Threat and risk analysis
Maps threats, weaknesses and consequences for a system or process, weighs likelihood against impact and names appropriate measures.
How hrmforce measures this
- Assessment method
- Work sample test · rho 0.33 (SD 0.09)
- hrmforce instrument
- Knowledge test (client-specific), Work sample test
- Competency (50-framework)
- Judgment
- Trainability
- medium
- Demand outlook 2026 to 2030
- rising
The candidate performs a representative work sample under standardised conditions.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Completes a risk inventory using a given list of threats and submits the outcome to the specialist. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Independently performs a threat analysis on an application, prioritises risks and advises on measures with costs and effect. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Determines the organisation's risk appetite and analysis method and accounts for the security risk picture to the board. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| V | Performing threat modelling Threat modelling | Maps attack paths, attackers and weak spots per system and links measures to each path. | rising |
| K | Applying ISO 27001 ISO 27001 · ISMS | Applies the controls and risk method of iso 27001 and maintains the associated documentation. | rising |
| K | Applying NIS2 NIS2 | Knows the nis2 obligations for risk management, reporting duty and management accountability and applies them. | rising |
| K | Applying the Dutch government baseline Dutch government baseline | Applies the Dutch government baseline controls to public sector systems and justifies deviations with a risk assessment. | rising |
| V | Setting up vulnerability management Vulnerability management | Tracks known vulnerabilities, prioritises on risk and monitors whether they are fixed within the deadline. | rising |
| T | Running a vulnerability scan Vulnerability scanning | Runs an automated scan on systems or code and filters false positives out of the findings. | rising |
| V | Managing a penetration test Penetration testing | Defines scope and rules for a penetration test, guides the execution and turns findings into actionable items. | rising |
| V | Maintaining a risk register Risk register | Registers security risks with likelihood, impact, owner and measure and updates the status periodically. | rising |
| V | Assessing supplier risk Third party risk | Assesses a supplier security on certification, interfaces and dependency and records requirements contractually. | rising |