NICE Framework Categories
Securely Provision (SP)
Conceptualizes, designs, procures, and/or builds secure information technology (IT) systems, with responsibility for aspects of system and/or network development.
NICE Specialty Area:
Risk Management (RSK)
Oversees, evaluates, and supports the documentation, validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization’s cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives.
NICE Category:
Securely Provision (SP)
NICE Work Roles:
NICE Specialty Area:
Software Development (DEV)
Develops and writes/codes new (or modifies existing) computer applications, software, or specialized utility programs following software assurance best practices.
NICE Category:
Securely Provision (SP)
NICE Work Roles:
NICE Specialty Area:
Systems Architecture (ARC)
Develops system concepts and works on the capabilities phases of the systems development life cycle; translates technology and environmental conditions (e.g., law and regulation) into system and security designs and processes.
NICE Category:
Securely Provision (SP)
NICE Work Roles:
NICE Specialty Area:
Technology R&D (TRD)
Conducts technology assessment and integration processes; provides and supports a prototype capability and/or evaluates its utility.
NICE Category:
Securely Provision (SP)
NICE Work Role:
NICE Specialty Area:
Systems Requirements Planning (SRP)
Consults with customers to gather and evaluate functional requirements and translates these requirements into technical solutions. Provides guidance to customers about applicability of information systems to meet business needs.
NICE Category:
Securely Provision (SP)
NICE Work Role:
NICE Specialty Area:
Test and Evaluation (TST)
Develops and conducts tests of systems to evaluate compliance with specifications and requirements by applying principles and methods for cost-effective planning, evaluating, verifying, and validating of technical, functional, and performance characteristics (including interoperability) of systems or elements of systems incorporating IT.
NICE Category:
Securely Provision (SP)
NICE Work Role:
NICE Specialty Area:
Systems Development (SYS)
Works on the development phases of the systems development life cycle.
NICE Category:
Securely Provision (SP)
NICE Work Roles:
Operate and Maintain (OM)
Provides the support, administration, and maintenance necessary to ensure effective and efficient information technology (IT) system performance and security.
NICE Specialty Area:
Data Administration (DTA)
Develops and administers databases and/or data management systems that allow for the storage, query, protection, and utilization of data.
NICE Category:
Operate and Maintain (OM)
NICE Work Roles:
NICE Specialty Area:
Knowledge Management (KMG)
Manages and administers processes and tools that enable the organization to identify, document, and access intellectual capital and information content.
NICE Category:
Operate and Maintain (OM)
NICE Work Role:
NICE Specialty Area:
Customer Service and Technical Support (STS)
Addresses problems; installs, configures, troubleshoots, and provides maintenance and training in response to customer requirements or inquiries (e.g., tiered-level customer support). Typically provides initial incident information to the Incident Response (IR) Specialty.
NICE Category:
Operate and Maintain (OM)
NICE Work Role:
NICE Specialty Area:
Network Services (NET)
Installs, configures, tests, operates, maintains, and manages networks and their firewalls, including hardware (e.g., hubs, bridges, switches, multiplexers, routers, cables, proxy servers, and protective distributor systems) and software that permit the sharing and transmission of all spectrum transmissions of information to support the security of information and information systems.
NICE Category:
Operate and Maintain (OM)
NICE Work Role:
NICE Specialty Area:
Systems Administration (ADM)
Installs, configures, troubleshoots, and maintains server configurations (hardware and software) to ensure their confidentiality, integrity, and availability. Manages accounts, firewalls, and patches. Responsible for access control, passwords, and account creation and administration.
NICE Category:
Operate and Maintain (OM)
NICE Work Role:
NICE Specialty Area:
Systems Analysis (ANA)
Studies an organization’s current computer systems and procedures, and designs information systems solutions to help the organization operate more securely, efficiently, and effectively. Brings business and information technology (IT) together by understanding the needs and limitations of both.
NICE Category:
Operate and Maintain (OM)
NICE Work Role:
Oversee and Govern (OV)
Provides leadership, management, direction, or development and advocacy so the organization may effectively conduct cybersecurity work.
NICE Specialty Area:
Legal Advice and Advocacy (LGA)
Provides legally sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain. Advocates legal and policy changes, and makes a case on behalf of client via a wide range of written and oral work products, including legal briefs and proceedings.
NICE Category:
Oversee and Govern (OV)
NICE Work Roles:
NICE Specialty Area:
Training, Education, and Awareness (TEA)
Conducts training of personnel within pertinent subject domain. Develops, plans, coordinates, delivers and/or evaluates training courses, methods, and techniques as appropriate.
NICE Category:
Oversee and Govern (OV)
NICE Work Roles:
NICE Specialty Area:
Cybersecurity Management (MGT)
Oversees the cybersecurity program of an information system or network, including managing information security implications within the organization, specific program, or other area of responsibility, to include strategic, personnel, infrastructure, requirements, policy enforcement, emergency planning, security awareness, and other resources.
NICE Category:
Oversee and Govern (OV)
NICE Work Roles:
NICE Specialty Area:
Strategic Planning and Policy (SPP)
Develops policies and plans and/or advocates for changes in policy that support organizational cyberspace initiatives or required changes/enhancements.
NICE Category:
Oversee and Govern (OV)
NICE Work Roles:
NICE Specialty Area:
Executive Cyber Leadership (EXL)
Supervises, manages, and/or leads work and workers performing cyber and cyber-related and/or cyber operations work.
NICE Category:
Oversee and Govern (OV)
NICE Work Role:
NICE Specialty Area:
Program/Project Management (PMA) and Acquisition
Applies knowledge of data, information, processes, organizational interactions, skills, and analytical expertise, as well as systems, networks, and information exchange capabilities to manage acquisition programs. Executes duties governing hardware, software, and information system acquisition programs and other program management policies. Provides direct support for acquisitions that use information technology (IT) (including National Security Systems), applying IT-related laws and policies, and provides IT-related guidance throughout the total acquisition life cycle.
NICE Category:
Oversee and Govern (OV)
NICE Work Roles:
Protect and Defend (PR)
Identifies, analyzes, and mitigates threats to internal information technology (IT) systems and/or networks.
NICE Specialty Area:
Cybersecurity Defense Analysis (CDA)
Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network to protect information, information systems, and networks from threats.
NICE Category:
Protect and Defend (PR)
NICE Work Role:
NICE Specialty Area:
Cybersecurity Defense Infrastructure Support (INF)
Tests, implements, deploys, maintains, reviews, and administers the infrastructure hardware and software that are required to effectively manage the computer network defense service provider network and resources. Monitors network to actively remediate unauthorized activities.
NICE Category:
Protect and Defend (PR)
NICE Work Role:
NICE Specialty Area:
Incident Response (CIR)
Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities.
NICE Category:
Protect and Defend (PR)
NICE Work Role:
NICE Specialty Area:
Vulnerability Assessment and Management (VAM)
Conducts assessments of threats and vulnerabilities; determines deviations from acceptable configurations, enterprise or local policy; assesses the level of risk; and develops and/or recommends appropriate mitigation countermeasures in operational and nonoperational situations.
NICE Category:
Protect and Defend (PR)
NICE Work Role:
Analyze (AN)
Performs highly-specialized review and evaluation of incoming cybersecurity information to determine its usefulness for intelligence.
NICE Specialty Area:
Threat Analysis (TWA)
Identifies and assesses the capabilities and activities of cybersecurity criminals or foreign intelligence entities; produces findings to help initialize or support law enforcement and counterintelligence investigations or activities.
NICE Category:
Analyze (AN)
NICE Work Role:
NICE Specialty Area:
Exploitation Analysis (EXP)
Analyzes collected information to identify vulnerabilities and potential for exploitation.
NICE Category:
Analyze (AN)
NICE Work Role:
NICE Specialty Area:
All-Source Analysis (ASA)
Analyzes threat information from multiple sources, disciplines, and agencies across the Intelligence Community. Synthesizes and places intelligence information in context; draws insights about the possible implications.
NICE Category:
Analyze (AN)
NICE Work Roles:
NICE Specialty Area:
Targets (TGT)
Applies current knowledge of one or more regions, countries, non-state entities, and/or technologies.
NICE Category:
Analyze (AN)
NICE Work Roles:
NICE Specialty Area:
Language Analysis (LNG)
Applies language, cultural, and technical expertise to support information collection, analysis, and other cybersecurity activities.
NICE Category:
Analyze (AN)
NICE Work Role:
Collect and Operate (CO)
Provides specialized denial and deception operations and collection of cybersecurity information that may be used to develop intelligence.
NICE Specialty Area:
Collection Operations (CLO)
Executes collection using appropriate strategies and within the priorities established through the collection management process.
NICE Category:
Collect and Operate (CO)
NICE Work Roles:
NICE Specialty Area:
Cyber Operational Planning (OPL)
Performs in-depth joint targeting and cybersecurity planning process. Gathers information and develops detailed Operational Plans and Orders supporting requirements. Conducts strategic and operational-level planning across the full range of operations for integrated information and cyberspace operations.
NICE Category:
Collect and Operate (CO)
NICE Work Roles:
NICE Specialty Area:
Cyber Operations (OPS)
Performs activities to gather evidence on criminal or foreign intelligence entities to mitigate possible or real-time threats, protect against espionage or insider threats, foreign sabotage, international terrorist activities, or to support other intelligence activities.
NICE Category:
Collect and Operate (CO)
NICE Work Role:
Investigate (IN)
Investigates cybersecurity events or crimes related to information technology (IT) systems, networks, and digital evidence.
NICE Specialty Area:
Cyber Investigation (INV)
Applies tactics, techniques, and procedures for a full range of investigative tools and processes to include, but not limited to, interview and interrogation techniques, surveillance, counter surveillance, and surveillance detection, and appropriately balances the benefits of prosecution versus intelligence gathering.
NICE Category:
Investigate (IN)
NICE Work Role:
NICE Specialty Area:
Digital Forensics (FOR)
Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations.