Hybrid programs blend both competency- and time-based strategies,
using a minimum and maximum range of hours for each major job
function and the successful demonstration of identified competencies.
using a minimum and maximum range of hours for each major job
function and the successful demonstration of identified competencies.
Information Security Analyst
Anonymous
National (OA)
Work Process Content
On the Job Training
Anonymous
69
Skills
Hours do not meet minimum OA standard for this occupation
4K
OJT hours
Assists in developing security policies and protocols; assists in enforcing company compliance with network security policies and protocols
9
480
Assists in developing security policies and protocols; assists in enforcing company compliance with network security policies and protocols
9
480
- Locates (in intranet, employee handbook security handbook or security protocols) organizational policies intended to maintain security and minimize risk and explains use.
- Provides guidance to employees on how to access networks, set passwords, reduce security threats and provide defensive measures associated with searches, software downloads, email, internet, add-ons, software coding and transferred files.
- Ensures that password characteristics are explained and enforced and that updates are required and enforced based on appropriate intervals.
- Explains company or organization’s policies regarding the storage, use and transfer of sensitive data, including intellectual property and personally identifiable information. Identifies data life cycle, data storage facilities, technologies, and describes business continuity risks.
- Monitors compliance for information and security audits/reviews.
- Advise employees in the use of technologies that restrict or allow for remote access to the organization’s information technology network.
- Develops security compliance policies and protocols for external services (i.e. Cloud service provider, software services, external data centers).
- Complies with incident response and handling methodologies.
- Articulates the business need or mission of the organization as it pertains to the use of IT systems and the storage of sensitive data.
Provides technical support to users or customers. Applies security policies to meet security objectives of the system
3
480
Provides technical support to users or customers. Applies security policies to meet security objectives of the system
3
480
- Diagnoses and resolves customer-reported cyber related incidents.
- Audit accounts, network rights, and access to systems and equipment.
- Architect security measures for uses in system and ensures that system designs incorporate security configuration guidelines.
Ensure that infrastructure deployed meets departmental security standards and is in compliance with security policy
9
530
Ensure that infrastructure deployed meets departmental security standards and is in compliance with security policy
9
530
- Collaborates with system developers and users to assist in the selection of appropriate design solutions to ensure the compatibility of system components.
- Audit or scan, network hubs, routers switches.
- Reviews and approves technology recovery plan and system recovery plan backup and recovery procedures.
- Assist in the diagnoses or network connectivity problems.
- Scans for network vulnerabilities to ensure information is safeguarded against outside parties.
- Establishes standards for adequate access controls based on principles of least privilege and need-to-know.
- Establish security standards for users in system and ensures that system designs incorporate security configuration guidelines.
- Education and outreach on security best practices.
- Assess cloud security playbooks and standards to ensure secure cloud provisioning.
Ensures that software deployed meets departmental security standards and is in compliance with security policy
8
530
Ensures that software deployed meets departmental security standards and is in compliance with security policy
8
530
- Sets the standards for group policies and access control lists and audits to ensure compliance with security standards.
- Oversees compliance with or changes to system administration standard operating procedures.
- Maintains baseline system security standards according to organizational policies.
- Audits accounts, network rights and access to systems and equipment.
- Validate data redundancy and system recovery procedures.
- Assists in the coordination or installation of new or modified hardware, operating systems and other baseline software.
- Provides ongoing optimization and problem-solving support.
- Establishes standards and audits access controls based on principles of least privilege, role-based access controls (RBAC) and need-to-know.
Performs technical and non-technical risk and vulnerability assessments of relevant technology focus areas.
5
530
Performs technical and non-technical risk and vulnerability assessments of relevant technology focus areas.
5
530
- Establish standards for cyber security detection, monitoring and threat management software.
- Coordinates with network administrators to administer the updating of rules and signatures for intrusion/detection protection system.
- Manages IP addresses based on current threat environment.
- Ensures application of security patches for commercial products integrated into system design.
- Uses computer network defense tools for continual monitoring and analysis of system activity to identify malicious activity.
Assess IT systems, software, business continuity and related security risks and vulnerabilities; assist in the development of mitigation strategies to reduce departmental risk.
12
550
Assess IT systems, software, business continuity and related security risks and vulnerabilities; assist in the development of mitigation strategies to reduce departmental risk.
12
550
- Applies security policies to meet security objectives of the system.
- Performs scanning to ensure current defense applications are in place, including on Virtual Private Network devices.
- Validate data back up and restoration systems are functional and consistent with company’s document retention policy and business continuity needs.
- Identifies potential conflicts with implementation of any computer network defense tools. Performs tool signature testing and optimization.
- Installs, manages and updates intrusion detection system.
- Performs technical and non-technical risk and vulnerability assessments of relevant technology focus areas.
- Conducts authorized penetration testing (Wi-Fi, network perimeter, application security, cloud, mobile devices) and assesses results.
- Documents systems security operations and maintenance activities.
- Communicates potential risks or vulnerabilities to manager. Collaborates with others to recommend vulnerability corrections.
- Identifies information technology security program implications of new technologies or technology upgrades.
- Approves System Security Plans.
- Collaborate on the categorization and classification of data systems.
Communicates potential risks or vulnerabilities to manager. Collaborates with others to recommend vulnerability correction.
12
550
Communicates potential risks or vulnerabilities to manager. Collaborates with others to recommend vulnerability correction.
12
550
- Identifies organizational trends with regard to the security posture of systems; identifies unusual patterns or activities.
- Characterizes and analyzes network traffic to identify anomalous activity and potential threats; performs computer network defense trend analysis and reporting.
- Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts.
- Runs tests to detect real or potential threats, viruses, malware, etc.
- Assists in researching cost-effective security controls to mitigate risks.
- Helps perform damage assessments in the event of an attack.
- Monitors network data to identify unusual activity, trends, unauthorized devices or other potential vulnerabilities.
- Documents and escalates incidents that may cause immediate or long term impact to the environment.
- Provides timely detection, identification and alerts of possible attacks and intrusions, anomalous activities, and distinguish these incidents and events from normal baseline activities.
- Uses network monitoring tools to capture and analyze network traffic associated with malicious activity.
- Performs intrusion analysis.
- Sets containment blockers to align with company policy regarding computer use and web access.
Responds to cyber intrusions and attacks and provides defensive strategies.
11
380
Responds to cyber intrusions and attacks and provides defensive strategies.
11
380
- Assists in the development of appropriate courses of action in response to identified anomalous network activity.
- Triages systems operations impact: malware, worms, man-in-the-middle attack, denial of service, rootkits, keystroke loggers, SQL injection and cross-site scripting.
- Reconstructs a malicious attack or activity based on network traffic.
- Correlates incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
- Monitors external data sources to maintain currency of Computer Network Defense threat condition and determines which security issues may have an impact on the enterprise. Performs file signature analysis.
- Performs analysis of log files from a variety of sources to identify threats to network security; performs file signature analysis.
- Performs computer network defense incident triage to include determining scope, urgency and potential impact; identifies the specific vulnerability; provides training recommendations; and makes recommendations that enable expeditious remediation.
- Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts.
- Tracks and documents computer network defense incidents from initial detection through final resolution.
- Collects intrusion artifacts and uses discovered data to enable mitigation of potential computer network defense (CND) incidents.
- Performs virus scanning on digital media.
Related Instruction Content
Training Provider(s):
American River College
960
RI hours
Cisco Network Academy (CCNA)™ Networking Fundamentals
72
Cisco Network Academy (CCNA)™ Networking Fundamentals
72
Systems and Network Administration
72
Systems and Network Administration
72
Network Security Fundamentals
72
Network Security Fundamentals
72
Ethical Hacking
72
Ethical Hacking
72
Cisco Networking Academy™: CCNA Cybersecurity Operations
72
Cisco Networking Academy™: CCNA Cybersecurity Operations
72
Scripting – Bash/PowerShell/Other
72
Scripting – Bash/PowerShell/Other
72
Implementing Internet Security & Firewalls
72
Implementing Internet Security & Firewalls
72
Disaster Recovery
54
Disaster Recovery
54
Computer Forensics & Investigation
72
Computer Forensics & Investigation
72
Implementing Windows Operating System Security
72
Implementing Windows Operating System Security
72
Implementing Linux Operating System Security
72
Implementing Linux Operating System Security
72
GTA Writing Course
8
GTA Writing Course
8
English for Business Professionals
54
English for Business Professionals
54
Business Communications
54
Business Communications
54
Department Specific Leadership Training
Department Specific Leadership Training
Introduction to Leadership in Action
54
Introduction to Leadership in Action
54
Reading Across the Disciplines for Content Courses
9
Reading Across the Disciplines for Content Courses
9
Writing Across the Curriculum
9
Writing Across the Curriculum
9