Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

IT auditortoICT resilience manager

A IT auditor already meets 24% of what the ICT resilience manager role asks for. The move turns on 14 required skills not yet in the profile.

From IT auditor
24%
Overlap1
To ICT resilience manager
8 Skills carried over
14 Required, not held
76.8 Difficulty2
Career overlap Distant match

24%

Learning distance A rebuild

76.8/ 100

1 Share of the ICT resilience manager role’s weighted skill requirement already met by the IT auditor profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Why

Why this move works

A ICT resilience manager role treats 6 of its required skills as things a IT auditor already does. These are the ones it depends on most.

  • cyber security
  • execute ICT audits
  • identify ICT security risks
  • manage IT security compliances
  • organisational resilience
  • perform ICT security testing

What stands in the way is 14 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.

Table 2

Table 2 · What you already bring

Of the 8 skills that carry over, these are the ones fewest other occupations ask for. A ICT resilience manager role needs them, and most people applying for one will not have them already. This is the part of a IT auditor background worth leading with.

Skill the target role also needs Area
  • already held perform ICT security testing working with computers
  • already held identify ICT security risks information skills
  • already held manage IT security compliances working with computers
  • already held organisational resilience business, administration and law
  • already held ICT network security risks information and communication technologies (icts)
  • already held ICT process quality models information and communication technologies (icts)

All 8 carried skills, including the 6 the ICT resilience manager role treats as required.

Table 3

Table 3 · What you would need to learn

The 34 missing skills fall into 8 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 management skills 3 required, 5 supplementary
  • required, not held develop contingency plans for emergencies required
  • required, not held lead disaster recovery exercises required
  • required, not held manage disaster recovery plans required
  • optional, not held coordinate technological activities optional
  • optional, not held define security policies optional
  • optional, not held implement a management system optional
  • optional, not held manage budgets optional
  • optional, not held perform project management optional
02 information skills 3 required, 2 supplementary
  • required, not held implement ICT risk management required
  • required, not held analyse business processes required
  • required, not held analyse the context of an organisation required
  • optional, not held analyse business requirements optional
  • optional, not held provide cost benefit analysis reports optional
03 information and communication technologies (icts) 2 required, 5 supplementary
  • required, not held ICT recovery techniques required
  • required, not held system backup best practice required
  • optional, not held ICT system user requirements optional
  • optional, not held cloud security and compliance optional
  • optional, not held core banking software optional
  • optional, not held ethical hacking principles optional
  • optional, not held human-computer interaction optional
04 working with computers 2 required, 2 supplementary
  • required, not held implement ICT recovery system required
  • required, not held manage system security required
  • optional, not held ICT safety optional
  • optional, not held manage keys for data protection optional
05 assisting and caring 2 required
  • required, not held develop information security strategy required
  • required, not held comply with legal regulations required
06 business, administration and law 1 required, 1 supplementary
  • required, not held internal risk management policy required
  • optional, not held business process modelling optional

2 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a ICT resilience manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 8 skills that carry over
Skill Type
  • already held cyber security knowledge
  • already held execute ICT audits skill
  • already held identify ICT security risks skill
  • already held manage IT security compliances skill
  • already held organisational resilience knowledge
  • already held perform ICT security testing skill
  • already held ICT network security risks knowledge
  • already held ICT process quality models knowledge
The 2 learning areas not shown above
Skill to acquire Tier
07 engineering, manufacturing and construction 1 required
  • required, not held security engineering required
08 communication, collaboration and creativity 5 supplementary
  • optional, not held advise on strengthening security optional
  • optional, not held respond to incidents in cloud optional
  • optional, not held build business relationships optional
  • optional, not held perform procurement processes optional
  • optional, not held train employees optional
20 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held ICT safety optional
  • optional, not held ICT system user requirements optional
  • optional, not held advise on strengthening security optional
  • optional, not held business process modelling optional
  • optional, not held cloud security and compliance optional
  • optional, not held coordinate technological activities optional
  • optional, not held core banking software optional
  • optional, not held define security policies optional
  • optional, not held ethical hacking principles optional
  • optional, not held human-computer interaction optional
  • optional, not held manage keys for data protection optional
  • optional, not held respond to incidents in cloud optional
  • optional, not held analyse business requirements optional
  • optional, not held build business relationships optional
  • optional, not held implement a management system optional
  • optional, not held manage budgets optional
  • optional, not held perform procurement processes optional
  • optional, not held perform project management optional
  • optional, not held provide cost benefit analysis reports optional
  • optional, not held train employees optional
29 held skills the ICT resilience manager role does not ask for
Skill Type
  • not needed by the target role ICT accessibility standards knowledge
  • not needed by the target role ICT project management knowledge
  • not needed by the target role ICT quality policy knowledge
  • not needed by the target role ICT security legislation knowledge
  • not needed by the target role ICT security standards knowledge
  • not needed by the target role World Wide Web Consortium standards knowledge
  • not needed by the target role analyse ICT system skill
  • not needed by the target role apply information security policies skill
  • not needed by the target role audit techniques knowledge
  • not needed by the target role cloud technologies knowledge
  • not needed by the target role communicate analytical insights skill
  • not needed by the target role define organisational standards skill
  • not needed by the target role develop ICT workflow skill
  • not needed by the target role develop audit plan skill
  • not needed by the target role develop documentation in accordance with legal requirements skill
  • not needed by the target role engineering processes knowledge
  • not needed by the target role ensure adherence to organisational ICT standards skill
  • not needed by the target role identify legal requirements skill
  • not needed by the target role improve business processes skill
  • not needed by the target role inform on workplace safety standards skill
  • not needed by the target role information security strategy knowledge
  • not needed by the target role legal requirements of ICT products knowledge
  • not needed by the target role monitor technology trends skill
  • not needed by the target role perform quality audits skill
  • not needed by the target role prepare financial auditing reports skill
  • not needed by the target role product life-cycle knowledge
  • not needed by the target role protect personal data and privacy skill
  • not needed by the target role quality standards knowledge
  • not needed by the target role systems development life-cycle knowledge
10 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held ICT recovery techniques required
  • required, not held internal risk management policy required
  • required, not held security engineering required
  • required, not held system backup best practice required
  • optional, not held ICT system user requirements optional
  • optional, not held business process modelling optional
  • optional, not held cloud security and compliance optional
  • optional, not held core banking software optional
  • optional, not held ethical hacking principles optional
  • optional, not held human-computer interaction optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.