Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

IT auditortochief ICT security officer

A IT auditor already meets 25% of what the chief ICT security officer role asks for. The move turns on 34 required skills not yet in the profile.

From IT auditor
25%
Overlap1
To chief ICT security officer
18 Skills carried over
34 Required, not held
83.6 Difficulty2
Career overlap Distant match

25%

Learning distance A rebuild

83.6/ 100

1 Share of the chief ICT security officer role’s weighted skill requirement already met by the IT auditor profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Why

Why this move works

A chief ICT security officer role treats 13 of its required skills as things a IT auditor already does. These are the ones it depends on most.

  • ICT network security risks
  • ICT process quality models
  • ICT project management
  • ICT security legislation
  • ICT security standards
  • audit techniques

What stands in the way is 34 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.

Table 2

Table 2 · What you already bring

Of the 18 skills that carry over, these are the ones fewest other occupations ask for. A chief ICT security officer role needs them, and most people applying for one will not have them already. This is the part of a IT auditor background worth leading with.

Skill the target role also needs Area
  • already held ensure adherence to organisational ICT standards assisting and caring
  • already held identify ICT security risks information skills
  • already held manage IT security compliances working with computers
  • already held identify legal requirements information skills
  • already held organisational resilience business, administration and law
  • already held ICT project management business, administration and law

All 18 carried skills, including the 13 the chief ICT security officer role treats as required.

Table 3

Table 3 · What you would need to learn

The 63 missing skills fall into 12 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 information and communication technologies (icts) 6 required, 11 supplementary
  • required, not held attack vectors required
  • required, not held data protection required
  • required, not held decision support systems required
  • required, not held ethical hacking principles required
  • required, not held information confidentiality required
  • required, not held assessment of risks and threats required
  • optional, not held ICT encryption optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held Internet of Things optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held computer forensics optional
  • optional, not held internet governance optional
  • optional, not held software anomalies optional
  • optional, not held web application security threats optional
  • optional, not held computer programming optional
02 communication, collaboration and creativity 5 required, 3 supplementary
  • required, not held implement corporate governance required
  • required, not held communicate with stakeholders required
  • required, not held educate on data confidentiality required
  • required, not held engage with stakeholders required
  • required, not held ensure cross-department cooperation required
  • optional, not held create solutions to problems optional
  • optional, not held train employees optional
  • optional, not held use different communication channels optional
03 assisting and caring 5 required, 1 supplementary
  • required, not held develop information security strategy required
  • required, not held ensure information privacy required
  • required, not held establish an Information Security Management System required
  • required, not held comply with legal regulations required
  • required, not held ensure compliance with legal requirements required
  • optional, not held apply operations for an ITIL-based environment optional
04 working with computers 4 required, 5 supplementary
  • required, not held ICT safety required
  • required, not held implement ICT security policies required
  • required, not held manage system security required
  • required, not held utilise decision support system required
  • optional, not held implement a firewall optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held manage keys for data protection optional
  • optional, not held optimise choice of ICT solution optional
05 management skills 4 required, 3 supplementary
  • required, not held establish an ICT security prevention plan required
  • required, not held lead disaster recovery exercises required
  • required, not held maintain plan for continuity of operations required
  • required, not held manage disaster recovery plans required
  • optional, not held assess ICT knowledge optional
  • optional, not held coordinate technological activities optional
  • optional, not held manage staff optional
06 information skills 4 required, 2 supplementary
  • required, not held advice on security risk management required
  • required, not held implement ICT risk management required
  • required, not held forecast organisational risks required
  • required, not held monitor developments in field of expertise required
  • optional, not held implement cloud security and compliance optional
  • optional, not held conduct impact evaluation of ICT processes on business optional

6 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a chief ICT security officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 18 skills that carry over
Skill Type
  • already held ICT network security risks knowledge
  • already held ICT process quality models knowledge
  • already held ICT project management knowledge
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held audit techniques knowledge
  • already held cyber security knowledge
  • already held ensure adherence to organisational ICT standards skill
  • already held identify ICT security risks skill
  • already held information security strategy knowledge
  • already held manage IT security compliances skill
  • already held monitor technology trends skill
  • already held organisational resilience knowledge
  • already held World Wide Web Consortium standards knowledge
  • already held cloud technologies knowledge
  • already held execute ICT audits skill
  • already held identify legal requirements skill
  • already held protect personal data and privacy skill
The 6 learning areas not shown above
Skill to acquire Tier
07 business, administration and law 3 required
  • required, not held ICT project management methodologies required
  • required, not held internal risk management policy required
  • required, not held risk management required
08 engineering, manufacturing and construction 1 required, 2 supplementary
  • required, not held security engineering required
  • optional, not held ICT communications protocols optional
  • optional, not held ICT infrastructure optional
09 arts and humanities 1 required
  • required, not held ethics required
10 services 1 required
  • required, not held cyber attack counter-measures required
11 core skills and competences 1 supplementary
  • optional, not held manage digital identity optional
12 social sciences, journalism and information 1 supplementary
  • optional, not held control objectives for information and related technology optional
29 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held apply operations for an ITIL-based environment optional
  • optional, not held control objectives for information and related technology optional
  • optional, not held ICT communications protocols optional
  • optional, not held ICT encryption optional
  • optional, not held ICT infrastructure optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held Internet of Things optional
  • optional, not held assess ICT knowledge optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held computer forensics optional
  • optional, not held coordinate technological activities optional
  • optional, not held implement a firewall optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held implement cloud security and compliance optional
  • optional, not held internet governance optional
  • optional, not held manage keys for data protection optional
  • optional, not held optimise choice of ICT solution optional
  • optional, not held software anomalies optional
  • optional, not held web application security threats optional
  • optional, not held computer programming optional
  • optional, not held conduct impact evaluation of ICT processes on business optional
  • optional, not held create solutions to problems optional
  • optional, not held manage digital identity optional
  • optional, not held manage staff optional
  • optional, not held train employees optional
  • optional, not held use different communication channels optional
19 held skills the chief ICT security officer role does not ask for
Skill Type
  • not needed by the target role ICT accessibility standards knowledge
  • not needed by the target role ICT quality policy knowledge
  • not needed by the target role analyse ICT system skill
  • not needed by the target role apply information security policies skill
  • not needed by the target role communicate analytical insights skill
  • not needed by the target role define organisational standards skill
  • not needed by the target role develop ICT workflow skill
  • not needed by the target role develop audit plan skill
  • not needed by the target role develop documentation in accordance with legal requirements skill
  • not needed by the target role engineering processes knowledge
  • not needed by the target role improve business processes skill
  • not needed by the target role inform on workplace safety standards skill
  • not needed by the target role legal requirements of ICT products knowledge
  • not needed by the target role perform ICT security testing skill
  • not needed by the target role perform quality audits skill
  • not needed by the target role prepare financial auditing reports skill
  • not needed by the target role product life-cycle knowledge
  • not needed by the target role quality standards knowledge
  • not needed by the target role systems development life-cycle knowledge
26 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held ICT project management methodologies required
  • required, not held attack vectors required
  • required, not held cyber attack counter-measures required
  • required, not held data protection required
  • required, not held decision support systems required
  • required, not held ethical hacking principles required
  • required, not held information confidentiality required
  • required, not held internal risk management policy required
  • required, not held assessment of risks and threats required
  • required, not held ethics required
  • required, not held risk management required
  • required, not held security engineering required
  • optional, not held control objectives for information and related technology optional
  • optional, not held ICT communications protocols optional
  • optional, not held ICT encryption optional
  • optional, not held ICT infrastructure optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held Internet of Things optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held computer forensics optional
  • optional, not held internet governance optional
  • optional, not held software anomalies optional
  • optional, not held web application security threats optional
  • optional, not held computer programming optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.