Ensures that the stakeholder security requirements necessary to protect the organization’s mission and business processes are adequately addressed in all aspects of enterprise architecture including reference models, segment and solution architectures, and the resulting systems supporting those missions and business processes.
*Certification Declaration
Certification Declaration
Each certification is mapped to the NICE Framework, which organizes cybersecurity into seven high-level Categories, each comprised of several specialty areas, work roles, knowledge, skills, abilities, and tasks. These seven high-level Categories are aligned directly to the CCE® Program’s certification Concentration Areas. Candidates often prepare for an exam by using a variety of resources that familiarize them with the authoritative sources and the exam’s concentration area.
Third-party products and services, including course instructors have helped many candidates to close knowledge and skill gaps. The CCE® Program does not endorse any particular provider and encourages candidates to use a variety of tools and resources that will enhance their understanding of relevant principles and the exam’s concentration area.
NICE Framework Category
CCE® Concentration Area:
Securely Provision (SP)
NICE Specialty Area:
Systems Architecture (ARC)
NICE Work Role ID:
SP-ARC-002
OPM Code | DCWF Code:
652
Cybersecurity Enterprise Engineering and Architecture (SP151)
Cybersecurity Enterprise Engineering and Architecture – SP (SP151-SP)
Enterprise Architect (SP203-RBT)
Implementing and Securing Your Virtual Environment (OM112)
Implementing and Securing Your Virtual Environment – WBT (OM012-WBT)
KSA-T
Below are the Knowledge, Skills, Abilities and Tasks (KSA-T) identified as being required to perform this work role.
ID & Description
- K001 - Knowledge of computer networking concepts and protocols, and network security methodologies.
- K0002 - Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- K0003 - Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- K0004 - Knowledge of cybersecurity and privacy principles.
- K0005 - Knowledge of cyber threats and vulnerabilities.
- K0006 - Knowledge of specific operational impacts of cybersecurity lapses.
- K0007 - Knowledge of authentication, authorization, and access control methods.
- K0008 - Knowledge of applicable business processes and operations of customer organizations.
- K0009 - Knowledge of application vulnerabilities.
- K0010 - Knowledge of communication methods, principles, and concepts that support the network infrastructure.
- K0011 - Knowledge of capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and related hardware.
- K0012 - Knowledge of capabilities and requirements analysis.
- K0013 - Knowledge of cyber defense and vulnerability assessment tools and their capabilities.
- K0015 - Knowledge of computer algorithms.
- K0018 - Knowledge of encryption algorithms.
- K0019 - Knowledge of cryptography and cryptographic key management concepts.
- K0024 - Knowledge of database systems.
- K0026 - Knowledge of business continuity and disaster recovery continuity of operations plans.
- K0027 - Knowledge of organization’s enterprise information security architecture.
- K0030 - Knowledge of electrical engineering as applied to computer architecture (e.g., circuit boards, processors, chips, and computer hardware).
- K0035 - Knowledge of installation, integration, and optimization of system components.
- K0036 - Knowledge of human-computer interaction principles.
- K0037 - Knowledge of Security Assessment and Authorization process.
- K0043 - Knowledge of industry-standard and organizationally accepted analysis principles and methods.
- K0044 - Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- K0052 - Knowledge of mathematics (e.g. logarithms, trigonometry, linear algebra, calculus, statistics, and operational analysis).
- K0055 - Knowledge of microprocessors.
- K0056 - Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).
- K0057 - Knowledge of network hardware devices and functions.
- K0059- Knowledge of new and emerging information technology (IT) and cybersecurity technologies.
- K0060 - Knowledge of operating systems.
- K0061 - Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
- K0063 - Knowledge of parallel and distributed computing concepts.
- K0071 - Knowledge of remote access technology concepts.
- K0074 - Knowledge of key concepts in security management (e.g., Release Management, Patch Management).
- K0082 - Knowledge of software engineering.
- K0091 - Knowledge of systems testing and evaluation methods.
- K0092 - Knowledge of technology integration processes.
- K0093 - Knowledge of telecommunications concepts (e.g., Communications channel, Systems Link Budgeting, Spectral efficiency, Multiplexing).
- K0102 - Knowledge of the systems engineering process.
- K0170 - Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
- K0180 - Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools.
- K0198 - Knowledge of organizational process improvement concepts and process maturity models (e.g., Capability Maturity Model Integration (CMMI) for Development, CMMI for Services, and CMMI for Acquisitions).
- K0200 - Knowledge of service management concepts for networks and related standards (e.g., Information Technology Infrastructure Library, current version [ITIL]).
- K0202 - Knowledge of the application firewall concepts and functions (e.g., Single point of authentication/audit/policy enforcement, message scanning for malicious content, data anonymization for PCI and PII compliance, data loss protection scanning, accelerated cryptographic operations, SSL security, REST/JSON processing).
- K0211 - Knowledge of confidentiality, integrity, and availability requirements.
- K0212 - Knowledge of cybersecurity-enabled software products.
- K0214 - Knowledge of the Risk Management Framework Assessment Methodology.
- K0227 - Knowledge of various types of computer architectures.
- K0240 - Knowledge of multi-level security systems and cross domain solutions.
- K0260 - Knowledge of Personally Identifiable Information (PII) data security standards.
- K0261 - Knowledge of Payment Card Industry (PCI) data security standards.
- K0262 - Knowledge of Personal Health Information (PHI) data security standards.
- K0264 - Knowledge of program protection planning (e.g. information technology (IT) supply chain security/risk management policies, anti-tampering techniques, and requirements).
- K0275 - Knowledge of configuration management techniques.
- K0277 - Knowledge of current and emerging data encryption (e.g., Column and Tablespace Encryption, file and disk encryption) security features in databases (e.g. built-in cryptographic key management features).
- K0286 - Knowledge of N-tiered typologies (e.g. including server and client operating systems).
- K0287 - Knowledge of an organization’s information classification program and procedures for information compromise.
- K0291 - Knowledge of the enterprise information technology (IT) architectural concepts and patterns (e.g., baseline, validated design, and target architectures.)
- K0293 - Knowledge of integrating the organization’s goals and objectives into the architecture.
- K0320 - Knowledge of organization’s evaluation and validation criteria.
- K0322 - Knowledge of embedded systems.
- K0323 - Knowledge of system fault tolerance methodologies.
- K0325 - Knowledge of Information Theory (e.g., source coding, channel coding, algorithm complexity theory, and data compression).
- K0326 - Knowledge of demilitarized zones.
- K0332 - Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.
- K0333 - Knowledge of network design processes, to include understanding of security objectives, operational objectives, and trade-offs.
- K0336 - Knowledge of access authentication methods.
- K0374 - WITHDRAWN: Knowledge of basic structure, architecture, and design of modern digital and telephony networks. (See K0599)
- K0565 - Knowledge of the common networking and routing protocols (e.g. TCP/IP), services (e.g., web, mail, DNS), and how they interact to provide network communications.