C
CISO (Chief Information Security Officer)
ExecutiveCompetency profile for a CISO who owns the organisation's information security strategy, manages cyber risk at board level and leads the security organisation.
12SFIA skills
L6Avg target
L7Highest required
Strategy and architectureMain category
SFIA 9 Responsibility Levels — what each level means
L1 — FollowL2 — AssistL3 — ApplyL4 — EnableL5 — Ensure / AdviseL6 — Initiate / SetL7 — Set Strategy
Most skills in this template are L5–L7. L3 means you work independently on tasks. L4 means you own decisions and guide others.
Not sure which level to pick? During self-assessment, each level shows its definition and a suggested STAR evidence prompt.
Required Competencies
12 SFIA Skills for this Role
On smaller screens, this table scrolls horizontally so you can still read full level guidance.
| Code | Skill | Category | Target Level | What you need to demonstrate |
|---|---|---|---|---|
| SCTY | Information security Defining and operating a framework of security controls and security management strategies. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| GOVN | Governance Defining and operating frameworks for decision-making, risk management, stakeholder relationships and compliance with organisational and regulatory obligations. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| BURM | Risk management Planning and implementing processes for managing risk across the enterprise, aligned with organisational strategy and governance frameworks. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| RLMT | Stakeholder relationship management Systematically analysing, managing and influencing stakeholder relationships to achieve mutually beneficial outcomes through structured engagement. | Relationships and engagement | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| ITSP | Strategic planning Creating and maintaining organisational-level strategies to align overall business plans, actions and resources with high-level business objectives. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| INAS | Information assurance Protecting against and managing risks related to the use, storage and transmission of data and information systems. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| PEDP | Information and data compliance Implementing and promoting compliance with information and data management legislation. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| CNSL | Consultancy Providing advice and recommendations, based on expertise and experience, to address client needs. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| THIN | Threat intelligence Developing and sharing actionable insights on current and potential security threats to the success or integrity of an organisation. | Strategy and architecture | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| AUDT | Audit Delivering independent, risk-based assessments of the effectiveness of processes, the controls and the compliance environment of an organisation. | Strategy and architecture | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| OCDV | Organisational capability development Providing leadership, advice and implementation support to assess organisational capabilities and to identify, prioritise and implement improvements. | Change and transformation | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| WFPL | Workforce planning Strategically projecting the demand for people and skills and proactively planning the workforce supply to meet organisational needs. | People and skills | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
Template Preview
Ready to build your CISO (Chief Information Security Officer) profile?
Review the 12 required skills above, then start your self-assessment. You can save a draft and return anytime.
① Rate each skill L1–L7② Write evidence (~15 min)③ Save draft and continue later