| SFIAplus includes EIGHT additional Skill resources: |
| Skill Resources | |
| SFIA SKill Title | Information security (SCTY) |
SFIA Skill / ISM Function Description |
The management of, and provision of expert advice on, the selection, design, justification, implementation and operation of information security controls and management strategies to maintain the confidentiality, integrity, availability, accountability and relevant compliance of information systems. |
Related SFIA Skills |
These are listed below:
|
Technical Overview, Including Typical Tools and Techniques |
Organisations have become increasingly dependent upon information systems and networks, and these are valuable business assets that need to be protected. As the sophistication and number of malicious software and hacking attacks continue to grow, the importance and necessity of effective IT security is becoming clearer. Effective IT Security means appropriately managing the business risks associated with Information Systems and networks, and there are a number of tools and techniques available to do this. Typical tools and techniques cover:
|
| Overview of Training, Development and Qualifications | Most of the 1000+ Computer Science, Computing or Information Systems / Technology related first degrees offered by UK universities incorporate some security content. Details of these can be found under the UCAS website www.ucas.ac.uk under the key word of "Computing". However there are a small number of first degrees which are focused more on Security, including Network Management and Security degrees, and few specifically on Information Security Management / Computer Systems Security. Details of these can be found under the UCAS website under the key word of "Security". The following internationally recognised professional qualifications are available:
The Information Systems Audit and Control Association (ISACA) offers two exam based qualifications: Certified Information Systems Auditor (CISA) and a Security Management qualification: Certified Information Security Manager (CISM), www.isaca.org, (or www.isaca.org.uk for UK regional information). The Cabinet Office’s www.cabinetoffice.gov.uk Infosec Training Paths and Competencies (ITPC) scheme is available to practitioners working on systems operated by HMG or other public bodies. The ITCP operation will be transferred to the Institute of Information Security Professionals (IISP) with effect from April 2009. The BCS ISEB www.iseb.org.uk offers exam based qualification in information security management. |
| Careers and Jobs | There are a small number of specialised IT Security job Sites including:- Jobs that require a UK security clearance can be found at www.clearedjobs.co.uk/index.asp. The BCS www.bcs.org/careers provides information on careers. |
| Professional Bodies | Internationally recognised bodies offering comprehensive information are:
Other associations and bodies that cater for information security professionals include:
|
| Standards and Codes of Practice | The following standards are relevant:
A Code of Conduct www.bcs.org/conduct and a Code of Good Practice www.bcs.org/practice are available from the BCS. |
| Communities and Events | The following communities are relevant:
|
| Publications and Resources | There are many security books, magazines, security related email lists, blogs, computer security conferences, and Web pages. Google and Amazon can help locate available material, but some useful computer security links and magazines are given below:
For those involved in projects for HMG, local authorities, or national infrastructure the CESG web site www.cesg.gov.uk/index.shtml is a useful starting point. The BCS www.bcs.org/publications publishes journals, books and magazines. |
|
Skills Framework for the Information Age © SFIA Foundation 2006 © Copyright BCS 2006
|