data protection officertochief ICT security officer
A data protection officer already meets 24% of what the chief ICT security officer role asks for. The move turns on 35 required skills not yet in the profile.
24%
84.3/ 100
1 Share of the chief ICT security officer role’s weighted skill requirement already met by the data protection officer profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A chief ICT security officer role treats 12 of its required skills as things a data protection officer already does. These are the ones it depends on most.
- ICT security legislation
- ICT security standards
- cyber security
- data protection
- develop information security strategy
- ensure compliance with legal requirements
What stands in the way is 35 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 18 skills that carry over, these are the ones fewest other occupations ask for. A chief ICT security officer role needs them, and most people applying for one will not have them already. This is the part of a data protection officer background worth leading with.
- already held conduct impact evaluation of ICT processes on business information skills
- already held manage digital identity core skills and competences
- already held ensure information privacy assisting and caring
- already held manage keys for data protection working with computers
- already held develop information security strategy assisting and caring
- already held internal risk management policy business, administration and law
All 18 carried skills, including the 12 the chief ICT security officer role treats as required.
Table 3 · What you would need to learn
The 63 missing skills fall into 11 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ICT network security risks required
- required, not held ICT process quality models required
- required, not held attack vectors required
- required, not held decision support systems required
- required, not held ethical hacking principles required
- required, not held assessment of risks and threats required
- optional, not held ICT encryption optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held cloud technologies optional
- optional, not held computer forensics optional
- optional, not held internet governance optional
- optional, not held software anomalies optional
- optional, not held web application security threats optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- required, not held advice on security risk management required
- required, not held identify ICT security risks required
- required, not held implement ICT risk management required
- required, not held forecast organisational risks required
- required, not held monitor developments in field of expertise required
- required, not held monitor technology trends required
- optional, not held execute ICT audits optional
- optional, not held implement cloud security and compliance optional
- required, not held implement corporate governance required
- required, not held communicate with stakeholders required
- required, not held educate on data confidentiality required
- required, not held engage with stakeholders required
- required, not held ensure cross-department cooperation required
- optional, not held create solutions to problems optional
- optional, not held use different communication channels optional
- required, not held ICT safety required
- required, not held manage IT security compliances required
- required, not held manage system security required
- required, not held utilise decision support system required
- optional, not held implement a firewall optional
- optional, not held implement a virtual private network optional
- optional, not held implement anti-virus software optional
- optional, not held optimise choice of ICT solution optional
- required, not held establish an ICT security prevention plan required
- required, not held lead disaster recovery exercises required
- required, not held maintain plan for continuity of operations required
- required, not held manage disaster recovery plans required
- optional, not held assess ICT knowledge optional
- optional, not held coordinate technological activities optional
- optional, not held manage staff optional
- required, not held ICT project management required
- required, not held ICT project management methodologies required
- required, not held organisational resilience required
- required, not held audit techniques required
5 further areas in the appendix
Table 4 · Where to start
The 3 entries a chief ICT security officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 establish an ICT security prevention plan skill · occupation specific
- 02 ICT network security risks knowledge · sector specific
- 03 ICT process quality models knowledge · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 18 skills that carry over
- already held ICT security legislation knowledge
- already held ICT security standards knowledge
- already held cyber security knowledge
- already held data protection knowledge
- already held develop information security strategy skill
- already held ensure compliance with legal requirements skill
- already held ensure information privacy skill
- already held implement ICT security policies skill
- already held information confidentiality knowledge
- already held information security strategy knowledge
- already held internal risk management policy knowledge
- already held risk management knowledge
- already held conduct impact evaluation of ICT processes on business skill
- already held identify legal requirements skill
- already held manage digital identity skill
- already held manage keys for data protection skill
- already held protect personal data and privacy skill
- already held train employees skill
The 5 learning areas not shown above
- required, not held ensure adherence to organisational ICT standards required
- required, not held establish an Information Security Management System required
- required, not held comply with legal regulations required
- optional, not held apply operations for an ITIL-based environment optional
- required, not held security engineering required
- optional, not held ICT communications protocols optional
- optional, not held ICT infrastructure optional
- required, not held ethics required
- required, not held cyber attack counter-measures required
- optional, not held control objectives for information and related technology optional
28 supplementary skills, helpful but not required
- optional, not held apply operations for an ITIL-based environment optional
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT encryption optional
- optional, not held ICT infrastructure optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held assess ICT knowledge optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held cloud technologies optional
- optional, not held computer forensics optional
- optional, not held coordinate technological activities optional
- optional, not held execute ICT audits optional
- optional, not held implement a firewall optional
- optional, not held implement a virtual private network optional
- optional, not held implement anti-virus software optional
- optional, not held implement cloud security and compliance optional
- optional, not held internet governance optional
- optional, not held optimise choice of ICT solution optional
- optional, not held software anomalies optional
- optional, not held web application security threats optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- optional, not held create solutions to problems optional
- optional, not held manage staff optional
- optional, not held use different communication channels optional
31 held skills the chief ICT security officer role does not ask for
- not needed by the target role GDPR knowledge
- not needed by the target role address identified risks skill
- not needed by the target role advise on government policy compliance skill
- not needed by the target role analyse legal enforceability skill
- not needed by the target role apply information security policies skill
- not needed by the target role apply system organisational policies skill
- not needed by the target role assist with litigation matters skill
- not needed by the target role cooperate with colleagues skill
- not needed by the target role data ethics knowledge
- not needed by the target role define organisational standards skill
- not needed by the target role develop organisational policies skill
- not needed by the target role develop training programmes skill
- not needed by the target role document project progress skill
- not needed by the target role estimate impact of risks skill
- not needed by the target role information governance compliance knowledge
- not needed by the target role internal auditing knowledge
- not needed by the target role keep up-to-date with regulations skill
- not needed by the target role legal case management knowledge
- not needed by the target role legal research knowledge
- not needed by the target role legal terminology knowledge
- not needed by the target role maintain internal communication systems skill
- not needed by the target role manage data for legal matters skill
- not needed by the target role monitor legislation developments skill
- not needed by the target role perform data cleansing skill
- not needed by the target role perform project management skill
- not needed by the target role provide legal advice skill
- not needed by the target role respect data protection principles skill
- not needed by the target role respond to enquiries skill
- not needed by the target role support managers skill
- not needed by the target role use consulting techniques skill
- not needed by the target role write work-related reports skill
29 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT network security risks required
- required, not held ICT process quality models required
- required, not held ICT project management required
- required, not held ICT project management methodologies required
- required, not held attack vectors required
- required, not held cyber attack counter-measures required
- required, not held decision support systems required
- required, not held ethical hacking principles required
- required, not held organisational resilience required
- required, not held assessment of risks and threats required
- required, not held audit techniques required
- required, not held ethics required
- required, not held security engineering required
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT encryption optional
- optional, not held ICT infrastructure optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held cloud technologies optional
- optional, not held computer forensics optional
- optional, not held internet governance optional
- optional, not held software anomalies optional
- optional, not held web application security threats optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
Other moves recorded from data protection officer
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.