USA National Initiative for Cybersecurity Education (NICE)
SFIA skills profiles for 52 information and cyber security roles published by the US National Institute of Standards and Technology (NIST).
This was developed as part of SFIA 8 and has been revised for SFIA 9 and the latest update to NICE framework components.
SFIA Skills Profiles
NICE 1 Oversight and governance (OG) roles |
||
Communications Security (COMSEC) Management |
Responsible for managing the Communications Security (COMSEC) resources of an organization. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cybersecurity Policy and Planning |
Responsible for developing and maintaining cybersecurity plans, strategy, and policy to support and align with organizational cybersecurity initiatives and regulatory compliance. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cybersecurity Workforce Management |
Responsible for developing cybersecurity workforce plans, assessments, strategies, and guidance, including cybersecurity-related staff training, education, and hiring processes. Makes adjustments in response to or in anticipation of changes to cybersecurity-related policy, technology, and staffing needs and requirements. Authors mandated workforce planning strategies to maintain compliance with legislation, regulation, and policy. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cybersecurity Curriculum Development |
Responsible for developing, planning, coordinating, and evaluating cybersecurity awareness, training, or education content, methods, and techniques based on instructional needs and requirements. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cybersecurity Instruction |
Responsible for developing and conducting cybersecurity awareness, training, or education. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cybersecurity Legal Advice |
Responsible for providing cybersecurity legal advice and recommendations, including monitoring related legislation and regulations. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Executive Cybersecurity Leadership |
Responsible for establishing vision and direction for an organization's cybersecurity operations and resources and their impact on digital and physical spaces. Possesses authority to make and execute decisions that impact an organization broadly, including policy approval and stakeholder engagement. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Privacy Compliance |
Responsible for developing and overseeing an organization’s privacy compliance program and staff, including establishing and managing privacy-related governance, policy, and incident response needs. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Product Support Management |
Responsible for planning, estimating costs, budgeting, developing, implementing, and managing product support strategies in order to field and maintain the readiness and operational capability of systems and components. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Program Management |
Responsible for leading, coordinating, and the overall success of a defined program. Includes communicating about the program and ensuring alignment with agency or organizational priorities. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Secure Project Management |
Responsible for overseeing and directly managing technology projects. Ensures cybersecurity is built into projects to protect the organization’s critical infrastructure and assets, reduce risk, and meet organizational goals. Tracks and communicates project status and demonstrates project value to the organization. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Security Control Assessment |
Responsible for conducting independent comprehensive assessments of management, operational, and technical security controls and control enhancements employed within or inherited by a system to determine their overall effectiveness. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Systems Authorization |
Responsible for operating an information system at an acceptable level of risk to organizational operations, organizational assets, individuals, other organizations, and the nation. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
|
|
Systems Security Management |
Responsible for managing the cybersecurity of a program, organization, system, or enclave. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Technology Portfolio Management |
Responsible for managing a portfolio of technology investments that align with the overall needs of mission and enterprise priorities. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Technology Program Auditing |
Responsible for conducting evaluations of technology programs or their individual components to determine compliance with published standards. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 2 Design and Development (DD) roles |
||
Cybersecurity Architecture |
Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Enterprise Architecture |
Responsible for developing and maintaining business, systems, and information processes to support enterprise mission needs. Develops technology rules and requirements that describe baseline and target architectures. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Secure Software Development |
Responsible for developing, creating, modifying, and maintaining computer applications, software, or specialized utility programs. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Secure Systems Development |
Responsible for the secure design, development, and testing of systems and the evaluation of system security throughout the systems development life cycle. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Software Security Assessment |
Responsible for analyzing the security of new or existing computer applications, software, or specialized utility programs and delivering actionable results. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Systems Requirements Planning |
Responsible for consulting with internal and external customers to evaluate and translate functional requirements and integrating security policies into technical solutions. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Systems Testing and Evaluation |
Responsible for planning, preparing, and executing system tests; evaluating test results against specifications and requirements; and reporting test results and findings. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Technology Research and Development |
Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 3 Implementation and Operation (IO) roles |
||
Data Analysis |
Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Database Administration |
Responsible for administering databases and data management systems that allow for the secure storage, query, protection, and utilization of data. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Knowledge Management |
Responsible for managing and administering processes and tools to identify, document, and access an organization’s intellectual capital. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Network Operations |
Responsible for planning, implementing, and operating network services and systems, including hardware and virtual environments. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Systems Administration |
Responsible for setting up and maintaining a system or specific components of a system in adherence with organizational security policies and procedures. Includes hardware and software installation, configuration, and updates; user account management; backup and recovery management; and security control implementation. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Systems Security Analysis |
Responsible for developing and analyzing the integration, testing, operations, and maintenance of systems security. Prepares, performs, and manages the security aspects of implementing and operating a system. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Technical Support |
Responsible for providing technical support to customers who need assistance utilizing client-level hardware and software in accordance with established or approved organizational policies and processes. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 4 Protection and Defense (PD) roles |
||
Defensive Cybersecurity |
Responsible for analyzing data collected from various cybersecurity defense tools to mitigate risks. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Digital Forensics |
Responsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Incident Response |
Responsible for investigating, analyzing, and responding to network cybersecurity incidents. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Infrastructure Support |
Responsible for testing, implementing, deploying, maintaining, and administering infrastructure hardware and software for cybersecurity. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Threat Analysis |
Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Vulnerability Analysis |
Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 5 Investigation roles (IN) roles |
||
Cybercrime Investigation |
Responsible for investigating cyberspace intrusion incidents and crimes. Applies tactics, techniques, and procedures for a full range of investigative tools and processes and appropriately balances the benefits of prosecution versus intelligence gathering. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Digital Evidence Analysis |
Responsible for identifying, collecting, examining, and preserving digital evidence using controlled and documented analytical and investigative techniques. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 6 Cyberspace Intelligence (CI) roles |
||
All-Source Analysis |
Responsible for analyzing data and information from one or multiple sources to conduct preparation of the operational environment, respond to requests for information, and submit intelligence collection and production requirements in support of intelligence planning and operations. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
All-Source Collection Management |
Responsible for identifying intelligence collection authorities and environment; incorporating priority information requirements into intelligence collection management; and developing concepts to meet leadership's intent. Determines capabilities of available intelligence collection assets; constructs and disseminates intelligence collection plans; and monitors execution of intelligence collection tasks to ensure effective execution of collection plans. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
All-Source Collection Requirements Management |
Responsible for evaluating intelligence collection operations and developing effects-based collection requirements strategies using available sources and methods to improve collection. Develops, processes, validates, and coordinates submission of intelligence collection requirements. Evaluates performance of intelligence collection assets and operations. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cyber Intelligence Planning |
Responsible for developing intelligence plans to satisfy cyber operation requirements. Identifies, validates, and levies requirements for intelligence collection and analysis. Participates in targeting selection, validation, synchronization, and execution of cyber actions. Synchronizes intelligence activities to support organization objectives in cyberspace. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Multi-Disciplined Language Analysis |
Responsible for applying language and cultural expertise with target, threat, and technical knowledge to process, analyze, and disseminate intelligence information derived from lanugage, voice, and/or graphic materials. Creates and maintains language-specific databases and working aids to support cyber action execution and ensure critical knowledge sharing. Provides subject matter experise in foreign language-intensive or interdisciplinary projects. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
NICE 7 Cyberspace Effects (CE) roles |
||
Cyberspace Operations |
Responsible for gathering evidence on criminal or foreign intelligence entities to mitigate and protect against possible or real-time threats. Conducts collection, processing, and geolocation of systems to exploit, locate, and track targets. Performs network navigation and tactical forensic analysis and executes on-net operations when directed. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Cyber Operations Planning |
Responsible for developing cybersecurity operations plans; participating in targeting selection, validation, and synchronization; and enabling integration during the execution of cyber actions. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Exploitation Analysis |
Responsible for identifying access and intelligence collection gaps that can be satisfied through cyber collection and/or preparation activities. Leverages all authorized resources and analytic techniques to penetrate targeted networks. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Mission Assessment |
Responsible for developing assessment plans and performance measures; conducting strategic and operational effectiveness assessments for cyber events; determining whether systems perform as expected; and providing input to the determination of operational effectiveness. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
|
|
Partner Integration Planning |
Responsible for advancing cooperation across organizaitonal or national borders betwen cyber operations partners. Provides guidance, resources, and collaboration to develop best practices and facilitate organizational support for achieving objectives in integrated cyber actions. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
||
Target Analysis |
Responsible for conducting target development at the system, component, and entity levels. Builds and maintains electronic target folders to include inputs from environment preparation and/or internal or external intelligence sources. Coordinates with partner target working groups and intelligence community members, and presents candidate targets for vetting and validation. Assesses and reports on damage resulting from the application of military force and coordinates federal support as required. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|
|
|
Target Network Analysis |
Responsible for conducting advanced analysis of collection and open-source data to ensure target continuity; profiling targets and their activities; and developing techniques to gain target information. Determines how targets communicate, move, operate, and live based on knowledge of target technologies, digital networks, and applications. |
|
Example job titles... | Look at these SFIA skills first… | Other SFIA skills to consider... |
|