Mapping
- Public service levels: A08-SES
- SFIA: 6-7
- Leadership competencies for Queensland – Program leader; Executive; Chief executive
SFIA professional skills
- Audit AUDT
- Continuity management COPL
- Data analytics DAAN
- Governance GOVN
- Information and data compliance PEDP
- Information assurance INAS
- Information security SCTY
- Investment appraisal INVA
- Risk management BURM
- Stakeholder relationship management RLMT
Competencies
- How to set, direct and review a strategy and governance framework for cyber security that aligns with organisational direction.
- How to support executives to define the cyber security risk tolerance of the organisation and manage this as an enterprise risk.
- How to liaise with regulatory authorities to run the organisation’s governance, risk and compliance function and maintain relationships with key internal and external stakeholders.
- How to assure the organisation that its cyber security controls align with the business and comply with regulations, policy and procedure.
- How to develop business cases and or appraise investments that can assist with managing the organisation’s cyber security resilience.
- How to lead and secure the resources to deliver the cyber security governance risk and compliance function.
- How to lead and implement business impact analyses (BIA) for continuity strategies and plans
70:20:10 examples
70: Suggested experiential learning
- Set or review overarching cyber security governance arrangements.
- Define the governance, risk and compliance function in the organisation’s context.
- Support and deliver board level (or similar) presentations and visibility of risk.
- Collaborate with corporate teams (e.g. finance, portfolio management) to develop cyber related business cases.
- Set cyber security strategy and policy.
- Lead annual IS18 return.
- Address emerging areas of risk or practices (e.g. third-party supply chain, artificial intelligence, quantum).
20: Suggested professional development
- Make contributions to the industry e.g. keynotes, board representation, conference attendance, working groups, boards.
- Deliver presentations to business executives.
- Mentor emerging leaders.
- Contribute to the development or related national, international and industry standards.
10: Example formal learning
- Certified in the Governance of Enterprise IT (CGEIT)
- CISM – Certified Information Security Manager
- LDR514: Security strategic planning, policy and leadership
- Lead Auditor ISMS ISO/IEC 27001:2022 & ISO 19011:2018
- Last updated:
- 30 June 2025