The Workforce Framework for Cybersecurity, commonly referred to as the NICE Framework, is a nationally focused resource to help employers develop their cybersecurity workforce. It establishes a common lexicon that describes cybersecurity work and workers regardless of where or for whom the work is performed. The NICE Framework applies across public, private, and academic sectors.

The NICE program of the National Institute for Standards and Technology (NIST) released NICE Framework Components v1.0.0(link is external) in March 2024. This data includes changes to Work Role Categories and Work Role names and descriptions; 11 Competency Areas; new Insider Threat Analysis Work Role; and updates to align Task, Knowledge, and Skill (TKS) statements with the TKS Authoring Guide principles(link is external).

The NICE Framework includes the following components: 

  • Work Role Categories (7): A high-level grouping of common cybersecurity functions
  • Work Roles (52): A grouping of work for which someone is responsible or accountable. Please note, Work Roles are not synonymous to job titles or occupations.
  • TKS Statements (2,200+): A set of discrete building blocks that describe the work to be done (in the form of Tasks) and what is required to perform that work (through Knowledge and Skills).
  • Competency Areas (11): Clusters of related Knowledge and Skill statements that correlate with one’s capability to perform Tasks in a particular domain.

To explore the updated version of the NICE Framework, click on the Work Role Categories below or use the links at the top of this page to search within the NICE Framework components. To learn more, visit the NICE Framework Resource Center(link is external) and review the NICE Framework Overview PDF(link is external).

Work Role Categories

Work Roles

Defensive Cybersecurity

Responsible for analyzing data collected from various cybersecurity defense tools to mitigate risks.

Digital Forensics

Responsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation.

Incident Response

Responsible for investigating, analyzing, and responding to network cybersecurity incidents.

Infrastructure Support

Responsible for testing, implementing, deploying, maintaining, and administering infrastructure hardware and software for cybersecurity.

Insider Threat Analysis

Responsible for identifying and assessing the capabilities and activities of cybersecurity insider threats; produces findings to help initialize and support law enforcement and counterintelligence activities and investigations.

Threat Analysis

Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Vulnerability Analysis

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

The NICE Framework data used for this tool is from the NICE Framework Components v1.0.0.(link is external)