cybersecurity risk managertochief ICT security officer
A cybersecurity risk manager already meets 63% of what the chief ICT security officer role asks for. The move turns on 15 required skills not yet in the profile.
This move: 53.5 of 100 · moderate
1 Share of the chief ICT security officer role’s weighted skill requirement already met by the cybersecurity risk manager profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Table 2 · What you already bring
Of the 47 skills that carry over, these are the ones fewest other occupations ask for. A chief ICT security officer role needs them, and most people applying for one will not have them already. This is the part of a cybersecurity risk manager background worth leading with.
- already held establish an Information Security Management System assisting and caring
- already held establish an ICT security prevention plan management skills
- already held advice on security risk management information skills
- already held computer forensics information and communication technologies (icts)
- already held engage with stakeholders communication, collaboration and creativity
- already held lead disaster recovery exercises management skills
All 47 carried skills, including the 32 the chief ICT security officer role treats as required.
Table 3 · What you would need to learn
The 34 missing skills fall into 11 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held implement corporate governance required
- required, not held educate on data confidentiality required
- required, not held ensure cross-department cooperation required
- optional, not held create solutions to problems optional
- optional, not held train employees optional
- optional, not held use different communication channels optional
- required, not held ensure information privacy required
- required, not held comply with legal regulations required
- required, not held ensure compliance with legal requirements required
- optional, not held apply operations for an ITIL-based environment optional
- optional, not held protect personal data and privacy optional
- required, not held forecast organisational risks required
- required, not held monitor developments in field of expertise required
- required, not held monitor technology trends required
- optional, not held conduct impact evaluation of ICT processes on business optional
- optional, not held identify legal requirements optional
- required, not held manage IT security compliances required
- required, not held utilise decision support system required
- optional, not held optimise choice of ICT solution optional
- required, not held data protection required
- optional, not held cloud technologies optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- required, not held maintain plan for continuity of operations required
- optional, not held assess ICT knowledge optional
- optional, not held coordinate technological activities optional
- optional, not held manage staff optional
5 further areas in the appendix
Table 4 · Where to start
The 3 entries a chief ICT security officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 ICT project management methodologies knowledge · sector specific
- 02 data protection knowledge · sector specific
- 03 ensure information privacy skill · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 47 skills that carry over
- already held ICT network security risks knowledge
- already held ICT process quality models knowledge
- already held ICT project management knowledge
- already held ICT safety skill
- already held ICT security legislation knowledge
- already held ICT security standards knowledge
- already held advice on security risk management skill
- already held assessment of risks and threats knowledge
- already held attack vectors knowledge
- already held audit techniques knowledge
- already held communicate with stakeholders skill
- already held cyber attack counter-measures knowledge
- already held cyber security knowledge
- already held decision support systems knowledge
- already held develop information security strategy skill
- already held engage with stakeholders skill
- already held ensure adherence to organisational ICT standards skill
- already held establish an ICT security prevention plan skill
- already held establish an Information Security Management System skill
- already held ethical hacking principles knowledge
- already held identify ICT security risks skill
- already held implement ICT risk management skill
- already held implement ICT security policies skill
- already held information confidentiality knowledge
- already held information security strategy knowledge
- already held internal risk management policy knowledge
- already held lead disaster recovery exercises skill
- already held manage disaster recovery plans skill
- already held manage system security skill
- already held organisational resilience knowledge
- already held risk management knowledge
- already held security engineering knowledge
- already held ICT encryption knowledge
- already held ICT recovery techniques knowledge
- already held ICT system user requirements knowledge
- already held Internet of Things knowledge
- already held cloud monitoring and reporting knowledge
- already held cloud security and compliance knowledge
- already held computer forensics knowledge
- already held execute ICT audits skill
- already held implement a firewall skill
- already held implement a virtual private network skill
- already held implement anti-virus software skill
- already held implement cloud security and compliance skill
- already held internet governance knowledge
- already held manage keys for data protection skill
- already held web application security threats knowledge
The 5 learning areas not shown above
- required, not held ethics required
- required, not held ICT project management methodologies required
- optional, not held ICT communications protocols optional
- optional, not held ICT infrastructure optional
- optional, not held manage digital identity optional
- optional, not held control objectives for information and related technology optional
19 supplementary skills, helpful but not required
- optional, not held apply operations for an ITIL-based environment optional
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT infrastructure optional
- optional, not held assess ICT knowledge optional
- optional, not held cloud technologies optional
- optional, not held coordinate technological activities optional
- optional, not held optimise choice of ICT solution optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- optional, not held conduct impact evaluation of ICT processes on business optional
- optional, not held create solutions to problems optional
- optional, not held identify legal requirements optional
- optional, not held manage digital identity optional
- optional, not held manage staff optional
- optional, not held protect personal data and privacy optional
- optional, not held train employees optional
- optional, not held use different communication channels optional
25 held skills the chief ICT security officer role does not ask for
- not needed by the target role ICT performance analysis methods knowledge
- not needed by the target role ICT problem management techniques knowledge
- not needed by the target role ICT quality policy knowledge
- not needed by the target role Open source model knowledge
- not needed by the target role Outsourcing model knowledge
- not needed by the target role define security policies skill
- not needed by the target role define technology strategy skill
- not needed by the target role design for organisational complexity skill
- not needed by the target role develop with cloud services skill
- not needed by the target role domain name service knowledge
- not needed by the target role hybrid model knowledge
- not needed by the target role implement spam protection skill
- not needed by the target role investment analysis knowledge
- not needed by the target role legal requirements of ICT products knowledge
- not needed by the target role levels of software testing knowledge
- not needed by the target role mobile device management knowledge
- not needed by the target role remove computer virus or malware from a computer skill
- not needed by the target role security threats knowledge
- not needed by the target role service-oriented modelling knowledge
- not needed by the target role solve ICT system problems skill
- not needed by the target role systems development life-cycle knowledge
- not needed by the target role tools for ICT test automation knowledge
- not needed by the target role use ICT ticketing system skill
- not needed by the target role use an application-specific interface skill
- not needed by the target role use back-up and recovery tools skill
10 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT project management methodologies required
- required, not held data protection required
- required, not held ethics required
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT infrastructure optional
- optional, not held cloud technologies optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
Other moves recorded from cybersecurity risk manager
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.