Skills Framework for the Information Age
Version 3.0

SFIA 3.0

Framework summary

The purpose of SFIA

How SFIA works

How SFIA is used

Levels of responsibility

Skills

Index of skill definitions

Skill definitions

Strategy & planning

Development

Business change

Service provision

Procurement & management support

Ancillary skills

Moving from SFIA 1 or 2

SFIA 3: changes in detail

Useful stuff

© 2005 The SFIA Foundation
www.sfia.org.uk
info@sfia.org.uk

<< Information security (SCTY) | Technical strategy and planning >>

Information assurance (INAS)

The protection of systems and information in storage, processing, or transit from unauthorised access or modification. Denial of service to unauthorised users; or the provision of service to authorised users. Includes those measures necessary to detect, document and counter threats to the integrity of stored information, such as the application of firewalls and intrusion detection systems (IDS).

Level 3 Applies procedures to enhance resilience to unauthorised access. Recognises when an IT network/system has been attacked, can take immediate action to limit damage and escalates event to higher authority.

Level 4 Investigates suspected attacks and recommends remedial action.

Level 5 Develops procedures and implements the application of firewalls and IDS to improve network/system resilience.

Level 6 Protects and defends information and information systems by ensuring availability, integrity, authentication, confidentiality and non-repudiation. Provides for restoration of information systems by ensuring that protection, detection and reaction capabilities are incorporated.