KROG
🇳🇴

CWA 18398 · assessment rubric

D.1 Information Security Strategy Development

← All competences

Level e-4

From role 3.1 AI Security Specialist · EQF EQF7

Develop and lead AI security strategies across organisational functions and systems by analysing risks, establishing governance frameworks aligned with recognized standards, integrating ethical and regulatory requirements, coordinating multi-disciplinary teams, and ensuring resilient, compliant, and business-aligned AI operations.

  1. 4.1 Analyse AI risks, vulnerabilities, and potential impacts across organisational units, services, and systems, using structured risk assessment frameworks such as NIST AI RMF or threat modelling approaches.

    Assessed by AI Risk Assessment Report, case study analysis, and scenario-based risk evaluation, assessed for analysis of AI risks, vulnerabilities, and potential impacts across organizational units, services, and systems using structured risk assessment frameworks such as NIST AI RMF or threat modelling approaches.

  2. 4.2 Develop and implement AI security strategies that align with organisational objectives, ethical principles, and regulatory requirements, by referencing widely adopted standards such as ISO/IEC 27001, ISO/IEC 23894, GDPR, or OWASP AI Security guidelines.

    Assessed by AI Security Strategy Document, policy proposal, and peer review of strategy alignment, assessed for development and implementation of AI security strategies aligned with organizational objectives, ethical principles, regulatory requirements, and widely adopted standards.

  3. 4.3 Establish governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for AI systems at the organisational level, in alignment with corporate compliance and operational structures.

    Assessed by AI Governance Framework Specification, rubric-based evaluation, and audit simulation, assessed for establishment of governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for AI systems at the organizational level.

  4. 4.4 Guide and coordinate multi-disciplinary teams to implement AI security measures in line with ethical, regulatory, and strategic objectives, by facilitating collaboration across IT, data science, and business units.

    Assessed by AI Implementation Guidance Report, team coordination plan, presentation of AI implementation roadmap, and reflective report on team guidance, assessed for coordination of multi-disciplinary teams and implementation of AI security measures across IT, data science, and business units.

  5. 4.5 Evaluate the effectiveness of AI security strategies, monitor compliance, and recommend improvements for resilience, trust, and business alignment, using audits, metrics, and performance monitoring systems.

    Assessed by AI Strategy Evaluation Report, KPI/metric analysis, and compliance review exercises, assessed for evaluation of AI security strategy effectiveness, compliance monitoring, and recommendations for resilience, trust, and business alignment.

  6. 4.6 Integrate strategic security-by-design principles into organisational AI system lifecycles to ensure proactive risk mitigation, by incorporating security checkpoints and governance reviews in design and deployment phases.

    Assessed by AI Security-by-Design Plan, lifecycle mapping submission, and strategic design checklist evaluation, assessed for integration of security-by-design principles, security checkpoints, and governance reviews across organizational AI system lifecycles.

  7. 4.7 Anticipate emerging AI threats, regulatory changes, and ethical considerations to adapt organisational security strategies proactively, by monitoring industry trends, regulatory updates, and threat intelligence reports.

    Assessed by AI Threat & Regulation Foresight Brief, scenario planning exercise, and policy adaptation proposal, assessed for anticipation of emerging AI threats, regulatory changes, and ethical considerations using industry trends, regulatory updates, and threat intelligence reports.

  8. 4.8 Communicate AI security priorities and strategies to stakeholders to foster a culture of security and ethical responsibility across the organisation, using presentations, briefings, and strategic documentation targeted at executives and teams.

    Assessed by AI Stakeholder Communication Package, peer/expert review, and communication effectiveness rubric, assessed for clear communication of AI security priorities and strategies to executives and teams and for contribution to a culture of security and ethical responsibility.

From role 5.1 AI Governance Officer · EQF EQF8

Develop and lead AI security strategies across organisational functions and systems by analysing risks, establishing governance frameworks aligned with recognized standards, integrating ethical and regulatory requirements, coordinating multi-disciplinary teams, and ensuring resilient, compliant, and business-aligned AI operations.

  1. 3.1 Analyse AI risks, vulnerabilities, and potential impacts across organisational units, services, and systems, using structured risk assessment frameworks such as NIST AI RMF or threat modelling approaches.

    Assessed by AI Risk Assessment Report, supported by case study analysis and scenario-based risk evaluation, assessing AI risks, vulnerabilities, and potential impacts across organizational units, services, and systems using structured frameworks such as NIST AI RMF or threat modelling approaches.

  2. 3.2 Develop and implement AI security strategies that align with organisational objectives, ethical principles, and regulatory requirements, by referencing widely adopted standards such as ISO/IEC 27001, ISO/IEC 23894, GDPR, or OWASP AI Security guidelines.

    Assessed by AI Security Strategy Document, policy proposal, and peer review of strategy alignment, assessed for development and implementation of AI security strategies aligned with organizational objectives, ethical principles, regulatory requirements, and relevant standards.

  3. 3.3 Establish governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for AI systems at the organisational level, in alignment with corporate compliance and operational structures.

    Assessed by AI Governance Framework Specification, supported by rubric-based evaluation and audit simulation, assessing governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for organizational AI systems.

  4. 3.4 Guide and coordinate multi-disciplinary teams to implement AI security measures in line with ethical, regulatory, and strategic objectives, by facilitating collaboration across IT, data science, and business units.

    Assessed by AI Implementation Guidance Report, team coordination plan, implementation roadmap presentation, and reflective report assessing guidance and coordination of multi-disciplinary teams implementing AI security measures across IT, data science, and business units.

  5. 3.5 Evaluate the effectiveness of AI security strategies, monitor compliance, and recommend improvements for resilience, trust, and business alignment, using audits, metrics, and performance monitoring systems.

    Assessed by AI Strategy Evaluation Report, KPI/metric analysis, and compliance review exercises assessing effectiveness of AI security strategies, compliance monitoring, and recommendations for resilience, trust, and business alignment.

  6. 3.6 Integrate strategic security-by-design principles into organisational AI system lifecycles to ensure proactive risk mitigation, by incorporating security checkpoints and governance reviews in design and deployment phases.

    Assessed by AI Security-by-Design Plan, lifecycle mapping submission, and strategic design checklist evaluation assessing integration of security-by-design principles, security checkpoints, and governance reviews across AI system lifecycle phases.

  7. 3.7 Anticipate emerging AI threats, regulatory changes, and ethical considerations to adapt organisational security strategies proactively, by monitoring industry trends, regulatory updates, and threat intelligence reports.

    Assessed by AI Threat & Regulation Foresight Brief, scenario planning exercise, and policy adaptation proposal assessing anticipation of emerging AI threats, regulatory changes, and ethical considerations for proactive strategy adaptation.

  8. 3.8 Communicate AI security priorities and strategies to stakeholders to foster a culture of security and ethical responsibility across the organisation, using presentations, briefings, and strategic documentation targeted at executives and teams.

    Assessed by AI Stakeholder Communication Package, including presentations, briefings, and strategic documents, assessed through peer/expert review and a communication effectiveness rubric for clarity, audience fit, and promotion of security and ethical responsibility.

From role 5.2 AI Compliance Officer · EQF EQF7

Develop and lead AI security strategies across organisational functions and systems by analysing risks, establishing governance frameworks aligned with recognized standards, integrating ethical and regulatory requirements, coordinating multi-disciplinary teams, and ensuring resilient, compliant, and business-aligned AI operations.

  1. 3.1 Analyse AI risks, vulnerabilities, and potential impacts across organisational units, services, and systems, using structured risk assessment frameworks such as NIST AI RMF or threat modelling approaches.

    Assessed by AI Risk Assessment Report, supported by case study analysis and scenario-based risk evaluation, assessing AI risks, vulnerabilities, and potential impacts across organizational units, services, and systems using structured frameworks such as NIST AI RMF or threat modelling approaches.

  2. 3.2 Develop and implement AI security strategies that align with organisational objectives, ethical principles, and regulatory requirements, by referencing widely adopted standards such as ISO/IEC 27001, ISO/IEC 23894, GDPR, or OWASP AI Security guidelines.

    Assessed by AI Security Strategy Document, policy proposal, and peer review of strategy alignment, assessed for development and implementation of AI security strategies aligned with organizational objectives, ethical principles, regulatory requirements, and relevant standards.

  3. 3.3 Establish governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for AI systems at the organisational level, in alignment with corporate compliance and operational structures.

    Assessed by AI Governance Framework Specification, supported by rubric-based evaluation and audit simulation, assessing governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for organizational AI systems.

  4. 3.4 Guide and coordinate multi-disciplinary teams to implement AI security measures in line with ethical, regulatory, and strategic objectives, by facilitating collaboration across IT, data science, and business units.

    Assessed by AI Implementation Guidance Report, team coordination plan, implementation roadmap presentation, and reflective report assessing guidance and coordination of multi-disciplinary teams implementing AI security measures across IT, data science, and business units.

  5. 3.5 Evaluate the effectiveness of AI security strategies, monitor compliance, and recommend improvements for resilience, trust, and business alignment, using audits, metrics, and performance monitoring systems.

    Assessed by AI Strategy Evaluation Report, KPI/metric analysis, and compliance review exercises assessing effectiveness of AI security strategies, compliance monitoring, and recommendations for resilience, trust, and business alignment.

  6. 3.6 Integrate strategic security-by-design principles into organisational AI system lifecycles to ensure proactive risk mitigation, by incorporating security checkpoints and governance reviews in design and deployment phases.

    Assessed by AI Security-by-Design Plan, lifecycle mapping submission, and strategic design checklist evaluation assessing integration of security-by-design principles, security checkpoints, and governance reviews across AI system lifecycle phases.

  7. 3.7 Anticipate emerging AI threats, regulatory changes, and ethical considerations to adapt organisational security strategies proactively, by monitoring industry trends, regulatory updates, and threat intelligence reports.

    Assessed by AI Threat & Regulation Foresight Brief, scenario planning exercise, and policy adaptation proposal assessing anticipation of emerging AI threats, regulatory changes, and ethical considerations for proactive strategy adaptation.

  8. 3.8 Communicate AI security priorities and strategies to stakeholders to foster a culture of security and ethical responsibility across the organisation, using presentations, briefings, and strategic documentation targeted at executives and teams.

    Assessed by AI Stakeholder Communication Package, including presentations, briefings, and strategic documents, assessed through peer/expert review and a communication effectiveness rubric for clarity, audience fit, and promotion of security and ethical responsibility.

From role 5.3 AI Risk Manager · EQF EQF7

Develop and lead AI security strategies across organisational functions and systems by analysing risks, establishing governance frameworks aligned with recognized standards, integrating ethical and regulatory requirements, coordinating multi-disciplinary teams, and ensuring resilient, compliant, and business-aligned AI operations.

  1. 3.1 Analyse AI risks, vulnerabilities, and potential impacts across organisational units, services, and systems, using structured risk assessment frameworks such as NIST AI RMF or threat modelling approaches.

    Assessed by AI Risk Assessment Report, supported by case study analysis and scenario-based risk evaluation, assessing AI risks, vulnerabilities, and potential impacts across organizational units, services, and systems using structured frameworks such as NIST AI RMF or threat modelling approaches.

  2. 3.2 Develop and implement AI security strategies that align with organisational objectives, ethical principles, and regulatory requirements, by referencing widely adopted standards such as ISO/IEC 27001, ISO/IEC 23894, GDPR, or OWASP AI Security guidelines.

    Assessed by AI Security Strategy Document, policy proposal, and peer review of strategy alignment, assessed for development and implementation of AI security strategies aligned with organizational objectives, ethical principles, regulatory requirements, and relevant standards.

  3. 3.3 Establish governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for AI systems at the organisational level, in alignment with corporate compliance and operational structures.

    Assessed by AI Governance Framework Specification, supported by rubric-based evaluation and audit simulation, assessing governance frameworks, roles, responsibilities, policies, and monitoring mechanisms for organizational AI systems.

  4. 3.4 Guide and coordinate multi-disciplinary teams to implement AI security measures in line with ethical, regulatory, and strategic objectives, by facilitating collaboration across IT, data science, and business units.

    Assessed by AI Implementation Guidance Report, team coordination plan, implementation roadmap presentation, and reflective report assessing guidance and coordination of multi-disciplinary teams implementing AI security measures across IT, data science, and business units.

  5. 3.5 Evaluate the effectiveness of AI security strategies, monitor compliance, and recommend improvements for resilience, trust, and business alignment, using audits, metrics, and performance monitoring systems.

    Assessed by AI Strategy Evaluation Report, KPI/metric analysis, and compliance review exercises assessing effectiveness of AI security strategies, compliance monitoring, and recommendations for resilience, trust, and business alignment.

  6. 3.6 Integrate strategic security-by-design principles into organisational AI system lifecycles to ensure proactive risk mitigation, by incorporating security checkpoints and governance reviews in design and deployment phases.

    Assessed by AI Security-by-Design Plan, lifecycle mapping submission, and strategic design checklist evaluation assessing integration of security-by-design principles, security checkpoints, and governance reviews across AI system lifecycle phases.

  7. 3.7 Anticipate emerging AI threats, regulatory changes, and ethical considerations to adapt organisational security strategies proactively, by monitoring industry trends, regulatory updates, and threat intelligence reports.

    Assessed by AI Threat & Regulation Foresight Brief, scenario planning exercise, and policy adaptation proposal assessing anticipation of emerging AI threats, regulatory changes, and ethical considerations for proactive strategy adaptation.

  8. 3.8 Communicate AI security priorities and strategies to stakeholders to foster a culture of security and ethical responsibility across the organisation, using presentations, briefings, and strategic documentation targeted at executives and teams.

    Assessed by AI Stakeholder Communication Package, including presentations, briefings, and strategic documents, assessed through peer/expert review and a communication effectiveness rubric for clarity, audience fit, and promotion of security and ethical responsibility.