SGC Job Analysis Questionnaire - R3G33 - Intrusion Analyst

 

 

You have completed 0% of this survey
0%
100%

For the role of Intrusion Analyst in the Smartgrid Cybersecurity environment, please indicate how frequently each task below would be performed by a person at the listed level of expertise, and how important is it that this task be completed by a person with the listed level of expertise.
*Identify observables that flow from particular attacker Tactics, Techniques, and Procedures (TTPs) to optimize your security monitoring capabilities (Task ID: R3-9811)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Identify external scanning needs than an internal scanner may not adequately be able to assess (Task ID: R3-9275)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Identify external scanning needs that an internal scanner may not adequately be able to assess (Task ID: R3-9547)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Monitor for new systems installed on the network. (Task ID: R3-9544)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Report test completion providing a summary of what was tested with results to management (Task ID: R3-9402)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Scan against configuration anomalies. (Task ID: R3-9425)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Scan for gaps in system configuration against a benchmark configuration manual. (Task ID: R3-9444)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Scan internal and external networks for new and unauthorized systems. (Task ID: R3-9554)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Scan internal and external networks for new and unauthorized systems. (Task ID: R3-9555)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Assign a technical POC for vulnerability remediation and assistance (Task ID: R3-9624)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Decide the risk ratings of the vulnerability based on the technical information and how the technology is deployed/importance of the systems (Task ID: R3-9625)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Develop appropriate mitigations after consulting with the vendor/integrators and internal system owners (Task ID: R3-9626)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Document all vulnerability information alerts or disclosures that apply to deployed technology and note the time and responsible party to develop the risk picture and initiate workflow (Task ID: R3-9623)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)
 
*Implement vulnerability mitigations in accordance with the plan to include patches or additional security controls (Task ID: R3-9627)
  Frequency   Importance
  Never Rarely Sometimes Often Always   Unimportant Low Moderately Very Extremely
Novice (Apprentice)  
Intermediate (Journeyman)  
Expert
(Master)