Ability ID: A0001
Ability Description: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
Work Roles with this Ability:
- Work Role ID: PR-VAM-001Work Roles: Vulnerability Assessment AnalystWork Role Description: Performs assessments of systems and networks within the network environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Category: Protect and DefendSpecialty Area(s): Vulnerability Assessment and Management
- Work Role ID: SP-RSK-002Work Roles: Security Control AssessorWork Role Description: Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).Category: Securely ProvisionSpecialty Area(s): Risk Management
- Work Role ID: SP-SYS-001Work Roles: Information Systems Security DeveloperWork Role Description: Designs, develops, tests, and evaluates information system security throughout the systems development life cycle.Category: Securely ProvisionSpecialty Area(s): Systems Development
- Work Role ID: SP-TRD-001Work Roles: Research & Development SpecialistWork Role Description: Conducts software and systems engineering and software systems research to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.Category: Securely ProvisionSpecialty Area(s): Technology R&D