+31 (0)88 88 321 88
V Skill HF-D7.6-002 sector-specific 9 kompetenser

Threat and risk analysis

Maps threats, weaknesses and consequences for a system or process, weighs likelihood against impact and names appropriate measures.

Hur hrmforce mäter detta

Bedömningsmetod
Work sample test · rho 0.33 (SD 0.09)
hrmforce instrument
Knowledge test (client-specific), Work sample test
Kompetens (50-ramverk)
Judgment
Utbildningsbarhet
medium
Prognos för efterfrågan 2026–2030
rising

The candidate performs a representative work sample under standardised conditions.

Beteendeankare

NivåBeteende på denna nivå
N1 Guided Completes a risk inventory using a given list of threats and submits the outcome to the specialist.
works under supervision and follows instruction · routine, one variable at a time · own task
N3 Proficient Independently performs a threat analysis on an application, prioritises risks and advises on measures with costs and effect.
sets own approach and seeks input proactively · several variables, some ambiguity · own team or process
N5 Leading Determines the organisation's risk appetite and analysis method and accounts for the security risk picture to the board.
sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession

N2 och N4 är medvetet inte förankrade. Bedömarna placerar dem mellan förankringarna, i enlighet med konventionen O*NET.

Grundläggande kompetenser

Dessa kompetenser ärver bedömningsvägen och beteendeankarna för detta konstrukt.

TKompetensDefinitionPrognos för efterfrågan 2026–2030
V Performing threat modelling
Threat modelling
Maps attack paths, attackers and weak spots per system and links measures to each path. rising
K Applying ISO 27001
ISO 27001 · ISMS
Applies the controls and risk method of iso 27001 and maintains the associated documentation. rising
K Applying NIS2
NIS2
Knows the nis2 obligations for risk management, reporting duty and management accountability and applies them. rising
K Applying the Dutch government baseline
Dutch government baseline
Applies the Dutch government baseline controls to public sector systems and justifies deviations with a risk assessment. rising
V Setting up vulnerability management
Vulnerability management
Tracks known vulnerabilities, prioritises on risk and monitors whether they are fixed within the deadline. rising
T Running a vulnerability scan
Vulnerability scanning
Runs an automated scan on systems or code and filters false positives out of the findings. rising
V Managing a penetration test
Penetration testing
Defines scope and rules for a penetration test, guides the execution and turns findings into actionable items. rising
V Maintaining a risk register
Risk register
Registers security risks with likelihood, impact, owner and measure and updates the status periodically. rising
V Assessing supplier risk
Third party risk
Assesses a supplier security on certification, interfaces and dependency and records requirements contractually. rising
Gratis demo