Reserve levy spend interest

Talk to Oaks about workforce training

business and administration

Cyber security technician

Auto-created from legacy migration wizard.

Cyber security technician

Course overview

Version v1.1

Level
3
Type
standard
Duration
18 months
Awarding body
CompTIA
Course code
ST0865
Minimum OTJ hours
187

Description

Auto-created from legacy migration wizard.

What you will learn

Knowledge, skills and behaviours grouped by occupational duty.

  • K1

    K1

    Principles of organisational information security governance and the components of an organisation's cyber security technical infrastructure including hardware, operating systems, networks, software and cloud

  • K2

    K2

    Cyber security policies and standards based on an Information Security Management System (ISMS)

  • K3

    K3

    Types of physical, procedural and technical controls

  • K4

    K4

    Awareness of how current legislation relates to or impacts upon the occupation including Data Protection Act, Regulation of Investigatory Powers Act, Human Rights Act, Computer Misuse Act, Freedom of Information Act, Official Secrets Act, Payment Card Industry Data Security Standard (PCI-DSS), Wireless and Telegraphy Act, professional body codes of conduct, ethical use of information assets

  • K7

    K7

    Core terminology of cyber security – confidentiality, integrity, availability (the CIA triad), assurance, authenticity, identification, authentication, authorization, accountability, reliability, non-repudiation, access control

  • K29

    K29

    How to use data ethically and the implications for wider society, with respect to the use of data

  • K5

    K5

    Cyber security awareness and components of an effective security culture, different organisational structures and cultures, the importance of maintaining privacy and confidentiality of an organisation's information and the impact of a poor security culture

  • K6

    K6

    Principles of cyber security compliance and compliance monitoring techniques

  • K25

    K25

    Importance of maintaining privacy and confidentiality of an organisations information and the impact of a poor security culture

  • K30

    K30

    Roles within a multidisciplinary team and the interfaces with other areas of an organisation

  • K8

    K8

    Common security administrative operational tasks e.g. patching, software updates, access control, configuring a range of firewalls, security incident and event management tools (SIEM) and protection tools (Anti-virus, Anti-malware, Anti-spam)

  • K22

    K22

    The significance of customer issues, problems, business value, brand awareness, cultural awareness/ diversity, accessibility, internal/ external audience, level of technical knowledge and profile in a business context

  • K26

    K26

    Concepts of service desk delivery and how to respond to requests for assistance received by a service desk and be able to describe different methods of escalation, when to escalate to a higher level where necessary and the need to communicate accurately and appropriately during an escalation

  • K9

    K9

    Cryptography, certificates and use of certificate management tools

  • K10

    K10

    Processes for detecting, reporting, assessing, responding to, dealing with and learning from information security events

  • K17

    K17

    Types of information security events – brute force attack, malware activity, suspicious user behaviour, suspicious device behaviour, unauthorized system changes

  • K19

    K19

    Standard information security event incident, exception and management reporting requirements and how to document incident and event information as part of a chain or evidence

  • K11

    K11

    Principles of identity and access management - authentication, authorisation and federation - and the inter-relationship between privacy and access rights and access control, and the types of access control, access control mechanisms and application control

  • K12

    K12

    Types of digital information assets used in a controlled environment and the need to maintain an inventory of information assets used in a controlled environment and the need for and practice of secure information asset disposal

  • K13

    K13

    Disaster prevention and recovery methods and the need for continuity of service planning and how an organisation might implement basic disaster prevention and recovery practices using conventional and incremental secure backup and recovery techniques and tools both onsite and offsite including geographic considerations

  • K15

    K15

    Components of a vulnerability assessment scope and techniques to evaluate the results of a vulnerability assessment and provide recommendations based upon the evidence provided by the vulnerability assessment tools. The impact that vulnerabilities might have on an organisation and common vulnerability assessment tools and their strengths and weaknesses

  • K14

    K14

    Categories of cyber security vulnerabilities and common vulnerability exposures –software misconfiguration, sensitive data exposure, injection vulnerabilities, using components with known vulnerabilities, insufficient logging and monitoring, broken access control and authentication, security misconfiguration, incorrect cross-site validation

  • K16

    K16

    Threat sources and threat identification and network reconnaissance techniques and the impact that threats might have on an organisation

  • K18

    K18

    Computer forensic principles – the importance of ensuring that evidence is not contaminated and maintaining the continuity of evidence without compromising it

  • K20

    K20

    Common information security policies – acceptable use, incident management, patching, anti-virus, BYOD, access control, social media, password, data handling and data classification, IT asset disposal

  • K27

    K27

    Risk assessment, risk management and business impact analysis principles

  • K21

    K21

    Cyber security audit requirements, procedures and plans, need to obtain and document evidence in an appropriate form for an internal or external auditor to review

  • K23

    K23

    Evolving cyber security issues in the digital world including the application to critical national infrastructure, communications technologies, the need for information assurance and governance, control systems and internet of things (IoT) devices

  • K24

    K24

    Different learning techniques and the breadth and sources of knowledge and sources of verified information and data

  • K28

    K28

    How their occupation fits into the wider digital landscape and any current or future regulatory requirements

  • S1

    S1

    Follow information security procedures

  • S2

    S2

    Maintain information security controls

  • S21

    S21

    Communication skills to co-operate as part of a multi-functional, multi-disciplinary team using a range of technical and non-technical language to provide an effective interface between internal or external users and suppliers

  • S22

    S22

    Keep up-to-date with legislation and industry standards related to the implementation of cyber security in an organisation

  • S3

    S3

    Develop information security training and awareness resources

  • S4

    S4

    Monitor the effectiveness of information security training and awareness

  • S5

    S5

    Handle and assess the validity of security requests from a range of internal and external stakeholders

  • S6

    S6

    Follow technical procedures to install and maintain technical security controls

  • S7

    S7

    Monitor and report information security events

  • S8

    S8

    Recognise when and how to escalate information security events in accordance with relevant procedures and standards

  • S9

    S9

    Review and modify access rights to digital information systems, services, devices or data

  • S10

    S10

    Maintain an inventory of digital information systems, services, devices and data storage

  • S11

    S11

    Scopes cyber security vulnerability assessments

  • S12

    S12

    Evaluate the results of a cyber security vulnerability assessment

  • S14

    S14

    Undertake digital information risk assessments

  • S15

    S15

    Identify and categorise threats, vulnerabilities and risks in preparation for response or escalation

  • S13

    S13

    Perform routine threat intelligence gathering tasks through consulting external sources

  • S16

    S16

    Document cyber security event information whilst preserving evidence

  • S17

    S17

    Draft information management reports using standard formats appropriate to the recipients

  • S19

    S19

    Perform cyber security compliance checks

  • S18

    S18

    Review and comment upon cyber security policies, procedures, standards and guidelines

  • S20

    S20

    Translate audit requirements and collate relevant information from log files, incident reports and other data sources

  • B2

    B2

    Work independently and take responsibility for own actions within the occupation

  • B4

    B4

    A structured approach to the prioritisation of tasks

  • B5

    B5

    Treat colleagues and external stakeholders fairly and with respect without bias or discrimination

  • B6

    B6

    Act in accordance with occupation specific laws, regulations and professional standards and not accept instruction that is incompatible with any of these

  • B1

    B1

    Manage own time to meet deadlines and manage stakeholder expectations

  • B3

    B3

    Use own initiative

  • B7

    B7

    Review own development needs in order to keep up to date with evolution in technologies, trends and innovation using a range of sources