-
Understand Security & Risk Management: ethics, security concepts,
governance, compliance, law/regulation, policies/procedures, threat
models, supply chain risk, awareness training, and more
-
Ensure Secure Assets: identify/classify information and assets;
handling requirements, resource provisioning, data lifecycles,
retention
-
Review Security Architecture & Engineering: secure processes and
principles, security models and controls, system capabilities,
vulnerability assessment/mitigation, crypto attacks/solutions,
site/facility design and controls
-
Improve Communication & Network Security: secure network
architectures, components, and channels
-
Strengthen Identity & Access Management (IAM): physical/logical access
control, identification, authentication, federated identity services,
authorization, identity/access provisioning
-
Enhance Security Assessment & Testing: design/validate assessment,
test, and audit strategies; test controls; collect process data;
evaluate and report test results; conduct or support audits
-
Manage Security Operations: investigations, logs, monitoring, resource
protection, incident management, detection/prevention; configuration,
patches, vulnerabilities, and change
-
management; DR/BC, physical and personnel security, and more