Cyberstudy
PDF p.22 In progress

Information Security Competencies

Open PDF at p.22 17 flashcards

Summary

PDF p.22

IT professionals with security responsibilities need a broad skill set, covering network and application design, procurement, and HR. Their roles include risk assessment, system configuration, access control, incident response, and training.

In plain words

Supplementary — not from your PDF

People with security duties need broad skills: assessing risk and testing systems, choosing and configuring secure devices, managing access, reviewing logs and privileges, handling incidents, planning for disasters, and keeping their own training current.

Detailed explanation

PDF p.22
  • Risk Assessments and Testing
    • Activities: Participate in risk assessments and security system testing.
    • Outcome: Make recommendations to improve security.
  • Device and Software Management
    • Activities: Specify, source, install, and configure secure devices and software.
    • Outcome: Ensure systems are secure and up-to-date.
  • Access Control
    • Activities: Set up and maintain document access control and user privilege profiles.
    • Outcome: Control who can access sensitive information.
  • Audit and Monitoring
    • Activities: Monitor audit logs, review user privileges, and document access controls.
    • Outcome: Detect and respond to unauthorized access.
  • Incident Response
    • Activities: Manage security-related incident response and reporting.
    • Outcome: Address and mitigate security incidents.
  • Business Continuity and Disaster Recovery
    • Activities: Create and test business continuity and disaster recovery plans and procedures.
    • Outcome: Ensure the organization can recover from disruptions.
  • Training and Education
    • Activities: Participate in security training and education programs.
    • Outcome: Keep skills and knowledge up-to-date.

Important terms

taken from the text above
Participate
Assess risks and test systems.
Recommend
Improve security measures.
Specify and Source
Secure devices and software.
Install and Configure
Ensure security.
Set Up
Document access control.
Maintain
User privilege profiles.
Monitor
Audit logs.
Review
User privileges and access controls.
Manage
Incident response and reporting.
Create and Test
Continuity and recovery plans.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Reviewing which users still hold administrator rights (audit and monitoring).
  • Writing and testing a disaster recovery plan (business continuity and disaster recovery).
  • Choosing a secure configuration for new laptops before they are handed out (device and software management).

Scenario

A job posting for a security analyst asks for log monitoring, privilege reviews, incident handling and disaster-recovery testing. Each duty maps to a competency area in this subsection.

Common mistakes

Supplementary — not from your PDF
  • Thinking security work is only technical. The guide also mentions design, procurement and HR as part of the skill set.

Practical skills

Supplementary — not from your PDF
  • Map a list of job duties to the competency areas.

What I should remember

Key Points PDF p.22
  • Risk Assessments and Testing
    • Participate: Assess risks and test systems.
    • Recommend: Improve security measures.
  • Device and Software Management
    • Specify and Source: Secure devices and software.
    • Install and Configure: Ensure security.
  • Access Control
    • Set Up: Document access control.
    • Maintain: User privilege profiles.
  • Audit and Monitoring
    • Monitor: Audit logs.
    • Review: User privileges and access controls.
  • Incident Response
    • Manage: Incident response and reporting.
  • Business Continuity and Disaster Recovery
    • Create and Test: Continuity and recovery plans.
  • Training and Education
    • Participate: Security training programs.