TASK
Assess the effectiveness of security controls
TASK
Manage Accreditation Packages (e.g., ISO/IEC 15026-2)
TASK
Expand network access
TASK
Conduct technical exploitation of a target
TASK
Determine special needs of cyber-physical systems
TASK
Determine the operational and safety impacts of cybersecurity lapses
TASK
Review cyber defense service provider reporting structure
TASK
Review enterprise information technology (IT) goals and objectives
TASK
Identify critical technology procurement requirements
TASK
Determine procurement requirements
TASK
Estimate the impact of collateral damage
TASK
Integrate leadership priorities
TASK
Integrate organization objectives in intelligence collection
TASK
Determine impact of software configurations
TASK
Assess operation performance
TASK
Assess operation impact
TASK
Scope analysis reports to various audiences that accounts for data sharing classification restrictions
TASK
Determine if priority information requirements are satisfied
TASK
Develop cybersecurity risk profiles
TASK
Identify anomalous network activity
TASK
Identify vulnerabilities
TASK
Recommend vulnerability remediation strategies
TASK
Approve accreditation packages
TASK
Perform security reviews
TASK
Identify gaps in security architecture
TASK
Develop a cybersecurity risk management plan
TASK
Recommend risk mitigation strategies
TASK
Conduct risk analysis of applications and systems undergoing major changes
TASK
Plan security authorization reviews for system and network installations
TASK
Conduct security authorization reviews for system and network installations
TASK
Develop security assurance cases for system and network installations
TASK
Advise on Risk Management Framework process activities and documentation
TASK
Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
TASK
Update security documentation to reflect current application and system security design features
TASK
Verify implementation of software, network, and system cybersecurity postures
TASK
Document software, network, and system deviations from implemented security postures
TASK
Recommend required actions to correct software, network, and system deviations from implemented security postures
TASK
Develop cybersecurity compliance processes for external services
TASK
Develop cybersecurity audit processes for external services
TASK
Provide cybersecurity guidance to organizational risk governance processes
TASK
Determine if vulnerability remediation plans are in place
TASK
Develop vulnerability remediation plans
TASK
Determine if cybersecurity requirements have been successfully implemented
TASK
Determine the effectiveness of organizational cybersecurity policies and procedures
TASK
Determine the impact of new system and interface implementations on organization's cybersecurity posture
TASK
Document impact of new system and interface implementations on organization's cybersecurity posture
TASK
Document cybersecurity design and development activities
TASK
Support cybersecurity compliance activities
TASK
Determine if acquisitions, procurement, and outsourcing efforts address cybersecurity requirements
TASK
Determine effectiveness of configuration management processes
TASK
Correlate incident data
TASK
Evaluate locally developed tools
KNOWLEDGE
Knowledge of language processing tools and techniques
KNOWLEDGE
Knowledge of cybersecurity practices in the acquisition process
KNOWLEDGE
Knowledge of intelligence fusion
KNOWLEDGE
Knowledge of cognitive biases
KNOWLEDGE
Knowledge of information privacy technologies
KNOWLEDGE
Knowledge of computer networking protocols
KNOWLEDGE
Knowledge of risk management processes
KNOWLEDGE
Knowledge of cybersecurity laws and regulations
KNOWLEDGE
Knowledge of cybersecurity policies and procedures
KNOWLEDGE
Knowledge of privacy laws and regulations
KNOWLEDGE
Knowledge of privacy policies and procedures
KNOWLEDGE
Knowledge of cybersecurity principles and practices
KNOWLEDGE
Knowledge of privacy principles and practices
KNOWLEDGE
Knowledge of cybersecurity threats
KNOWLEDGE
Knowledge of cybersecurity vulnerabilities
KNOWLEDGE
Knowledge of cybersecurity threat characteristics
KNOWLEDGE
Knowledge of access control principles and practices
KNOWLEDGE
Knowledge of authentication and authorization tools and techniques
KNOWLEDGE
Knowledge of business operations standards and best practices
KNOWLEDGE
Knowledge of network infrastructure principles and practices
KNOWLEDGE
Knowledge of cyber defense tools and techniques
KNOWLEDGE
Knowledge of vulnerability assessment tools and techniques
KNOWLEDGE
Knowledge of data backup and recovery policies and procedures
KNOWLEDGE
Knowledge of data warehousing principles and practices
KNOWLEDGE
Knowledge of data mining principles and practices
KNOWLEDGE
Knowledge of database systems and software
KNOWLEDGE
Knowledge of business continuity and disaster recovery (BCDR) policies and procedures
KNOWLEDGE
Knowledge of enterprise cybersecurity architecture principles and practices
KNOWLEDGE
Knowledge of evaluation and validation principles and practices
KNOWLEDGE
Knowledge of Local Area Networks (LAN)
KNOWLEDGE
Knowledge of Wide Area Networks (WAN)
KNOWLEDGE
Knowledge of network communications principles and practices
KNOWLEDGE
Knowledge of Security Assessment and Authorization (SA&A) processes
KNOWLEDGE
Knowledge of risk management principles and practices
KNOWLEDGE
Knowledge of vulnerability data sources
KNOWLEDGE
Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices
KNOWLEDGE
Knowledge of non-repudiation principles and practices
KNOWLEDGE
Knowledge of cyber safety principles and practices
KNOWLEDGE
Knowledge of systems security engineering (SSE) principles and practices
KNOWLEDGE
Knowledge of Risk Management Framework (RMF) requirements
KNOWLEDGE
Knowledge of risk management models and frameworks
KNOWLEDGE
Knowledge of information technology (IT) security principles and practices
KNOWLEDGE
Knowledge of identity and access management (IAM) principles and practices
KNOWLEDGE
Knowledge of new and emerging technologies
KNOWLEDGE
Knowledge of policy-based access controls
KNOWLEDGE
Knowledge of Risk Adaptive (Adaptable) Access Controls (RAdAC)
KNOWLEDGE
Knowledge of process engineering principles and practices
KNOWLEDGE
Knowledge of system threats
KNOWLEDGE
Knowledge of system vulnerabilities
KNOWLEDGE
Knowledge of server administration principles and practices
KNOWLEDGE
Knowledge of server diagnostic tools and techniques
KNOWLEDGE
Knowledge of Fault Detection and Diagnostics (FDD) tools and techniques
KNOWLEDGE
Knowledge of software engineering principles and practices
KNOWLEDGE
Knowledge of structured analysis principles and practices
KNOWLEDGE
Knowledge of collaboration tools and techniques
KNOWLEDGE
Knowledge of enterprise information technology (IT) architecture principles and practices
KNOWLEDGE
Knowledge of systems engineering processes
KNOWLEDGE
Knowledge of insider threat laws and regulations
KNOWLEDGE
Knowledge of insider threat tools and techniques
KNOWLEDGE
Knowledge of defense-in-depth principles and practices
KNOWLEDGE
Knowledge of evidence admissibility laws and regulations
KNOWLEDGE
Knowledge of supply chain risk management principles and practices
KNOWLEDGE
Knowledge of machine virtualization tools and techniques
KNOWLEDGE
Knowledge of secure coding tools and techniques
KNOWLEDGE
Knowledge of import and export control laws and regulations
KNOWLEDGE
Knowledge of supply chain risks
KNOWLEDGE
Knowledge of federal agency roles and responsibilities
KNOWLEDGE
Knowledge of supply chain risk management standards and best practices
KNOWLEDGE
Knowledge of technology procurement principles and practices
KNOWLEDGE
Knowledge of supply chain risk management policies and procedures
KNOWLEDGE
Knowledge of critical infrastructure systems and software
KNOWLEDGE
Knowledge of hardware reverse engineering tools and techniques
KNOWLEDGE
Knowledge of software reverse engineering tools and techniques
KNOWLEDGE
Knowledge of reverse engineering principles and practices
KNOWLEDGE
Knowledge of virtual machine detection tools and techniques
KNOWLEDGE
Knowledge of encryption tools and techniques
KNOWLEDGE
Knowledge of data classification standards and best practices
KNOWLEDGE
Knowledge of data classification tools and techniques
KNOWLEDGE
Knowledge of enterprise architecture (EA) reference models and frameworks
KNOWLEDGE
Knowledge of enterprise architecture (EA) principles and practices
KNOWLEDGE
Knowledge of application firewall principles and practices
KNOWLEDGE
Knowledge of network firewall principles and practices
KNOWLEDGE
Knowledge of industry cybersecurity models and frameworks
KNOWLEDGE
Knowledge of access control models and frameworks
KNOWLEDGE
Knowledge of learning assessment tools and techniques
KNOWLEDGE
Knowledge of instructional design principles and practices
KNOWLEDGE
Knowledge of instructional design models and frameworks
KNOWLEDGE
Knowledge of cyber defense laws and regulations
KNOWLEDGE
Knowledge of network architecture principles and practices
KNOWLEDGE
Knowledge of Personally Identifiable Information (PII) data security standards and best practices
KNOWLEDGE
Knowledge of Payment Card Industry (PCI) data security standards and best practices
KNOWLEDGE
Knowledge of Personal Health Information (PHI) data security standards and best practices
KNOWLEDGE
Knowledge of the acquisition life cycle models and frameworks
KNOWLEDGE
Knowledge of network analysis tools and techniques
KNOWLEDGE
Knowledge of systems engineering principles and practices
KNOWLEDGE
Knowledge of data classification policies and procedures
KNOWLEDGE
Knowledge of computer engineering principles and practices
KNOWLEDGE
Knowledge of embedded systems and software
KNOWLEDGE
Knowledge of data mining tools and techniques
KNOWLEDGE
Knowledge of targeting laws and regulations
KNOWLEDGE
Knowledge of exploitation laws and regulations
KNOWLEDGE
Knowledge of language analysis tools and techniques
KNOWLEDGE
Knowledge of voice analysis tools and techniques
KNOWLEDGE
Knowledge of graphic materials analysis tools and techniques
KNOWLEDGE
Knowledge of computer networking principles and practices
KNOWLEDGE
Knowledge of target selection criticality factors
KNOWLEDGE
Knowledge of target selection vulnerability factors
KNOWLEDGE
Knowledge of cyber operations principles and practices
KNOWLEDGE
Knowledge of network security principles and practices
KNOWLEDGE
Knowledge of target language
KNOWLEDGE
Knowledge of critical information requirements
KNOWLEDGE
Knowledge of operation assessment processes
KNOWLEDGE
Knowledge of virtual machine tools and technologies
KNOWLEDGE
Knowledge of risk scoring principles and practices
KNOWLEDGE
Knowledge of data security controls
KNOWLEDGE
Knowledge of web application security risks
KNOWLEDGE
Knowledge of data privacy controls
KNOWLEDGE
Knowledge of knowledge management tools and techniques
KNOWLEDGE
Knowledge of data analysis tools and techniques
KNOWLEDGE
Knowledge of personnel systems and software
KNOWLEDGE
Knowledge of code analysis tools and techniques
KNOWLEDGE
Knowledge of analytical tools and techniques
KNOWLEDGE
Knowledge of analytics
KNOWLEDGE
Knowledge of traceroute tools and techniques
KNOWLEDGE
Knowledge of virtual collaborative workspace tools and techniques
KNOWLEDGE
Knowledge of organizational cybersecurity goals and objectives
SKILL
Skill in conducting test events
SKILL
Skill in applying security controls
SKILL
Skill in interfacing with customers
SKILL
Skill in network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools
SKILL
Skill in assessing security systems designs
SKILL
Skill in applying secure coding techniques
SKILL
Skill in performing root cause analysis
SKILL
Skill in performing network analysis on targets
SKILL
Skill in performing target system analysis
SKILL
Skill in processing collected data for follow-on analysis
SKILL
Skill in communicating complex concepts
SKILL
Skill in communicating verbally
SKILL
Skill in communicating in writing
SKILL
Skill in facilitating small group discussions
SKILL
Skill in facilitating group discussions
SKILL
Skill in creating technical documentation
SKILL
Skill in developing assessments
SKILL
Skill in developing security assessments
SKILL
Skill in collecting data
SKILL
Skill in verifying data
SKILL
Skill in validating data
SKILL
Skill in deriving evaluative conclusions from data
SKILL
Skill in evaluating laws
SKILL
Skill in evaluating regulations
SKILL
Skill in evaluating policies
SKILL
Skill in analyzing processes to ensure conformance with procedural requirements
SKILL
Skill in collaborating with others
SKILL
Skill in applying critical thinking
SKILL
Skill in analyzing large data sets
SKILL
Skill in creating target intelligence products
SKILL
Skill in identifying targets of interest
SKILL
Skill in functioning effectively in a dynamic, fast-paced environment
SKILL
Skill in identifying external partners
SKILL
Skill in identifying target vulnerabilities
SKILL
Skill in describing target vulnerabilities
SKILL
Skill in mitigating cognitive biases
SKILL
Skill in aligning privacy and cybersecurity objectives
SKILL
Skill in integrating information security requirements in the acquisitions process
SKILL
Skill in implementing software quality control processes
SKILL
Skill in identifying critical infrastructure systems
SKILL
Skill in identifying systems designed without security considerations
SKILL
Skill in developing virtual machines
SKILL
Skill in maintaining virtual machines
SKILL
Skill in identifying software communications vulnerabilities
SKILL
Skill in selecting targets
SKILL
Skill in identifying vulnerabilities
SKILL
Skill in identifying customer information needs
SKILL
Skill in establishing priorities
SKILL
Skill in identifying partner capabilities
SKILL
Skill in analyzing software configurations
SKILL
Skill in scanning for vulnerabilities
SKILL
Skill in recognizing vulnerabilities
SKILL
Skill in developing algorithms
SKILL
Skill in performing data structure analysis
SKILL
Skill in developing security system controls
SKILL
Skill in evaluating security designs
SKILL
Skill in preparing reports
SKILL
Skill in monitoring system performance
SKILL
Skill in configuring systems for performance enhancement
SKILL
Skill in developing curricula
SKILL
Skill in teaching training programs
SKILL
Skill in categorizing types of vulnerabilities
SKILL
Skill in developing learning activities
SKILL
Skill in designing Test and Evaluation Strategies (TES)
SKILL
Skill in identifying Test and Evaluation Strategies (TES) infrastructure requirements
SKILL
Skill in managing test assets
SKILL
Skill in reviewing logs
SKILL
Skill in identifying evidence of past intrusions
SKILL
Skill in troubleshooting cyber defense infrastructure anomalies
SKILL
Skill in managing a workforce
SKILL
Skill in conducting system reviews
SKILL
Skill in designing secure test plans
SKILL
Skill in assessing application vulnerabilities
SKILL
Skill in implementing Public Key Infrastructure (PKI) encryption
SKILL
Skill in implementing digital signatures
SKILL
Skill in applying policies that meet system security objectives
SKILL
Skill in assessing security controls
SKILL
Skill in translating operational requirements into security controls
SKILL
Skill in optimizing system performance
SKILL
Skill in performing risk assessments
SKILL
Skill in performing administrative planning activities
SKILL
Skill in performing network data analysis
SKILL
Skill in mining data
SKILL
Skill in performing data mining analysis
SKILL
Skill in performing target analysis
SKILL
Skill in developing analytics
SKILL
Skill in evaluating metadata
SKILL
Skill in interpreting metadata
SKILL
Skill in evaluating data source quality
SKILL
Skill in evaluating information quality
SKILL
Skill in generating operation plans
SKILL
Skill in identifying intelligence gaps
SKILL
Skill in identifying regional languages and dialects
SKILL
Skill in prioritizing information
SKILL
Skill in interpreting traceroute results
SKILL
Skill in interpreting vulnerability scanner results
SKILL
Skill in managing client relationships
SKILL
Skill in preparing briefings
SKILL
Skill in preparing plans
SKILL
Skill in producing after-action reports
SKILL
Skill in analyzing intelligence products
SKILL
Skill in identifying network anomalies
SKILL
Skill in performing technical writing
SKILL
Skill in reconstructing a network
SKILL
Skill in incorporating feedback
SKILL
Skill in performing wireless network analysis
SKILL
Skill in navigating databases
SKILL
Skill in performing strategic guidance analysis
SKILL
Skill in developing intelligence collection plans
SKILL
Skill in developing collection strategies
SKILL
Skill in fulfilling information requests
SKILL
Skill in orchestrating planning teams
SKILL
Skill in coordinating collection support
SKILL
Skill in monitoring status
SKILL
Skill in presenting to an audience
SKILL
Skill in analyzing organizational patterns and relationships
SKILL
Skill in assessing partner operations capabilities
SKILL
Skill in solving problems
SKILL
Skill in utilizing cyber defense service provider information
SKILL
Skill in identifying cybersecurity issues in external connections
SKILL
Skill in identifying privacy issues in partner interconnections
SKILL
Skill in performing network traffic analysis
SKILL
Skill in performing risk analysis