ICT auditor managertoIT auditor
A ICT auditor manager already meets 61% of what the IT auditor role asks for. The move turns on 6 required skills not yet in the profile.
61%
44/ 100
1 Share of the IT auditor role’s weighted skill requirement already met by the ICT auditor manager profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A IT auditor role treats 13 of its required skills as things a ICT auditor manager already does. These are the ones it depends on most.
- ICT process quality models
- ICT quality policy
- ICT security legislation
- ICT security standards
- audit techniques
- develop audit plan
What stands in the way is 6 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 20 skills that carry over, these are the ones fewest other occupations ask for. A IT auditor role needs them, and most people applying for one will not have them already. This is the part of a ICT auditor manager background worth leading with.
- already held develop audit plan management skills
- already held ICT quality policy business, administration and law
- already held develop ICT workflow management skills
- already held ensure adherence to organisational ICT standards assisting and caring
- already held identify legal requirements information skills
- already held manage IT security compliances working with computers
All 20 carried skills, including the 13 the IT auditor role treats as required.
Table 3 · What you would need to learn
The 17 missing skills fall into 8 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held improve business processes required
- required, not held perform quality audits required
- optional, not held define organisational standards optional
- required, not held analyse ICT system required
- required, not held perform ICT security testing required
- required, not held product life-cycle required
- required, not held engineering processes required
- optional, not held ICT accessibility standards optional
- optional, not held ICT network security risks optional
- optional, not held information security strategy optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held communicate analytical insights optional
- optional, not held develop documentation in accordance with legal requirements optional
- optional, not held inform on workplace safety standards optional
2 further areas in the appendix
Table 4 · Where to start
The 3 entries a IT auditor role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 analyse ICT system skill · sector specific
- 02 engineering processes knowledge · sector specific
- 03 perform ICT security testing skill · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 20 skills that carry over
- already held ICT process quality models knowledge
- already held ICT quality policy knowledge
- already held ICT security legislation knowledge
- already held ICT security standards knowledge
- already held audit techniques knowledge
- already held develop audit plan skill
- already held ensure adherence to organisational ICT standards skill
- already held execute ICT audits skill
- already held legal requirements of ICT products knowledge
- already held organisational resilience knowledge
- already held prepare financial auditing reports skill
- already held quality standards knowledge
- already held systems development life-cycle knowledge
- already held ICT project management knowledge
- already held cloud technologies knowledge
- already held cyber security knowledge
- already held develop ICT workflow skill
- already held identify legal requirements skill
- already held manage IT security compliances skill
- already held monitor technology trends skill
The 2 learning areas not shown above
- optional, not held apply information security policies optional
- optional, not held protect personal data and privacy optional
- optional, not held identify ICT security risks optional
11 supplementary skills, helpful but not required
- optional, not held ICT accessibility standards optional
- optional, not held ICT network security risks optional
- optional, not held apply information security policies optional
- optional, not held communicate analytical insights optional
- optional, not held identify ICT security risks optional
- optional, not held information security strategy optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held define organisational standards optional
- optional, not held develop documentation in accordance with legal requirements optional
- optional, not held inform on workplace safety standards optional
- optional, not held protect personal data and privacy optional
22 held skills the IT auditor role does not ask for
- not needed by the target role AJAX knowledge
- not needed by the target role JavaScript knowledge
- not needed by the target role PHP knowledge
- not needed by the target role attack vectors knowledge
- not needed by the target role build business relationships skill
- not needed by the target role coach employees skill
- not needed by the target role control objectives for information and related technology knowledge
- not needed by the target role develop ICT test suite skill
- not needed by the target role develop information security strategy skill
- not needed by the target role ensure compliance with legal requirements skill
- not needed by the target role ensure information privacy skill
- not needed by the target role implement ICT risk management skill
- not needed by the target role implement ICT security policies skill
- not needed by the target role implement corporate governance skill
- not needed by the target role information confidentiality knowledge
- not needed by the target role information structure knowledge
- not needed by the target role manage changes in ICT system skill
- not needed by the target role manage standard enterprise resource planning system skill
- not needed by the target role perform contract compliance audits skill
- not needed by the target role train employees skill
- not needed by the target role use markup languages skill
- not needed by the target role web programming knowledge
6 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held engineering processes required
- required, not held product life-cycle required
- optional, not held ICT accessibility standards optional
- optional, not held ICT network security risks optional
- optional, not held information security strategy optional
- optional, not held World Wide Web Consortium standards optional
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.