ICT security administratortochief ICT security officer
A ICT security administrator already meets 34% of what the chief ICT security officer role asks for. The move turns on 33 required skills not yet in the profile.
34%
77.4/ 100
1 Share of the chief ICT security officer role’s weighted skill requirement already met by the ICT security administrator profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A chief ICT security officer role treats 14 of its required skills as things a ICT security administrator already does. These are the ones it depends on most.
- ICT network security risks
- ICT safety
- ICT security legislation
- ICT security standards
- cyber attack counter-measures
- cyber security
What stands in the way is 33 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 31 skills that carry over, these are the ones fewest other occupations ask for. A chief ICT security officer role needs them, and most people applying for one will not have them already. This is the part of a ICT security administrator background worth leading with.
- already held computer forensics information and communication technologies (icts)
- already held lead disaster recovery exercises management skills
- already held web application security threats information and communication technologies (icts)
- already held ICT safety working with computers
- already held ethical hacking principles information and communication technologies (icts)
- already held implement cloud security and compliance information skills
All 31 carried skills, including the 14 the chief ICT security officer role treats as required.
Table 3 · What you would need to learn
The 50 missing skills fall into 11 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held advice on security risk management required
- required, not held identify ICT security risks required
- required, not held implement ICT risk management required
- required, not held forecast organisational risks required
- required, not held monitor developments in field of expertise required
- required, not held monitor technology trends required
- optional, not held conduct impact evaluation of ICT processes on business optional
- optional, not held identify legal requirements optional
- required, not held develop information security strategy required
- required, not held ensure adherence to organisational ICT standards required
- required, not held ensure information privacy required
- required, not held establish an Information Security Management System required
- required, not held comply with legal regulations required
- required, not held ensure compliance with legal requirements required
- optional, not held apply operations for an ITIL-based environment optional
- required, not held ICT process quality models required
- required, not held attack vectors required
- required, not held data protection required
- required, not held decision support systems required
- required, not held assessment of risks and threats required
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held cloud technologies optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- required, not held implement corporate governance required
- required, not held communicate with stakeholders required
- required, not held educate on data confidentiality required
- required, not held engage with stakeholders required
- required, not held ensure cross-department cooperation required
- optional, not held create solutions to problems optional
- optional, not held use different communication channels optional
- required, not held ICT project management required
- required, not held ICT project management methodologies required
- required, not held internal risk management policy required
- required, not held audit techniques required
- required, not held risk management required
- required, not held establish an ICT security prevention plan required
- required, not held maintain plan for continuity of operations required
- required, not held manage disaster recovery plans required
- optional, not held coordinate technological activities optional
- optional, not held manage staff optional
5 further areas in the appendix
Table 4 · Where to start
The 3 entries a chief ICT security officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 establish an ICT security prevention plan skill · occupation specific
- 02 ICT process quality models knowledge · sector specific
- 03 ICT project management knowledge · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 31 skills that carry over
- already held ICT network security risks knowledge
- already held ICT safety skill
- already held ICT security legislation knowledge
- already held ICT security standards knowledge
- already held cyber attack counter-measures knowledge
- already held cyber security knowledge
- already held ethical hacking principles knowledge
- already held implement ICT security policies skill
- already held information confidentiality knowledge
- already held information security strategy knowledge
- already held lead disaster recovery exercises skill
- already held manage IT security compliances skill
- already held organisational resilience knowledge
- already held security engineering knowledge
- already held ICT encryption knowledge
- already held ICT infrastructure knowledge
- already held Internet of Things knowledge
- already held assess ICT knowledge skill
- already held cloud monitoring and reporting knowledge
- already held cloud security and compliance knowledge
- already held computer forensics knowledge
- already held execute ICT audits skill
- already held implement a firewall skill
- already held implement a virtual private network skill
- already held implement anti-virus software skill
- already held implement cloud security and compliance skill
- already held internet governance knowledge
- already held manage keys for data protection skill
- already held protect personal data and privacy skill
- already held train employees skill
- already held web application security threats knowledge
The 5 learning areas not shown above
- required, not held manage system security required
- required, not held utilise decision support system required
- optional, not held optimise choice of ICT solution optional
- required, not held ethics required
- optional, not held manage digital identity optional
- optional, not held ICT communications protocols optional
- optional, not held control objectives for information and related technology optional
17 supplementary skills, helpful but not required
- optional, not held apply operations for an ITIL-based environment optional
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held cloud technologies optional
- optional, not held coordinate technological activities optional
- optional, not held optimise choice of ICT solution optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
- optional, not held conduct impact evaluation of ICT processes on business optional
- optional, not held create solutions to problems optional
- optional, not held identify legal requirements optional
- optional, not held manage digital identity optional
- optional, not held manage staff optional
- optional, not held use different communication channels optional
28 held skills the chief ICT security officer role does not ask for
- not needed by the target role address problems critically skill
- not needed by the target role apply company policies skill
- not needed by the target role attend to ICT systems quality skill
- not needed by the target role build business relationships skill
- not needed by the target role database development tools knowledge
- not needed by the target role ensure proper document management skill
- not needed by the target role execute software tests skill
- not needed by the target role identify ICT system weaknesses skill
- not needed by the target role interpret technical texts skill
- not needed by the target role maintain ICT identity management skill
- not needed by the target role maintain database security skill
- not needed by the target role manage ICT data architecture skill
- not needed by the target role manage ICT virtualisation environments skill
- not needed by the target role manage cloud data and storage skill
- not needed by the target role manage database skill
- not needed by the target role mobile device management knowledge
- not needed by the target role network standards knowledge
- not needed by the target role operating systems knowledge
- not needed by the target role perform ICT troubleshooting skill
- not needed by the target role perform backups skill
- not needed by the target role quality assurance methodologies knowledge
- not needed by the target role remove computer virus or malware from a computer skill
- not needed by the target role respond to incidents in cloud skill
- not needed by the target role solve ICT system problems skill
- not needed by the target role store digital data and systems skill
- not needed by the target role system backup best practice knowledge
- not needed by the target role telecom regulations knowledge
- not needed by the target role use scripting programming skill
19 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT process quality models required
- required, not held ICT project management required
- required, not held ICT project management methodologies required
- required, not held attack vectors required
- required, not held data protection required
- required, not held decision support systems required
- required, not held internal risk management policy required
- required, not held assessment of risks and threats required
- required, not held audit techniques required
- required, not held ethics required
- required, not held risk management required
- optional, not held control objectives for information and related technology optional
- optional, not held ICT communications protocols optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held cloud technologies optional
- optional, not held software anomalies optional
- optional, not held World Wide Web Consortium standards optional
- optional, not held computer programming optional
Other moves recorded from ICT security administrator
- director of compliance and information security 50% covered · moderate
- ethical hacker 42% covered · substantial
- cybersecurity risk manager 39% covered · substantial
- cyber incident responder 36% covered · substantial
- ICT resilience manager 35% covered · substantial
- ICT system administrator 35% covered · substantial
- embedded systems security engineer 33% covered · substantial
- cloud engineer 32% covered · career change
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.