pasquale, F., & Das, S. (Eds.). (2021). The Oxford handbook of ethics of AI. Oxford University Press.

International Organization for Standardization. (2022). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection—Information security management systems—Requirements. ISO.

International Organization for Standardization. (2022). ISO/IEC 27005:2022 information security, cybersecurity and privacy protection—Guidance on managing information security risk. ISO.

ISACA. (2019). COBIT 2019 framework: Governance and management objectives. ISACA.

Kim, D., & Solomon, M. G. (2021). Fundamentals of information systems security (4th ed.). Jones & Bartlett Learning.

National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce.

Tavani, H. T. (2016). Ethics and technology: Controversies, questions, and strategies for ethical computing (5th ed.). Wiley.

Locations
Credit points
Year

Have a question?

We're available 9am–5pm AEST,
Monday to Friday

If you’ve got a question, our AskACU team has you covered. You can search FAQs, email, live chat, call – whatever works for you.

Live chat with us now

Chat to our team for real-time
answers to your questions.

Launch live chat

Visit our FAQs page

Find answers to some commonly
asked questions.

See our FAQs