Competencies: Security
Security
Overview
Information security encompasses protecting information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. This domain covers identity and access management, network access control, cryptography, offensive and defensive security, application security, governance and compliance, cloud security, forensics, and security architecture.
Industry Frameworks
-
CISSP — comprehensive security management and architecture
-
CompTIA Security+/CySA+/CASP+ — vendor-neutral security progression
-
NICE Cybersecurity Workforce Framework — role-based security competencies
-
OWASP — application security
-
MITRE ATT&CK — adversarial tactics and techniques
Subdomains
| Subdomain | Topics | Personal Coverage | Avg Level |
|---|---|---|---|
18 |
High |
Advanced |
|
18 |
Moderate |
Intermediate |
|
18 |
High |
Expert |
|
17 |
Low |
Beginner |
|
15 |
Moderate |
Intermediate |
|
15 |
Moderate |
Intermediate |
|
15 |
Low |
Beginner |
|
14 |
Low |
Beginner |
|
14 |
None |
— |
|
14 |
None |
— |