KROG
🇳🇴

CWA 18398 · assessment rubric

E.8 Information Security Management

← All competences

Level e-2

From role 2.12 AI Platform Engineer · EQF EQF6

Secure AI systems by identifying key components, understanding AI-specific risks, and applying established policies and procedures in structured environments.

  1. 7.1 Identify the components of AI systems, including models, datasets, and decision processes, relevant to their security in typical AI applications.

    Assessed by Review of Component Inventory document and oral questioning on AI system components, assessed for correct identification of models, datasets, and decision processes relevant to AI system security in typical AI applications.

  2. 7.2 Describe common AI-specific threats such as data poisoning, model manipulation, adversarial inputs, and privacy violations using real-world AI examples.

    Assessed by Evaluation of Threat Summary Report and short quizzes using real-world AI examples, assessed for accurate description of AI-specific threats such as data poisoning, model manipulation, adversarial inputs, and privacy violations.

  3. 7.3 Recall organisational AI security policies and procedures for safe AI use in compliance with standard guidelines.

    Assessed by Observation of adherence to AI security policies via Monitoring and Incident Log review, assessed for correct recall and application of organizational AI security policies and procedures in compliance with standard guidelines.

  4. 7.4 Follow prescribed AI security guidelines to assist in monitoring and incident reporting within controlled or supervised AI environments.

    Assessed by Review of Monitoring and Incident Log entries with instructor evaluation of correct procedure following, assessed for adherence to prescribed AI security guidelines in controlled or supervised monitoring and incident reporting.

  5. 7.5 Recognize abnormal AI system behaviours by observing AI outputs and performance metrics under guided supervision.

    Assessed by Assessment of documented observations of abnormal AI behaviours within supervised exercises, assessed for correct recognition of abnormal AI outputs and performance metrics under guided supervision. C.3 Support and Guidance SUPPORT & GUIDANCE [3]

Level e-3

From role 1.4 Data Engineer · EQF EQF6

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods.

  1. 6.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 6.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric- based assessment of AI risks related to data, models, deployment, and operation.

  3. 6.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 6.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 6.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. DATA PROCESSING & ANALYSIS [1]

From role 2.1 AI Architect · EQF EQF7

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods

  1. 8.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 8.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric- based assessment of AI risks related to data, models, deployment, and operation.

  3. 8.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 8.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 8.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. DEVELOPMENT & OPERATIONS [2]

From role 2.6 AI Quality & Evaluation Specialist · EQF EQF7

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods.

  1. 8.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 8.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric- based assessment of AI risks related to data, models, deployment, and operation.

  3. 8.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 8.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 8.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. DEVELOPMENT & OPERATIONS [2]

From role 3.5 AI Safety Specialist · EQF EQF6

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods.

  1. 6.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 6.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric- based assessment of AI risks related to data, models, deployment, and operation.

  3. 6.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 6.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 6.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. SUPPORT & GUIDANCE [3]

From role 4.6 AI Operations Manager · EQF EQF6

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods.

  1. 9.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 9.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric to assess AI risks related to data, models, deployment, and operation.

  3. 9.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 9.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 9.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. MANAGEMENT [4]

From role 5.3 AI Risk Manager · EQF EQF7

Ensure the security and reliability of AI systems by assessing vulnerabilities, applying secure development practices, and implementing mitigation strategies using appropriate tools and collaborative methods.

  1. 8.1 Analyse AI system components and workflows to identify potential security vulnerabilities in development or operational pipelines.

    Assessed by Evaluation of Vulnerability Analysis Report detailing AI components and workflow weaknesses, assessed for identification of potential security vulnerabilities in development or operational pipelines.

  2. 8.2 Evaluate AI risks related to data, models, deployment, and operation using established risk assessment frameworks and tools.

    Assessed by Review of Risk Assessment Matrix, including severity and mitigation measures, using rubric to assess AI risks related to data, models, deployment, and operation.

  3. 8.3 Apply secure AI development and operational practices (DevSecMLOps) to mitigate identified risks in practical project scenarios.

    Assessed by Assessment of Secure Development Implementation Plan, including evidence of applied DevSecMLOps practices to mitigate identified risks in practical project scenarios.

  4. 8.4 Implement AI monitoring and anomaly detection using software tools or supervised techniques.

    Assessed by Observation and review of Monitoring Dashboard or Log outputs during lab exercises, assessed for implementation of AI monitoring and anomaly detection using software tools or supervised techniques.

  5. 8.5 Collaborate effectively in teams to plan and execute AI security measures in applied projects or simulated operational scenarios.

    Assessed by Assessment of Team Project Security Plan documentation, with peer and instructor evaluation of collaboration, security planning, and execution of AI security measures in applied or simulated operational scenarios. GOVERNANCE [5]

Level e-4

From role 2.11 AI Incident Response & Reporting Lead · EQF EQF7

Secure organisational AI operations by developing and implementing comprehensive strategies, managing multidisciplinary teams, and aligning risk mitigation with regulatory, ethical, and business objectives in real-world contexts

  1. 6.1 Develop AI security policies and operational procedures for real-world organisational AI deployments.

    Assessed by Review of Organizational Security Policy Document, using rubric-based evaluation for completeness, operational usability, and regulatory alignment for real-world organizational AI deployments.

  2. 6.2 Implement AI risk mitigation plans addressing model manipulation, adversarial attacks, and privacy concerns in live operational systems.

    Assessed by Evaluation of Mitigation Implementation Report, assessed for evidence of implemented controls addressing model manipulation, adversarial attacks, and privacy concerns in live operational systems.

  3. 6.3 Manage multidisciplinary teams to execute AI security and compliance initiatives in organisational projects.

    Assessed by Review of Team Management Log and project records, assessed for coordination of multidisciplinary team activities, allocation of responsibilities, and execution evidence for AI security and compliance initiatives.

  4. 6.4 Evaluate AI security operations in live organisational environments using compliance and audit frameworks to ensure regulatory and ethical alignment.

    Assessed by Assessment of Operational Compliance Report, using audit-style evaluation of AI security operations in live organizational environments for regulatory and ethical adherence.

  5. 6.5 Apply AI governance frameworks across organisational AI systems to optimise operational resilience and trustworthiness.

    Assessed by Review of Governance Application Report, assessed for evidence that AI governance frameworks are applied across organizational AI systems to support operational resilience and trustworthiness. DEVELOPMENT & OPERATIONS [2]

From role 3.1 AI Security Specialist · EQF EQF7

Secure organisational AI operations by developing and implementing comprehensive strategies, managing multidisciplinary teams, and aligning risk mitigation with regulatory, ethical, and business objectives in real-world contexts.

  1. 6.1 Develop AI security policies and operational procedures for real-world organisational AI deployments.

    Assessed by Review of Organizational Security Policy Document, using rubric-based evaluation for completeness, operational usability, and regulatory alignment for real-world organizational AI deployments.

  2. 6.2 Implement AI risk mitigation plans addressing model manipulation, adversarial attacks, and privacy concerns in live operational systems.

    Assessed by Evaluation of Mitigation Implementation Report, assessed for evidence of implemented controls addressing model manipulation, adversarial attacks, and privacy concerns in live operational systems.

  3. 6.3 Manage multidisciplinary teams to execute AI security and compliance initiatives in organisational projects.

    Assessed by Review of Team Management Log and project records, assessed for coordination of multidisciplinary team activities, allocation of responsibilities, and execution evidence for AI security and compliance initiatives.

  4. 6.4 Evaluate AI security operations in live organisational environments using compliance and audit frameworks to ensure regulatory and ethical alignment.

    Assessed by Assessment of Operational Compliance Report, using audit-style evaluation of AI security operations in live organizational environments for regulatory and ethical adherence.

  5. 6.5 Apply AI governance frameworks across organisational AI systems to optimise operational resilience and trustworthiness.

    Assessed by Review of Governance Application Report, assessed for evidence that AI governance frameworks are applied across organizational AI systems to support operational resilience and trustworthiness. SUPPORT & GUIDANCE [3]

From role 5.2 AI Compliance Officer · EQF EQF7

Secure organisational AI operations by developing and implementing comprehensive strategies, managing multidisciplinary teams, and aligning risk mitigation with regulatory, ethical, and business objectives in real-world contexts

  1. 8.1 Develop AI security policies and operational procedures for real-world organisational AI deployments.

    Assessed by Review of Organizational Security Policy Document, rubric-based evaluation for completeness, regulatory alignment, and coverage of operational procedures for real-world organizational AI deployments.

  2. 8.2 Implement AI risk mitigation plans addressing model manipulation, adversarial attacks, and privacy concerns in live operational systems.

    Assessed by Evaluation of Mitigation Implementation Report, with evidence of implemented controls addressing model manipulation, adversarial attacks, and privacy risks in live operational systems.

  3. 8.3 Manage multidisciplinary teams to execute AI security and compliance initiatives in organisational projects.

    Assessed by Review of Team Management Log and project records assessing management of multidisciplinary teams in executing AI security and compliance initiatives in organizational projects.

  4. 8.4 Evaluate AI security operations in live organisational environments using compliance and audit frameworks to ensure regulatory and ethical alignment.

    Assessed by Assessment of Operational Compliance Report, audit-style evaluation for regulatory and ethical adherence in live organizational AI security operations using compliance and audit frameworks.

  5. 8.5 Apply AI governance frameworks across organisational AI systems to optimise operational resilience and trustworthiness.

    Assessed by Review of Governance Application Report evidence embedded in policy, mitigation, and compliance documentation, assessed for application of AI governance frameworks to optimize operational resilience and trustworthiness.