Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

ICT auditor managertodata protection officer

A ICT auditor manager already meets 26% of what the data protection officer role asks for. The move turns on 23 required skills not yet in the profile.

From ICT auditor manager
26%
Overlap1
To data protection officer
10 Skills carried over
23 Required, not held
78.8 Difficulty2
adjacent 0–30
moderate 30–55
substantial 55–75
career change 75–100
this move, 78.8

This move: 78.8 of 100 · career change

1 Share of the data protection officer role’s weighted skill requirement already met by the ICT auditor manager profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Table 2

Table 2 · What you already bring

Of the 10 skills that carry over, these are the ones fewest other occupations ask for. A data protection officer role needs them, and most people applying for one will not have them already. This is the part of a ICT auditor manager background worth leading with.

Skill the target role also needs Area
  • already held ensure information privacy assisting and caring
  • already held develop information security strategy assisting and caring
  • already held identify legal requirements information skills
  • already held ICT security standards information and communication technologies (icts)
  • already held cyber security services
  • already held ICT security legislation business, administration and law

All 10 carried skills, including the 10 the data protection officer role treats as required.

Table 3

Table 3 · What you would need to learn

The 39 missing skills fall into 10 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 business, administration and law 5 required, 2 supplementary
  • required, not held GDPR required
  • required, not held internal risk management policy required
  • required, not held internal auditing required
  • required, not held legal research required
  • required, not held legal terminology required
  • optional, not held legal case management optional
  • optional, not held risk management optional
02 communication, collaboration and creativity 4 required, 5 supplementary
  • required, not held advise on government policy compliance required
  • required, not held cooperate with colleagues required
  • required, not held provide legal advice required
  • required, not held use consulting techniques required
  • optional, not held analyse legal enforceability optional
  • optional, not held assist with litigation matters optional
  • optional, not held maintain internal communication systems optional
  • optional, not held support managers optional
  • optional, not held write work-related reports optional
03 assisting and caring 4 required, 1 supplementary
  • required, not held apply information security policies required
  • required, not held respect data protection principles required
  • required, not held protect personal data and privacy required
  • required, not held respond to enquiries required
  • optional, not held apply system organisational policies optional
04 information skills 3 required, 4 supplementary
  • required, not held manage data for legal matters required
  • required, not held keep up-to-date with regulations required
  • required, not held monitor legislation developments required
  • optional, not held address identified risks optional
  • optional, not held estimate impact of risks optional
  • optional, not held conduct impact evaluation of ICT processes on business optional
  • optional, not held document project progress optional
05 management skills 3 required, 1 supplementary
  • required, not held develop training programmes required
  • required, not held define organisational standards required
  • required, not held develop organisational policies required
  • optional, not held perform project management optional
06 information and communication technologies (icts) 2 required
  • required, not held data protection required
  • required, not held information security strategy required

4 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a data protection officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 10 skills that carry over
Skill Type
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held cyber security knowledge
  • already held develop information security strategy skill
  • already held ensure compliance with legal requirements skill
  • already held ensure information privacy skill
  • already held identify legal requirements skill
  • already held implement ICT security policies skill
  • already held information confidentiality knowledge
  • already held train employees skill
The 4 learning areas not shown above
Skill to acquire Tier
07 arts and humanities 1 required
  • required, not held data ethics required
08 social sciences, journalism and information 1 required
  • required, not held information governance compliance required
09 working with computers 2 supplementary
  • optional, not held manage keys for data protection optional
  • optional, not held perform data cleansing optional
10 core skills and competences 1 supplementary
  • optional, not held manage digital identity optional
16 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held address identified risks optional
  • optional, not held estimate impact of risks optional
  • optional, not held manage keys for data protection optional
  • optional, not held analyse legal enforceability optional
  • optional, not held apply system organisational policies optional
  • optional, not held assist with litigation matters optional
  • optional, not held conduct impact evaluation of ICT processes on business optional
  • optional, not held document project progress optional
  • optional, not held legal case management optional
  • optional, not held maintain internal communication systems optional
  • optional, not held manage digital identity optional
  • optional, not held perform data cleansing optional
  • optional, not held perform project management optional
  • optional, not held risk management optional
  • optional, not held support managers optional
  • optional, not held write work-related reports optional
32 held skills the data protection officer role does not ask for
Skill Type
  • not needed by the target role AJAX knowledge
  • not needed by the target role ICT process quality models knowledge
  • not needed by the target role ICT project management knowledge
  • not needed by the target role ICT quality policy knowledge
  • not needed by the target role JavaScript knowledge
  • not needed by the target role PHP knowledge
  • not needed by the target role attack vectors knowledge
  • not needed by the target role audit techniques knowledge
  • not needed by the target role build business relationships skill
  • not needed by the target role cloud technologies knowledge
  • not needed by the target role coach employees skill
  • not needed by the target role control objectives for information and related technology knowledge
  • not needed by the target role develop ICT test suite skill
  • not needed by the target role develop ICT workflow skill
  • not needed by the target role develop audit plan skill
  • not needed by the target role ensure adherence to organisational ICT standards skill
  • not needed by the target role execute ICT audits skill
  • not needed by the target role implement ICT risk management skill
  • not needed by the target role implement corporate governance skill
  • not needed by the target role information structure knowledge
  • not needed by the target role legal requirements of ICT products knowledge
  • not needed by the target role manage IT security compliances skill
  • not needed by the target role manage changes in ICT system skill
  • not needed by the target role manage standard enterprise resource planning system skill
  • not needed by the target role monitor technology trends skill
  • not needed by the target role organisational resilience knowledge
  • not needed by the target role perform contract compliance audits skill
  • not needed by the target role prepare financial auditing reports skill
  • not needed by the target role quality standards knowledge
  • not needed by the target role systems development life-cycle knowledge
  • not needed by the target role use markup languages skill
  • not needed by the target role web programming knowledge
11 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held information governance compliance required
  • required, not held GDPR required
  • required, not held data protection required
  • required, not held information security strategy required
  • required, not held internal risk management policy required
  • required, not held data ethics required
  • required, not held internal auditing required
  • required, not held legal research required
  • required, not held legal terminology required
  • optional, not held legal case management optional
  • optional, not held risk management optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.