of July 7, 2026 No. 392/Tax Code
About modification of the order of the Minister of digital development, innovations and the aerospace industry of the Republic of Kazakhstan of June 30, 2025 No. 329/Tax Code "About approval of the professional standard "Activities in the field of Cyber Security"
I ORDER:
1. Bring in the order of the Minister of digital development, innovations and the aerospace industry of the Republic of Kazakhstan of June 30, 2025 No. 329/Tax Code "About approval of the professional standard "Activities in the field of Cyber Security" the following change:
Professional standard: "Activities in the field of cyber security", approved by the specified order to be reworded as follows according to appendix to this order.
2. To provide to committee of information security of the Ministry of artificial intelligence and digital development of the Republic of Kazakhstan in the procedure established by the legislation of the Republic of Kazakhstan:
1) within five calendar days after signing of this order the direction it in the Kazakh and Russian languages in the Republican state company on the right of economic maintaining "Institute of the legislation and legal information of the Republic of Kazakhstan" the Ministries of Justice of the Republic of Kazakhstan for official publication and inclusion in Reference control bank of regulatory legal acts of the Republic of Kazakhstan;
2) placement of this order on Internet resource of the Ministry of artificial intelligence and digital development of the Republic of Kazakhstan after its official publication.
3. To impose control of execution of this order on the supervising vice-minister of artificial intelligence and digital development of the Republic of Kazakhstan.
4. This order becomes effective after ten calendar days after day of its first official publication.
Acting minister of artificial intelligence and digital development of the Republic of Kazakhstan
R. Konyashkin
|
It is approved Ministry of Labour and Social Protection of the population of the Republic of Kazakhstan |
|
Appendix
to the Order of the Acting Minister of artificial intelligence and digital development of the Republic of Kazakhstan of July 7, 2026 No. 392/Tax Code
Approved by the Order of the Minister of digital development, innovations and the aerospace industry of the Republic of Kazakhstan of June 30, 2025, No. 329/Tax Code
1. Scope of the professional standard: The professional standard "Activities in the field of Cyber Security" is developed according to article 5 of the Law of the Republic of Kazakhstan "About professional qualifications" and can be applied when forming requirements to the job seeker to employment, forming of educational programs, including personnel trainings at the companies, recognitions of professional qualification of workers and graduates of the organizations of education, and also to the solution of wide range of tasks in the field of personnel management in the organizations and at the companies.
2. In this professional standard the following terms and determinations are applied:
1) Systems thinking – Ability of the specialist to combine (to generalize) the private facts in overall picture, to build hierarchical levels for understanding of different situations (economic, political, business) and adoptions of long-term decisions. Important quality is the understanding of how change of one element can be reflected in other elements;
2) Cyber security (further – CB) – condition of security of digital objects from violation of their confidentiality, integrity or availability;
3) Digital technologies (further – TsT) – set of methods of work with electronic information resources and the methods of information exchange performed using the hardware and software and network of telecommunications.
3. In this professional standard the following reducings are applied:
1) TKUI – Technical channels of information leakage;
2) KS – Job evaluation catalogs;
3) the PASS – Software and hardware;
4) ON – Software;
5) ETKS – Single wage rate book;
6) PD – Personal data;
7) SVT – Computer aids;
8) PEMIN – Collateral electromagnetic radiations and aimings;
9) limited liability partnership – Limited liability partnership;
10) OYuL – Consolidation of legal entities;
11) NAO – Non-commercial joint-stock company;
12) CB – Cyber security;
13) ZRK – Law of the Republic of Kazakhstan;
14) DBMS – Database management system;
15) NPA – Regulatory legal acts;
16) specifications and technical documentation – Specifications and technical documentation;
17) OS – Operating system;
18) ND – Unauthorized access;
19) ORK – Industry frame of qualifications;
20) TsS – Digital systems;
21) TsT – Digital technologies;
22) EMK – Electronic medical records;
23) ACL – Access Control List;
24) API – Application Programming Interface;
25) BASH – Bourne Again SHell;
26) BDA – Battle Damage Assessment;
27) CARVER – The analysis technique is more whole;
28) COA – Course of Action;
29) DoS – Denial of Service;
30) HIDS – Host Intrusion Detection System;
31) HIPS – Host Intrusion Prevention System;
32) ICS – Industrial Control Systems;
33) IDS – Intrusion detection system;
34) IoT – Internet of Things;
35) IPS – Intrusion prevention system;
36) ISO – International Organization for Standardization;
37) JS – JavaScript;
38) KPI – Key Performance Indicators;
39) KRI – Key Risk Indicators;
40) NIDS – Network Intrusion Detection System;
41) NIPS – Network Intrusion Prevention System;
42) SIEM – Security Information and Event Management;
43) SQL – Structured Query Language;
44) SQLi – SQL injection;
45) TLP – Traffic Light Protocol;
36) TTPs – Tactics, Techniques, and Procedures;
47) VPN – Virtual Private Network;
48) XSS – Cross-Site Scripting.
4. Name of the professional standard: Activities in the field of cyber security
5. Code of the professional standard: J62092101
6. Instruction of section, the Section, group, class and subclass agrees OKED:
J Information and communication
62 Computer programming, the consulting and other accompanying services
62.0 Computer programming, the consulting and other accompanying services
62.09 Other types of activity in the field of information technologies and information systems
62.09. 2 Activities in the field of cyber security
7. Short description of the professional standard: The professional standard "Activities in the field of Cyber Security" is developed according to article 5 of the Law of the Republic of Kazakhstan "About professional qualifications"
8. List of cards of professions:
1) the Administrator on information security - the 7th ORK level
2) the Specialist in safety issues (ICT) - the 7th ORK level
3) the Specialist criminalist on digital technologies - the 7th ORK level
4) the information security Specialist - the 7th ORK level
5) the Auditor on information security - the 7th ORK level
6) the information security Specialist - the 7th ORK level
7) the Security specialist of services - the 7th ORK level
8) The encoder of data - the 7th ORK level
9) the Information protection engineer - the 7th ORK level
10) the risk management Manager (Risk Manager-SP-RSK-001) - the 6th ORK level
11) the Developer is more whole - the 6th ORK level
12) the Operator of cybertransactions - the 6th ORK level
13) the Cyber-instructor - the 6th ORK level
14) the researches and developments Specialist - the 6th ORK level
15) the IT Manager to investments/portfolio - the 6th ORK level
16) the Manager programs - the 6th ORK level
17) the Analyst of threats and preventions - the 6th ORK level
18) the network transactions Specialist - the 6th ORK level
19) the Scheduler of cybertransactions - the 6th ORK level
20) the Architect of corporate infrastructure - the 6th ORK level
21) the information security Specialist - the 6th ORK level
22) the Cyber-legal consultant - the 6th ORK level
23) the Authorized representative / responsible for authorization - the 6th ORK level
24) the Specialist in information security of transport infrastructure - the 6th ORK level
25) the Specialist criminalist on digital technologies - the 6th ORK level
26) the Manager of knowledge - the 6th ORK level
27) the Analyst on law-enforcement/judicial examination and counterintelligence - the 6th ORK level
28) the Encoder of data - the 6th ORK level
29) the Auditor on information security - the 6th ORK level
30) the Security specialist of services - the 6th ORK level
31) the multilingual analysis Specialist - the 6th ORK level
32) the information security Specialist in the field of health care - the 6th ORK level
33) the Information protection engineer - the 6th ORK level
34) the information security Specialist - the 6th ORK level
35) the Specialist in safety issues (ICT) - the 6th ORK level
|
9. Profession card "Administrator on information security": | |||
|
Group code: |
2524-0 | ||
|
Code of the name of occupation: |
2524-0-001 | ||
|
Name of profession: |
The administrator on information security | ||
|
Skill level on the ORK: |
7 | ||
|
qualification subtotal on the ORK: |
|||
|
Skill level on ETKC, KC and other standard qualification characteristics: |
|||
|
Level of professional education: |
Education level: postgraduate education (magistracy, residency) |
Specialty: Information security |
Qualification: - |
|
Requirements to work experience: |
1. The specialist in safety of information in key systems of information infrastructure of the I category: the highest (or postgraduate) education in the corresponding direction of training and length of service as the specialist in safety of information in key systems of information infrastructure of the II category at least 2 years | ||
|
Communication with informal and informalny education: |
Additional professional courses of advanced training in the field of cyber security | ||
|
Other possible names of profession: |
|||
|
Main objective of activities: |
Administer mechanisms of safety and to react timely to violations of CB | ||
|
Description of labor functions | |||
|
List of labor functions: |
Obligatory labor functions: |
1. Administration, operation and support of working capacity PASS of information security and providing CB 2. Administration of mechanisms of safety 3. Response to incidents of CB 4. Control and efficiency analysis of application the PASS are sewn up information and providing CB | |
|
Additional labor functions: |
|||
|
Labor function 1: Administration, operation and support of working capacity PASS of information security and providing CB |
|||
|
Skill 1: Maintaining reporting documentation |
Abilities: 1. Constitute reports on safety incidents, including the description of incident, actions taken for threat elimination, the analysis of the reasons, and also results of investigation 2. To regularly update and keep logs of safety, including information on access attempts, unauthorized actions and other events 3. Create and support documentation on politicians and procedures of safety, including policy of access, enciphering of data and use of passwords 4. Messages the reporting under vulnerabilities and patch management and timely to constitute reports on the current vulnerabilities and patches 5. Document procedures of response to incidents including step-by-step instructions for liquidation of threats, recovery of data and minimization of damage | ||
|
Knowledge: 1. Standards and requirements to the reporting in the field of cyber security 2. Understanding of structure and formats of the reporting, procedure for their creation 3. Methods of the analysis and data processing of safety, interpretation of data from logs of safety and other sources 4. The principles of maintaining logs and incidents, including registration of all significant events 5. The principles and change management processes and incidents in safety infrastructure | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Administration of system of detection / prevention of invasions |
Abilities: 1. Perform complex monitoring of safety of network using detection systems and prevention of invasions (IDS/IPS), providing timely response to potential hazards and realization the politician of cyber security 2. Administer accounting records of users with realization of strict differentiation of access rights, applying methods of role access (RBAC), and also realizing segmentation of network infrastructure and traffic filtering according to the principles of Zero Trust 3. Adjust and accompany password policy of the organization, including requirements to complexity of passwords, frequency of their change, and also realizing mechanisms of automatic blocking of accounting records in case of authentication abuse of regulations 4. Carry out configuring of parameters of network access, including setup of VPN, network screens, NAT, DHCP, ACL and other components, providing safe and controlled connection to resources of network 5. Limit access to crucial resources to IP addresses, hosts and subnets, minimizing the surface of the attack and excepting unauthorized access from the outside 6. Manage process of updating of the software in corporate environment, including testing, planning and centralized expansion of updates, for the purpose of increase in security and stability of IT infrastructure | ||
|
Knowledge: 1. Appointment, principles of action, architecture of systems of detection/prevention of invasions 2. The standards regulating functioning of systems of detection of invasions 3. Recommendations of the producer of system of detection/prevention of invasions about its installation and operation 4. Types and methods of detection of invasions 5. The technologies and tools used in systems of prevention of invasions | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 3: Configuring and setup of the firewall |
Abilities: 1. Adjust operating modes of the firewall and the politician of filtering 2. Perform creation of accounting record of the administrator, differentiation of access rights 3. Carry out backup and recovery 4. Perform setup of services (DNS, DHCP and other internal network services) 5. Adjust logging and monitoring of events 6. Adjust and debug routings 7. Adjust virtual domains and networks 8. Adjust the protected IPsec VPN connections 9. Adjust policy of authentication 10. Manage and apply cryptographic certificates | ||
|
Knowledge: 1. Rules of filtering and procedure for their application 2. Types and functions of firewalls 3. NAT use 4. Monitoring and journalizing of events 5. Updates and patching of system | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 4: Operation PASS of information security and providing CB and technical maintenance |
Abilities: 1. Operate the PASS of information security and providing CB 2. Accept from the supplier and/or the contractor the PASS of information security and providing CB 3. Consider and store carriers of confidential information 4. Operate the PASS of protection of confidential information 5. Carry out scheduled and scheduled maintenance on maintenance of means of information protection and providing CB | ||
|
Knowledge: 1. The legislative and other regulatory legal acts regulating activities for protection of the state secret and other information of limited access 2. Regulating and methodical documents on the questions connected with ensuring technical information security 3. The digital objects which are subject to protection 4. Specialization and activities of the organization and its divisions 5. The applied information technologies and systems 6. Management structure, bonds, automation 7. Means of technical investigation and evaluation methods of their opportunities 8. Safety hazards of information and classification (categories) of violations 9. Equipment of digital objects main and supportive technical means and systems, complexes and means of technical information security, services and mechanisms of safety of automated control systems 10. Access differentiation subsystems 11. Subsystems of detection of the attacks 12. Subsystems of protection against deliberate impact 13. Control methods of integrity of information, perspective of their development and upgrade 14. Evaluation methods of condition of security systems, identifications of channels of information leakage, control of process of reservation and duplication of critical computing and information resources 15. Operating procedure with technical, program, software and hardware of information security and control, services and mechanisms of safety of automated control systems and audit of their condition | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 5: Administration of antivirus software |
Abilities: 1. To effectively perform remote installation and updating of the anti-virus software and virus databases using centralized control systems, providing timely protection of information resources 2. Organize and support repositories of distribution kits of anti-virus solutions on network servers, providing their relevance and availability to centralized installation on all objects of IT infrastructure 3. Carry out thin setup of anti-virus solutions at workstations and servers in the remote mode, optimizing protection level according to security policy of the organization 4. Develop and plan tasks for accomplishment of scanning, updates and other transactions on devices of network, with possibility of the immediate or postponed start, increasing efficiency and automation of processes of administration | ||
|
Knowledge: 1. Appointments, classification and the principles of work of anti-virus programs, including signature, heuristic, behavioural methods of detection of threats, and also technologies of pro-active protection and integration with other means of cyber security 2. Official methodical recommendations of producers of antivirus software about its correct installation, taking into account features of operating systems, security policies and corporate infrastructure, and also requirements for preliminary preparation of the circle 3. Recommendations of developers of anti-virus solutions about their setup, administration and maintenance, including management of security policies, automation of updates, the organization of the reporting, monitoring of incidents and timely response to threats | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Labor function 2: Administration of mechanisms of safety |
|||
|
Skill 1: Process management on administration |
Abilities: 1. Constitute and maintain in urgent condition the list of access rights and powers of employees on access to the protected information 2. Monitor exits of updates and manage versions of PPO, DBMS, OS of the server and network hardware 3. Interact with other administrators for ensuring the coordinated work on updating of versions ON and lists of access rights | ||
|
Knowledge: 1. Lifecycle of management of IT processes: planning, design, implementation, operation, support and completion 2. The principles and models for management of IT services 3. Change management and configurations without risk for system operation 4. Control and monitoring of performance of system by means of different tools 5. Risk management and incidents of safety or failures in system operation. | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Attuning of security policy of OS, DBMS, PPO |
Abilities: 1. Manage cryptographic keys (generation and distribution) 2. Manage enciphering (To establish also synchronization of cryptographic parameters) 3. Manage authentication (distribution of information necessary for authentication - passwords, keys, etc.) 4. Manage access (distribution of information necessary for management - passwords, lists of access, etc.) 5. Establish and adjust controllers of domains of network | ||
|
Knowledge: 1. The principles of development of security policies, including determination of the purposes, risks and requirements 2. Security policy types, including: policy of management of access; policy of usage of passwords; to the politician of data processing; to the politician of incident management 3. Requirements to safety, established by different regulations and standards 4. Implementation process and implementations of policy, including training of employees, creation of the control system and ensuring compliance with policy 5. Monitoring and review of security policy in response to changes in organizational structure, new threats or changes in the legislation | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Labor function 3: Response to incidents of CB |
|||
|
Skill 1: Monitoring of events and incidents of CB |
Abilities: 1. Collect and analyze events in the systems which are under monitoring of CB 2. Classify events, serial events and combinations of events as violations of CB 3. Adjust procedures of processing of events and find events of CB | ||
|
Knowledge: 1. Safety monitoring process, including use of management systems which collect, is analyzed and trace data on safety events in real time 2. Types of events of safety and their classification 3. The principles of incident analysis and identification of threat, including use of machine training and analytics of big data 4. Procedure for maintaining logs of safety and to creation of reports for the analysis of tendencies and identification of risks | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Response to incidents of CB |
Abilities: 1. Register and notify (to inform) on incident of CB 2. Determine the causes of the incident of CB 3. Take measures to liquidation of incident of CB and its effects 4. Collect proofs about incident 5. Participate in conducting investigations of incidents of CB 6. Interact with competent authorities (CERT, law-enforcement bodies and others) | ||
|
Knowledge: 1. Processes of response to incidents and main stages of process 2. Classifications of incidents of safety by types and to gravity 3. Tools for investigation of incidents which help to collect proofs and to analyze the events 4. Communication roles in the course of reaction 5. Procedure for documentation and incident analysis for safety improvement | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Labor function 4: Control and efficiency analysis of application the PASS are sewn up information and providing CB |
|||
|
Skill 1: The current control of engineering procedure of processing of the protected information |
Abilities: 1. Constitute and support the PASS of information security and providing CB in urgent condition of documentation on placement and configuration 2. Control integrity of settings of mechanisms of safety of PPO, DBMS, OS of the server and telecommunication hardware 3. Analyze magazines of registration of events of system and application software for the purpose of identification of attempts of NSD to TsS and the protected information resources | ||
|
Knowledge: 1. Methods, principles and acceptances of control 2. Procedures of the analysis of the log of CB (accomplishment of tasks of the analysis, conducting investigation and the analysis of non-standard events, documentation of performing procedures and collection of proofs, to create the reporting for management) 3. Software of the analysis of logs of CB | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Current and periodic control of work PASS of information security and providing CB |
Abilities: 1. Analyze magazines of registration of events the PASS of information security and providing CB 2. Estimate use of the PASSES resources information and providing CB are sewn up 3. Develop suggestions for improvement and to increase in efficiency of use the PASS information and providing CB are sewn up | ||
|
Knowledge: 1. Principle of work and service regulations information security PASS 2. Criteria and indicators of effectiveness of use of the PASSES resources of information security and providing CB 3. Parameters of control PASS of information security and providing CB | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Requirements to personal competences: |
Responsibility Flexibility of thinking Ability to work in team Discipline Initiative | ||
|
List of technical regulations and national standards: |
ST of PK ISO/IEC 27001-2023 "Information security, cyber security and protection of confidentiality. Systems of management of information security. Requirements" ST of PK ISO/IEC 27006-2017 Information technologies. Methods and safety controls. Requirements to the bodies performing audit and certification of systems of management of information security of ST of PK 34.030-2008 Information technology. Audit of management systems information security of the organization | ||
|
Communication with other professions within the ORK: |
ORK level: |
Name of profession: | |
|
- |
- | ||
|
10. Profession card "Specialist in safety issues (ICT)": | |||
|
Group code: |
2524-0 | ||
|
Code of the name of occupation: |
2524-0-005 | ||
|
Name of profession: |
Specialist in safety issues (ICT) | ||
|
Skill level on the ORK: |
7 | ||
|
qualification subtotal on the ORK: |
|||
|
Skill level on ETKC, KC and other standard qualification characteristics: |
|||
|
Level of professional education: |
Education level: postgraduate education (magistracy, residency) |
Specialty: Information and communication technologies |
Qualification: - |
|
Requirements to work experience: |
1. The specialist in safety of information in key systems of information infrastructure of the I category: the highest (or postgraduate) education in the corresponding direction of training and length of service as the specialist in safety of information in key systems of information infrastructure of the II category at least 2 years | ||
|
Communication with informal and informalny education: |
|||
|
Other possible names of profession: |
|||
|
Main objective of activities: |
Counteraction to harmful influence of program and technical impact on subsystems, devices, elements and channels of infocommunication systems | ||
|
Description of labor functions | |||
|
List of labor functions: |
Obligatory labor functions: |
1. Estimation of level of safety of computer systems and networks 2. Development of the system of safety of computer systems and networks | |
|
Additional labor functions: |
|||
|
Labor function 1: Estimation of level of safety of computer systems and networks |
|||
|
Skill 1: Forming of security policies of computer systems and networks |
Abilities: 1. Analyze computer system for the purpose of determination of necessary level of security and trust 2. Develop profiles of protection of computer systems 3. Formulate tasks on safety of computer systems 4. Make the analysis of safety of computer systems and develop recommendations about operation of system of information security | ||
|
Knowledge: 1. Principles of creation of computer systems and networks 2. Models of safety of computer systems 3. Types of security policies of computer systems and networks 4. Principles of creation of means of cryptographic information security 5. National, interstate and international standards in the field of information security 6. Possibilities of the means of information protection used and planned to use 7. Regulatory legal acts in the field of information security 8. Organizational measures for information security | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Conducting control checks of working capacity and efficiency of the applied information security software and hardware |
Abilities: 1. Determine parameters of functioning of software and hardware of information security 2. Develop techniques of assessment of security of software and hardware of information security 3. Estimate efficiency of information security 4. Apply developed techniques of assessment of security of software and hardware of information security 5. Analyze protection software and hardware for the purpose of determination of level of the security provided with them and trust | ||
|
Knowledge: 1. Principles of creation of computer systems and networks 2. Methods and techniques of assessment of safety of software and hardware of information security 3. Principles of creation of software and hardware of information security 4. The principles of creation of subsystems of information security in computer systems 5. Evaluation methods of efficiency of the security policy realized in information security software and hardware 6. Methods and appraisal remedies of correctness and efficiency of program realization of algorithms of information security 7. Methods of the analysis of program code for the purpose of search of potential vulnerabilities and undocumented opportunities 8. Methods of the analysis of the applied methods and means of information protection regarding compliance to security policy 9. National, interstate and international standards in the field of information security 10. Regulatory legal acts in the field of information security 11. Organizational measures for information security | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 3: Carrying out analysis of safety of computer systems |
Abilities: 1. Analyze computer system for the purpose of determination of level of security and trust 2. Predict possible ways of development of actions of the violator of cyber security 3. Make the analysis of security policy regarding adequacy 4. Carry out monitoring, the analysis and comparison of efficiency of software and hardware of information security in operating systems 5. Constitute and draw up the analytical report by results of the carried-out analysis 6. Develop offers on elimination of the revealed vulnerabilities | ||
|
Knowledge: 1. Principles of creation of computer systems and networks 2. Vulnerabilities of computer systems and networks 3. Cryptographic methods of information security 4. Principles of creation of database management systems 5. Means of the analysis of configurations 6. National, interstate and international standards in the field of information security 7. Regulatory legal acts in the field of information security 8. The leading and methodical documents of authorized bodies of the executive authority on information security 9. Organizational measures for information security | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Labor function 2: Development of the system of safety of computer systems and networks |
|||
|
Skill 1: Designing of software and hardware of information security of computer systems and networks |
Abilities: 1. Conduct researches for the purpose of finding of the most reasonable practical decisions on ensuring information security 2. Apply domestic standards in the field of information security to designing of means of information protection of computer system 3. Develop architecture and interfaces of means of information protection, procedures of maintenance of means and systems of protection after failures 4. Select and generalize scientific and technical literature, methodical materials on program to both hardware and methods of information security, including in English | ||
|
Knowledge: 1. Methods and means of obtaining, processing and information transfer in operating systems, database management systems and computer networks 2. Types of the attacks and mechanisms of their realization in computer systems 3. Methods and means of information protection in computer networks, operating systems and database management systems 4. Principles of creation of systems of information security of computer systems, including anti-virus software 5. Methods of the analysis of safety of computer systems 6. The number-theoretic methods and algorithms applied in means of information protection 7. Formal management models access 8. Principles and methods of designing of hardware-software providing 9. Methodologies and technologies of development of the software 10. The principles and methods of management of projects in the field of cyber security 11. Cryptographic algorithms and features of their program realization 12. Regulatory legal acts in the field of information security 13. Organizational measures for information security 14. National, interstate and international standards in the field of information security | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Skill 2: Development of requirements to software and hardware of information security of computer systems and networks |
Abilities: 1. Generalize scientific and technical literature, normative and methodical materials in the field of information security 2. Create models of threats and model of the violator of safety of computer systems 3. Reveal the most reasonable approaches to ensuring information security of computer system 4. Develop private security policies of computer systems, including policy of management of access and information flows 5. Apply national, interstate and international standards in the field of information security to assessment of security of computer system 6. Apply the current legislation in the field of ensuring computer safety 7. Read and understand regulating and methodical documents on cyber security in English 8. Perform decision making about need of use of software and hardware of information security | ||
|
Knowledge: 1. Procedure for the organization of works on information security 2. Methods and means of obtaining, processing and information transfer in operating systems, database management systems and computer networks 3. Methods of the analysis of safety of computer systems 4. Types of the attacks and mechanisms of their realization in computer systems 5. Methods of identification of channels of information leakage 6. Methods and means of information protection in computer networks, operating systems and database management systems 7. Principles of creation of means of information protection of computer systems 8. Formal management models access 9. Cryptographic algorithms and features of their program realization 10. Regulatory legal acts in the field of information security 11. Organizational measures for information security 12. National, interstate and international standards in the field of information security | |||
|
Possibility of recognition of skill: |
It is not required | ||
|
Requirements to personal competences: |
Responsibility Analytical thinking Critical analysis Systems thinking Ability to solve non-standard problems Attentiveness to details | ||
Disclaimer! This text was translated by AI translator and is not a valid juridical document. No warranty. No claim. More info
Database include more 50000 documents. You can find needed documents using search system. For effective work you can mix any on documents parameters: country, documents type, date range, teams or tags.
More about search system
If you cannot find the required document, or you do not know where to begin, go to Help section.
In this section, we’ve tried to describe in detail the features and capabilities of the system, as well as the most effective techniques for working with the database.
You also may open the section Frequently asked questions. This section provides answers to questions set by users.