Accredited course Outline
12/09/2026 11:23 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Certificate IV in Offensive Cyber Security
Certificate IV in Offensive Cyber Security
11062NAT
BGS59
Current
Approved
Accreditation, State Implementation and Classification
Description
The Certificate IV in Offensive Cyber Security is designed to train individuals in conducting vulnerability assessment through offensive cyber security, otherwise known as ethical hacking/penetration testing for the specific purpose of mitigating risks to infrastructure, networks, and applications.
It will provide participants with a range of skills and knowledge needed to find and exploit vulnerabilities in the IT infrastructure, networks, and applications of a range of organisations in multiple industries to find and demonstrate weaknesses in those systems. This will allow organisations to implement security measures and strengthen ICT systems to reduce the likelihood and impact of malicious cyber-attacks.
Schedule
Packaging Rules
Total number of units = Thirteen (13)
- Ten (10) core units, plus
- Three (3) elective units from one of the specialisation groups listed below.
Note:
1. Core units must be undertaken in the order listed.
2. This course provides two specialisations, one of which must be chosen to complete the 11062NAT Certificate IV in Offensive Cyber Security.
To achieve the specialisation, the following rules must be adhered to.
To specialise in infrastructure, all three elective units in Group A must be completed.
To specialise in applications, all three elective units in Group B must be completed.
The achievement of the specialisation will be identified on a testamur as follows:
● Certificate IV in Offensive Cyber Security (Infrastructure Vulnerability Assessment Specialist)
● Certificate IV in Offensive Cyber Security (Application Vulnerability Assessment Specialist).
1. Core Units
Ten (10) must be completed in the below order:
- NAT11062001 Apply legal requirements and ethical protocols during offensive cyber security activities
- ICTNWK420 Install and configure virtual machines
- ICTWEB444 Create responsive website layouts
- ICTWEB430 Produce server-side script for dynamic web pages
- ICTPRG430 Apply introductory object-oriented language skills
- NAT11062002 Develop and implement programs and scripts for offensive cyber security
- ICTNWK311 Install and test network protocols
- NAT11062003 Test vulnerability of organisational networks
- NAT11062004 Test vulnerability of organisational operating systems
- ICTCYS603 Undertake penetration testing for organisations
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| OAQ05 | ICTPRG430 | Apply introductory object-oriented language skills | 60 | Unit of competency |
| BA040 | NAT11062001 | Apply legal requirements and ethical protocols during offensive cyber security activities | 15 | Module |
| OBS24 | ICTWEB444 | Create responsive website layouts | 50 | Unit of competency |
| BA042 | NAT11062002 | Develop and implement programs and scripts for offensive cyber security | 70 | Module |
| OAQ06 | ICTNWK420 | Install and configure virtual machines | 50 | Unit of competency |
| OBT78 | ICTNWK311 | Install and test network protocols | 30 | Unit of competency |
| OAQ01 | ICTWEB430 | Produce server-side script for dynamic web pages | 60 | Unit of competency |
| BA044 | NAT11062003 | Test vulnerability of organisational networks | 40 | Module |
| BA046 | NAT11062004 | Test vulnerability of organisational operating systems | 40 | Module |
| OBV07 | ICTCYS603 | Undertake penetration testing for organisations | 70 | Unit of competency |
2. Group A: Infrastructure Vulnerability Assessment Specialist
To specialise in infrastructure, all three (3) elective units in Group A must be completed.
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| BA050 | NAT11062006 | Implement privilege escalation in Linux operating systems | 15 | Module |
| BA048 | NAT11062005 | Implement privilege escalation in Windows operating systems | 15 | Module |
| BA052 | NAT11062007 | Infiltrate and test organisational digital environments | 50 | Module |
3. Group B: Application Vulnerability Assessment Specialist
To specialise in applications, all three (3) elective units in Group B must be completed.
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| BA058 | NAT11062010 | Analyse malware using reverse engineering software tools and techniques | 50 | Module |
| BA056 | NAT11062009 | Exploit cross-platform vulnerabilities in mobile applications | 40 | Module |
| BA054 | NAT11062008 | Exploit web application vulnerabilities | 60 | Module |
No information
General Notes
No information
Entry Requirements
Entrants to 11062NAT Certificate IV in Offensive Cyber Security must:
● be over 18 years of age
● possess intermediate computer skills sufficient to perform internet searches and download and install applications.
2. Recommended entry requirements
It is recommended that entrants have:
● intermediate knowledge of what the offensive cyber security vocation is and its applications in the workplace
● basic knowledge of Linux operating system
● ICT30120 Certificate III in Information Technology
● language, literacy, and numeracy levels sufficient to interpret at times complex documents and code scripts, to understand technical concepts, and to prepare written reports using both technical and non-technical language.
3. Limitations to entry
There are no formal entry requirements for this course. Learners seeking entry into this course are expected to have learning, reading, writing and literacy, and numeracy competencies to Level 3 as per the Australian Core Skills Framework (ACSF).
Applicants will undergo and interview process to determine their eligibility to undertake this course, and to determine what level of language, literacy and numeracy additional support may be needed for them to successfully complete the course.
This course moves quickly into hands-on technical training. It is suited to individuals pursuing a highly technical career in IT and cyber security.
This course gives learners access to information that has the potential for misuse within a simulated environment to mitigate any risks. Learners entering this course must demonstrate sufficient maturity to understand the importance of legal requirements, ethical protocols, and the consequences of misuse.
Learners are required to read and interpret object-oriented programming language scripts requiring a high level of logic and interpretation, and to comprehend and follow directions while working in complex subject matter, such as networks and IT infrastructure. They must have sufficient writing skills to prepare written reports of vulnerability findings using technical language.