EQF level 4
Learning outcomes
Knowledge
Describes national and EU legal regulations concerning cybersecurity
Verification criteria
- Identifies key EU and national legal acts regulating cybersecurity, for example NIS2 and KSC.
- Distinguishes between entities' obligations arising from cybersecurity regulations depending on the sector of activity.
Validation method: Theoretical test
Describes the principles of conducting audits of ICT systems
Verification criteria
- Lists the stages of the ICT systems audit process.
- Identifies the elements of audit documentation required at each stage of the audit.
Validation method: Theoretical test
Describes the elements of organizational, personnel and technical security policy
Verification criteria
- Distinguishes between organizational, personnel and technical security areas in security policy documentation.
- Identifies the required elements of ICT systems security policy documentation.
Validation method: Theoretical test
Describes risk analysis methods in the area of cybersecurity
Verification criteria
- Lists the stages of the risk analysis process in cybersecurity.
- Classifies types of threats to ICT systems according to risk level.
Validation method: Theoretical test
Describes the principles of personal data protection in ICT systems
Verification criteria
- Identifies the basic principles of personal data processing arising from GDPR.
- Distinguishes between types of personal data breaches and the related notification obligations.
Validation method: Theoretical test
Skills
Indicates the approach to designing cybersecurity procedures
Verification criteria
- Indicates the correct sequence of stages in developing a cybersecurity incident response procedure.
- Selects the appropriate corrective action for a given type of security incident.
Validation method: Theoretical test
Indicates how to select technical and organizational safeguards appropriate to the identified risk
Verification criteria
- Selects appropriate protective measures for a given risk level and asset type.
- Indicates the consequences of applying inadequate safeguards in a described scenario.
Validation method: Theoretical test
Indicates how to verify the organization's compliance with audit requirements
Verification criteria
- Indicates the correct sequence of control activities at a given stage of the audit.
- Assesses the correctness of described documentation in terms of compliance with audit requirements.
Validation method: Theoretical test
Social competences
Indicates the importance of professional responsibility in the area of cybersecurity
Verification criteria
- Indicates the consequences of failing to report an identified security incident.
- Indicates the correct course of action in a situation of conflict between business requirements and security principles.
Validation method: Theoretical test
Indicates the principles of cooperation within a team responsible for cybersecurity management
Verification criteria
- Indicates the division of responsibilities between roles in a typical cybersecurity team structure.
- Recognizes situations requiring escalation of an issue to a supervisor or another member of the cybersecurity team.
Validation method: Theoretical test