C
CISO (Chief Information Security Officer)
ExecutiveCompetency profile for a CISO who owns the organisation's information security strategy, manages cyber risk at board level and leads the security organisation.
12kỹ năng SFIA
L6Mức TB
L7Mức cao nhất
Strategy and architectureDanh mục chính
Mức độ trách nhiệm SFIA 9 — ý nghĩa từng mức
L1 — Tuân theoL2 — Hỗ trợL3 — Vận dụngL4 — Chủ trìL5 — Đảm bảo / Tư vấnL6 — Khởi tạo / Định hướngL7 — Định chiến lược
Hầu hết kỹ năng trong mẫu này ở mức L5–L7. L3 nghĩa là bạn làm việc độc lập. L4 nghĩa là bạn ra quyết định và hướng dẫn người khác.
Chưa chắc chọn mức nào? Trong quá trình tự đánh giá, mỗi mức sẽ hiện định nghĩa và gợi ý viết bằng chứng theo STAR.
Năng lực Yêu cầu
12 Kỹ năng SFIA cho Vị trí này
On smaller screens, this table scrolls horizontally so you can still read full level guidance.
| Mã | Kỹ năng | Danh mục | Mức độ Yêu cầu | Bạn cần chứng minh |
|---|---|---|---|---|
| SCTY | Information security Defining and operating a framework of security controls and security management strategies. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| GOVN | Governance Defining and operating frameworks for decision-making, risk management, stakeholder relationships and compliance with organisational and regulatory obligations. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| BURM | Risk management Planning and implementing processes for managing risk across the enterprise, aligned with organisational strategy and governance frameworks. | Strategy and architecture | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| RLMT | Stakeholder relationship management Systematically analysing, managing and influencing stakeholder relationships to achieve mutually beneficial outcomes through structured engagement. | Relationships and engagement | L7 — Set Strategy | Set strategy at the highest level and lead organisational transformation. |
| ITSP | Strategic planning Creating and maintaining organisational-level strategies to align overall business plans, actions and resources with high-level business objectives. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| INAS | Information assurance Protecting against and managing risks related to the use, storage and transmission of data and information systems. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| PEDP | Information and data compliance Implementing and promoting compliance with information and data management legislation. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| CNSL | Consultancy Providing advice and recommendations, based on expertise and experience, to address client needs. | Strategy and architecture | L6 — Initiate / Set | Initiate new approaches, set standards and drive enterprise-wide change. |
| THIN | Threat intelligence Developing and sharing actionable insights on current and potential security threats to the success or integrity of an organisation. | Strategy and architecture | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| AUDT | Audit Delivering independent, risk-based assessments of the effectiveness of processes, the controls and the compliance environment of an organisation. | Strategy and architecture | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| OCDV | Organisational capability development Providing leadership, advice and implementation support to assess organisational capabilities and to identify, prioritise and implement improvements. | Change and transformation | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
| WFPL | Workforce planning Strategically projecting the demand for people and skills and proactively planning the workforce supply to meet organisational needs. | People and skills | L5 — Ensure / Advise | Ensure overall quality, advise on strategy and influence organisational direction. |
Xem trước Mẫu Công việc
Sẵn sàng xây dựng hồ sơ CISO (Chief Information Security Officer)?
Xem lại 12 kỹ năng yêu cầu ở trên, sau đó bắt đầu tự đánh giá. Bạn có thể lưu bản nháp và quay lại bất cứ lúc nào.
① Đánh giá từng kỹ năng L1–L7② Viết bằng chứng (~15 phút)③ Lưu nháp và tiếp tục sau