ICT system administratortocybersecurity risk manager
A ICT system administrator already meets 23% of what the cybersecurity risk manager role asks for. The move turns on 18 required skills not yet in the profile.
23%
82.3/ 100
1 Share of the cybersecurity risk manager role’s weighted skill requirement already met by the ICT system administrator profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A cybersecurity risk manager role treats 4 of its required skills as things a ICT system administrator already does. These are the ones it depends on most.
- implement ICT risk management
- information security strategy
- manage system security
- security engineering
What stands in the way is 18 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 19 skills that carry over, these are the ones fewest other occupations ask for. A cybersecurity risk manager role needs them, and most people applying for one will not have them already. This is the part of a ICT system administrator background worth leading with.
- already held domain name service information and communication technologies (icts)
- already held ICT recovery techniques information and communication technologies (icts)
- already held implement spam protection working with computers
- already held manage system security working with computers
- already held cloud monitoring and reporting information and communication technologies (icts)
- already held internet governance information and communication technologies (icts)
All 19 carried skills, including the 4 the cybersecurity risk manager role treats as required.
Table 3 · What you would need to learn
The 53 missing skills fall into 8 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ICT network security risks required
- required, not held ICT performance analysis methods required
- required, not held ICT security standards required
- required, not held attack vectors required
- required, not held ethical hacking principles required
- required, not held assessment of risks and threats required
- optional, not held ICT encryption optional
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held computer forensics optional
- optional, not held decision support systems optional
- optional, not held hybrid model optional
- optional, not held information confidentiality optional
- optional, not held levels of software testing optional
- optional, not held mobile device management optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held web application security threats optional
- required, not held cyber attack counter-measures required
- required, not held cyber security required
- required, not held security threats required
- required, not held internal risk management policy required
- required, not held risk management required
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held ICT security legislation optional
- optional, not held investment analysis optional
- optional, not held organisational resilience optional
- optional, not held audit techniques optional
- optional, not held legal requirements of ICT products optional
- required, not held ensure adherence to organisational ICT standards required
- required, not held establish an Information Security Management System required
- optional, not held develop information security strategy optional
- required, not held communicate with stakeholders required
- required, not held engage with stakeholders required
- optional, not held design for organisational complexity optional
- required, not held establish an ICT security prevention plan required
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held lead disaster recovery exercises optional
- optional, not held manage disaster recovery plans optional
2 further areas in the appendix
Table 4 · Where to start
The 3 entries a cybersecurity risk manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 establish an ICT security prevention plan skill · occupation specific
- 02 ICT network security risks knowledge · sector specific
- 03 ICT performance analysis methods knowledge · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 19 skills that carry over
- already held implement ICT risk management skill
- already held information security strategy knowledge
- already held manage system security skill
- already held security engineering knowledge
- already held ICT recovery techniques knowledge
- already held ICT system user requirements knowledge
- already held cloud monitoring and reporting knowledge
- already held cloud security and compliance knowledge
- already held domain name service knowledge
- already held implement ICT security policies skill
- already held implement a firewall skill
- already held implement a virtual private network skill
- already held implement anti-virus software skill
- already held implement spam protection skill
- already held internet governance knowledge
- already held remove computer virus or malware from a computer skill
- already held solve ICT system problems skill
- already held systems development life-cycle knowledge
- already held use back-up and recovery tools skill
The 2 learning areas not shown above
- required, not held ICT safety required
- optional, not held develop with cloud services optional
- optional, not held manage keys for data protection optional
- optional, not held use an application-specific interface optional
- optional, not held use ICT ticketing system optional
- required, not held advice on security risk management required
- optional, not held execute ICT audits optional
- optional, not held identify ICT security risks optional
- optional, not held implement cloud security and compliance optional
35 supplementary skills, helpful but not required
- optional, not held ICT encryption optional
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held ICT security legislation optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held computer forensics optional
- optional, not held decision support systems optional
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held design for organisational complexity optional
- optional, not held develop information security strategy optional
- optional, not held develop with cloud services optional
- optional, not held execute ICT audits optional
- optional, not held hybrid model optional
- optional, not held identify ICT security risks optional
- optional, not held implement cloud security and compliance optional
- optional, not held information confidentiality optional
- optional, not held investment analysis optional
- optional, not held lead disaster recovery exercises optional
- optional, not held levels of software testing optional
- optional, not held manage keys for data protection optional
- optional, not held mobile device management optional
- optional, not held organisational resilience optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held use an application-specific interface optional
- optional, not held web application security threats optional
- optional, not held audit techniques optional
- optional, not held legal requirements of ICT products optional
- optional, not held manage disaster recovery plans optional
- optional, not held use ICT ticketing system optional
41 held skills the cybersecurity risk manager role does not ask for
- not needed by the target role Apache Tomcat knowledge
- not needed by the target role IBM WebSphere knowledge
- not needed by the target role ICT accessibility standards knowledge
- not needed by the target role ICT infrastructure knowledge
- not needed by the target role ICT system integration knowledge
- not needed by the target role ICT system programming knowledge
- not needed by the target role acquire system component skill
- not needed by the target role adjust ICT system capacity skill
- not needed by the target role administer ICT system skill
- not needed by the target role apply ICT system usage policies skill
- not needed by the target role apply system organisational policies skill
- not needed by the target role automate cloud tasks skill
- not needed by the target role cloud technologies knowledge
- not needed by the target role digital systems knowledge
- not needed by the target role engineering processes knowledge
- not needed by the target role execute integration testing skill
- not needed by the target role hardware components knowledge
- not needed by the target role implement ICT recovery system skill
- not needed by the target role install signal repeaters skill
- not needed by the target role integrate system components skill
- not needed by the target role interact with users to gather requirements skill
- not needed by the target role interfacing techniques knowledge
- not needed by the target role interpret technical texts skill
- not needed by the target role maintain ICT system skill
- not needed by the target role manage changes in ICT system skill
- not needed by the target role manage cloud data and storage skill
- not needed by the target role manage system testing skill
- not needed by the target role migrate existing data skill
- not needed by the target role monitor system performance skill
- not needed by the target role network engineering knowledge
- not needed by the target role network standards knowledge
- not needed by the target role operating systems knowledge
- not needed by the target role organisational policies knowledge
- not needed by the target role perform backups skill
- not needed by the target role provide ICT system training skill
- not needed by the target role quality assurance methodologies knowledge
- not needed by the target role software components libraries knowledge
- not needed by the target role store digital data and systems skill
- not needed by the target role support ICT system users skill
- not needed by the target role system design knowledge
1 further entry not listed here
33 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT network security risks required
- required, not held ICT performance analysis methods required
- required, not held ICT security standards required
- required, not held attack vectors required
- required, not held cyber attack counter-measures required
- required, not held cyber security required
- required, not held ethical hacking principles required
- required, not held internal risk management policy required
- required, not held assessment of risks and threats required
- required, not held risk management required
- required, not held security threats required
- optional, not held ICT encryption optional
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held ICT security legislation optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held computer forensics optional
- optional, not held decision support systems optional
- optional, not held hybrid model optional
- optional, not held information confidentiality optional
- optional, not held investment analysis optional
- optional, not held levels of software testing optional
- optional, not held mobile device management optional
- optional, not held organisational resilience optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held web application security threats optional
- optional, not held audit techniques optional
- optional, not held legal requirements of ICT products optional
Other moves recorded from ICT system administrator
- ICT network technician 39% covered · substantial
- ICT network administrator 36% covered · career change
- cloud engineer 31% covered · career change
- ICT security administrator 30% covered · career change
- cloud software developer 30% covered · substantial
- ICT system integration consultant 29% covered · career change
- telecommunications engineering technician 28% covered · career change
- cloud DevOps engineer 27% covered · career change
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.