Assesses the potential vulnerabilities identified against established vulnerability databases.
SFIA Skills: Vulnerability assessment (VUAS)
Vulnerability assessment (VUAS) (Level 4)
Conducts automated and manual vulnerability assessments and business impact analyses. Creates test cases using in-depth technical analysis of risks and typical vulnerabilities. Assesses effectiveness of security controls for infrastructure and application components, and recommends remedial action.
Tools and techniques (VUAS) (Level 4)
Contributes to the selection and deployment of vulnerability assessment tools and techniques.
Risk mitigation (VUAS) (Level 4)
Delivers risk treatment plans using one or more recognised control sets.
Risk assessment (VUAS) (Level 4)
Produces a risk assessment table to determine the likelihood and impact to an information or technology asset if a vulnerability is exposed to a threat source, assigning a likelihood and impact to determine risk level. Documents the business impact of a vulnerability being breached.
Critical information and technology assets (VUAS) (Level 4)
Allocates an impact level to critical information and technology assets should their confidentiality, integrity or availability be breached. Collates and analyses catalogues of information and technology assets for vulnerability assessment.
Communication and awareness (VUAS) (Level 4)
Promotes security awareness and communicates information on security risks and potential business impact to senior business managers and others.
Assessment documentation (VUAS) (Level 4)
Documents a full vulnerability assessment and business impact analysis conducted on medium complexity information systems.
Vulnerability identification and analysis (VUAS) (Level 5)
Takes a comprehensive approach to seeking vulnerabilities across the full spectrum of organisation policies, processes, and defences in order to improve organisational readiness, improve training for defensive practitioners, and inspect current performance levels.
Vulnerability assessment (VUAS) (Level 5)
Plans and manages automated and manual vulnerability assessment activities within the organisation. Assesses effectiveness of security controls for infrastructure and application components and recommends remedial action.
Tools and techniques (VUAS) (Level 5)
Reviews, evaluates, and selects vulnerability tools and techniques.
Risk mitigation (VUAS) (Level 5)
Identifies control owners and holds them accountable for the implementation of policies to reduce the risk of controls allocated to them using a recognised methodology.
Risk assessment (VUAS) (Level 5)
Uses complex quantitative risk analysis methods such as exposure factor, single loss expectancy, annualised rate of occurrence or annualised loss expectancy, to conduct security risk assessments, business impact analysis and accreditation on complex information systems.
Critical information and technology assets (VUAS) (Level 5)
Determines a quantifiable value to the impairment of an identified critical information or technology asset.
Communication and awareness (VUAS) (Level 5)
Communicates to the organisation’s leadership information on security risks to critical information and technology assets, and the impact on the business should vulnerabilities be breached.
Assessment documentation (VUAS) (Level 5)
Documents a full vulnerability assessment and business impact analysis conducted on complex information systems.
Vulnerability identification and analysis (VUAS) (Level 3)
Determines the potential vulnerabilities that might breach a critical information asset.
Vulnerability assessment (VUAS) (Level 3)
Conducts automated and manual vulnerability assessments under direction. Undertakes moderate-complexity vulnerability assessments using more sophisticated techniques and tools.
Risk assessment (VUAS) (Level 3)
Assesses the likelihood of attack on critical information and technology asset vulnerabilities from a threat source. Assesses the business impact and determines a value to the potential loss should a vulnerability be breached.
Critical information and technology assets(VUAS) (Level 3)
Assigns asset information security requirements and catalogues identified critical information and technology assets for vulnerability assessment.
Communication and awareness (VUAS) (Level 3)
Promotes security awareness and communicates information on known security risks and issues to business managers and others.
Assessment documentation (VUAS) (Level 3)
Documents vulnerability assessments. Evaluates and documents results, escalating and communicating issues where appropriate.
Vulnerability identification and analysis (VUAS) (Level 2)
Identifies basic vulnerabilities that might breach a critical information or technology asset.
Vulnerability assessment (VUAS) (Level 2)
Undertakes routine vulnerability assessments using automated and semi-automated tools, escalating issues where appropriate. Participates, under supervision, in more complex assessments.
Critical information and technology assets (VUAS) (Level 2)
Identifies and documents critical information and technology assets within the organisation, including the asset type and asset location.
Communication and awareness (VUAS) (Level 2)
Promotes awareness of security risks and issues to colleagues and others.
Assessment documentation (VUAS) (Level 2)
Documents the scope and results of basic vulnerability assessments, or contributes to the documentation of more complex assessments.