of cloud
Assessment 2
Manage information security compliance of cloud service deployment 3
Introduction 8
Assessment 2: Project Portfolio 9
Assessment 2: Checklist 13

Assessment Information
Welcome to your Assessment 2 for Cloud Computing Solutions.

Unit of Competency
ICTCLD602 Manage information security compliance of cloud service
ICTPRG614 Create cloud computing services

Student Instructions
Before you commence your Assessment, ensure that you have good
knowledge of the subject, have thoroughly read your Learner workbook, and
clearly understand the Assessment requirements and the expectations of the
You may be required to demonstrate knowledge and skills which may be
difficult for the Assessor to witness. If so, an Evidence Record is supplied which
will allow the knowledge or skill to be verified by at least one third party, and
preferably two or more. These witnesses would usually be current or recent
supervisors or your Assessor.
Explanations are given for each Task. If you have any questions, consult with
your Assessor.
The assessment tasks may be answered using your business, the simulated
business or a mixture of both as instructed by your Assessor.
When you are confident that you have met all requirements for this assessment
task, upload your file using your file using Learning Management System (LMS) for
For the due date of the assessments follow the instructions of your facilitator.
Assessment Conditions
All assessment in this subject/units must be completed in the class under the
supervision of your facilitator. Once completed the assessments are to be uploaded
on LMS
( in individual student profile for marking.
All assessments must be attempted
All questions must be answered in an appropriate manner as per the
Follow the Assessor’s instructions to complete the assessments
Use appropriate referencing where applicable. You are required to use APA
referencing style.
Assessment Grading
Individual assessments are to be marked as “Satisfactory” or “Not Yet satisfactory”. The
final outcome of this subject/unit is to be recorded in “Unit outcome Record” as
“competent” (C) or “Not Yet Competent” (NYC) and/or in LMS. In order to be
competent in a given unit of competency the student must satisfactorily complete all
assessment tasks and. If more than one unit of competency are clustered to form a
subject, the students are still required to attempt all assessments.

These instructions must be followed when assessing the student in this unit. The
checklist on the following page is to be completed for each student. Please refer to
separate mapping document for specific details relating to alignment of this task to the
unit requirements.
This competency is to be assessed using standard and authorised work practices, safety
requirements and environmental constraints.
Assessment of essential underpinning knowledge will usually be conducted in an off-site
Assessment is to comply with relevant regulatory or Australian standards’ requirements.
Reasonable adjustments for people with disabilities must be made to assessment
processes where required. This could include access to modified equipment and other
physical resources, and the provision of appropriate assessment support

“I understand all the above rules and guidelines for the assessment

Full Name Signature Date (dd/mm/yyyy)

Pre-assessment Checklist
Your assessor will go through the assessment for this unit. It is important that you understand this
assessment before taking on the questions and tasks. To confirm that you have been given this
overview, we ask you to complete the following Pre-Assessment Checklist.
You are required to carefully read each checklist item provided below and tick either ‘Y’ to confirm
your understanding or ‘N’ if you disagree. In case you disagree with an item, please provide your
reason under the ‘Comments’ column.
When you have done this, we ask you to sign this Pre-Assessment Checklist. This acknowledges
that your Trainer/Assessor has discussed all of the information with you prior to undertaking this

Pre – assessment Checklist Comments
Y N I, the student, understand the purpose of the
Y N I understand when and where the assessment will
occur, who will assess and in what format the
assessment will be submitted.
Y N I understand the methods of assessment.
Y N I understand what resources are required to
complete this assessment.
Y N I understand the performance level required for
each assessment event.
Y N I understand that it must be my own work. I have
been explained and understand the serious
consequences in case this work is found
Y N I understand the process if I am deemed not yet
Y N I understand the feedback process and the appeals
Y N The assessor has discussed with me if I have any
special needs and if so what arrangements have
been made.


Full Name
Student ID Student

The assessment tasks for Cloud computing Solutions are outlined in the assessment plan
below. These tasks have been designed to help you demonstrate the skills and knowledge
that you have learnt during your course.
Please ensure that you read the instructions provided with these tasks carefully. You should
also follow the advice provided in the
IT Works Student User Guide. The Student User Guide
provides important information for you relating to completing assessment successfully.
Assessment for this unit
Cloud Computing Solutions describes the performance outcomes, skills and knowledge to
manage cloud security controls, privacy and legal compliance when implementing cloud
services for an enterprise.
For you to be assessed as competent, you must successfully complete two assessment tasks:
Assessment Task 1: Knowledge questions – You must answer all questions correctly.
Assessment Task 2 ( this assessment): Project – You must work through a range of tasks
and complete a project portfolio.
Assessment Task 3 Project – You must work through a range of tasks and complete a
project portfolio.
Assessment 2: Project Portfolio
Information for students
In this task, you are required to demonstrate your skills and knowledge by working through a
number of activities and completing and submitting a project portfolio.
You will need access to:
a suitable place to complete activities that replicates an ICT environment including a
computer and internet access
Unit Simulation Pack or access to business specifications in relation to cloud security and
enterprise security policies, as well as WHS requirements
security environment information including legislation and expertise
risk analysis tools and methodologies
your learning resources and other information for reference
Project Portfolio template.
Ensure that you:
review the advice to students regarding responding to written tasks in the IT Works
Student User Guide
comply with the due date for assessment which your assessor will provide
adhere with the submission guidelines
answer all questions completely and correctly
submit work which is original and, where necessary, properly referenced
submit a completed cover sheet with your work
avoid sharing your answers with other students.

Assessment information
Information about how you should complete this assessment can be found in
Appendix A of the
IT Works Student User Guide. Refer to the appendix for
information on:
where this task should be completed
how your assessment should be submitted.
Note: You must complete and submit an assessment cover sheet with your work. A
template is provided in Appendix B of the Student User Guide. However, if your
RTO has provided you with an assessment cover sheet, please ensure that you use

Complete the following activities:
1. Carefully read the following:

This assessment task requires you to identify security risks relevant to cloud
services and then manage cloud security controls. This project can be based
on the case study business in the ICT simulation pack or you may like to base
this on your own business, or a business you are currently working for or are
familiar with. It is important that you can access a range of information relevant
to cloud security as indicated on the previous page. Speak to your assessor to
get approval if you want to base this on your own business or one you work for.
You will be collecting evidence for this unit in a Project Portfolio. The steps you
need to take are outlined below.

2. Planning

Make sure you are familiar with the business you are basing this assessment on
and have read through the necessary background information, Strategic Plan
and policies and procedures. For the case study business, this is all of the
documents included in the ICT simulation pack. If it’s your own business or a
business where you are working or are familiar with, it’s important at this step
that you have your business or case study approved by your assessor.
Page 4 of your Project Portfolio for this unit.
Read through the requirements of
Section 1, 2 and 3 of your Project Portfolio.

3. Cloud services security risks and controls

You are now to complete Section 1 of your Project Portfolio.
When you complete Section 1, you need to:
Identify the range of cloud security risks that apply to different cloud
Identify and review the business’ requirements for the cloud services, as
well as legal, privacy and contractual issues.
Investigate the cloud services vendor including:
o Their responsibilities and the business’
o Compliance and security controls for the cloud services
o Risks that apply to the vendor and risks that apply to the organisation
Configure and document the security controls for cloud services in order to
mitigate risk

4. Cloud privacy compliance

You are now to complete Section 2 of your Project Portfolio.
When you complete Section 2, you need to:
Determine how you will ensure business continuity and build in data
recovery to the cloud service and implement these requirements
Review the suitability of user access policies and configuration to data
Complete a check on controls and maintain a record.

5. Cloud security compliance enhancements

You are now to complete Section 3 of your Project Portfolio.
When you complete Section 3, you need to:
Update the risk register and business continuity plans based on the
security enhancements you have made.
Evaluate security effectiveness by assessing security controls against
prescribed benchmarks.
In the next activity you will present all of the work you have completed to a
small group of students in order to obtain sign off of your work. Present your
work using a PowerPoint Presentation and attach it to your Portfolio.

6. Round table discussion

In a group round-table style discussion with a student group of approximately
four or five, you will present how you have managed the information security
compliance of the cloud service. You are to assume that you are presenting
your results to management.
Each person will have a turn (10 minutes per person) to talk about their work as
per their project portfolio.
Other members of the group are to provide their feedback and approval of
Your assessor will be looking to see that you can present you work as
documented in your Project Portfolio and as per the presentation you have
developed. You must ensure that you present your work in such asway that
technical terminology can be understood by all.
During the roundtable discussion, you are to:
demonstrate effective communication skills including:
o Speaking clearly and concisely
o Using non-verbal communication to assist with understanding
o Asking questions to identify required information

o Responding to questions as required
o Using active listening techniques to confirm understanding


This can either be viewed in person by your assessor or you may like to video
record the session for your assessor to watch later. Your assessor can provide
you with more details at this step. Make sure you follow the instructions above
and meet the timeframes allocated.

7. Submit your completed Project Portfolio

Make sure you have completed all sections of your Project Portfolio, answered
all questions, provided enough detail as indicated and proofread for spelling
and grammar as necessary.
Submit to your assessor for marking.

Assessment 2: Checklist

Student’s name: SID:
Did the student: Completed
Yes No
Identify and describe cloud security
risks for different cloud delivery and
deployment models?
Identify, review and document legal,
privacy and contractual issues related
to cloud security, as well as business
policies and procedures and
Map responsibilities between the
business and cloud vendor?
Review and discuss the compliance
controls of cloud vendor?
Identify and describe risks relating to
cloud security that are the business’
Identify and document security
controls provided by the cloud vendor
for the cloud service?
Map security controls to the business’
Configure security controls in order to
mitigate risk as per the business’
Document the configuration of security
control and risk mitigation?
Identify and document the required
data storage compliance regulations?
Determine and document data privacy
risks associated with the cloud

Determine business continuity and
data recovery plan requirements?
Implement business continuity and
data recovery plan to meet
Review and document user access
policies and configuration to data?
Identify, secure and maintain, logs and
audit trails?
Document data privacy risk mitigation?
Implement and integrate required
changes to security into the risk
register and business continuity plans?
Establish and document a
performance measurement program?
Evaluate security effectiveness of
implemented security controls based
on performance measures?
Submit the required documentation
changes for security controls to
required personnel (assessor)?
Obtain final task sign off?
Articulates requirements clearly using
effective communication skills?
Articulates requirements clearly using
effective communication skills?
Use industry standard technical
language to explain concepts to
audience and in a way they can
Task outcome: Satisfactory Not satisfactory
Assessor signature:
Assessor name:

