Mapping

SFIA professional skills

  • Audit AUDT
  • Continuity management COPL
  • Data analytics DAAN
  • Governance GOVN
  • Information and data compliance PEDP
  • Information assurance INAS
  • Information security SCTY
  • Investment appraisal INVA
  • Risk management BURM
  • Stakeholder relationship management RLMT

Competencies

  • How to set, direct and review a strategy and governance framework for cyber security that aligns with organisational direction.
  • How to support executives to define the cyber security risk tolerance of the organisation and manage this as an enterprise risk.
  • How to liaise with regulatory authorities to run the organisation’s governance, risk and compliance function and maintain relationships with key internal and external stakeholders.
  • How to assure the organisation that its cyber security controls align with the business and comply with regulations, policy and procedure.
  • How to develop business cases and or appraise investments that can assist with managing the organisation’s cyber security resilience.
  • How to lead and secure the resources to deliver the cyber security governance risk and compliance function.
  • How to lead and implement business impact analyses (BIA) for continuity strategies and plans

70:20:10 examples

70: Suggested experiential learning

  • Set or review overarching cyber security governance arrangements.
  • Define the governance, risk and compliance function in the organisation’s context.
  • Support and deliver board level (or similar) presentations and visibility of risk.
  • Collaborate with corporate teams (e.g. finance, portfolio management) to develop cyber related business cases.
  • Set cyber security strategy and policy.
  • Lead annual IS18 return.
  • Address emerging areas of risk or practices (e.g. third-party supply chain, artificial intelligence, quantum).

20: Suggested professional development

  • Make contributions to the industry e.g. keynotes, board representation, conference attendance, working groups, boards.
  • Deliver presentations to business executives.
  • Mentor emerging leaders.
  • Contribute to the development or related national, international and industry standards.

10: Example formal learning

  • Certified in the Governance of Enterprise IT (CGEIT)
  • CISM – Certified Information Security Manager
  • LDR514: Security strategic planning, policy and leadership
  • Lead Auditor ISMS ISO/IEC 27001:2022 & ISO 19011:2018