PD-WRL-004
Infrastructure Support OPM Code: 521

Protects against, identifies, and analyzes risks to technology systems or networks. Includes investigation of cybersecurity events or crimes related to technology systems and networks.

Responsible for testing, implementing, deploying, maintaining, and administering infrastructure hardware and software for cybersecurity. 

Code Description Work Roles
T1020 Determine the operational and safety impacts of cybersecurity lapses 37
T1111 Administer rule and signature updates for specialized cyber defense applications 1
T1267 Perform system administration on specialized cyber defense applications and systems 1
T1268 Administer Virtual Private Network (VPN) devices 1
T1352 Coordinate critical cyber defense infrastructure protection measures 1
T1353 Prioritize critical cyber defense infrastructure resources 1
T1432 Build dedicated cyber defense hardware 1
T1433 Install dedicated cyber defense hardware 1
T1442 Assess the impact of implementing and sustaining a dedicated cyber defense infrastructure 1
T1503 Evaluate platforms managed by service providers 1
T1515 Manage network access control lists on specialized cyber defense systems 1
T1555 Implement cyber defense tools 1
T1561 Implement dedicated cyber defense systems 1
T1562 Document system requirements 1
Code Description Work Roles
K0674 Knowledge of computer networking protocols 40
K0675 Knowledge of risk management processes 41
K0676 Knowledge of cybersecurity laws and regulations 41
K0677 Knowledge of cybersecurity policies and procedures 41
K0678 Knowledge of privacy laws and regulations 41
K0679 Knowledge of privacy policies and procedures 41
K0680 Knowledge of cybersecurity principles and practices 40
K0681 Knowledge of privacy principles and practices 40
K0682 Knowledge of cybersecurity threats 40
K0683 Knowledge of cybersecurity vulnerabilities 40
K0684 Knowledge of cybersecurity threat characteristics 40
K0685 Knowledge of access control principles and practices 21
K0686 Knowledge of authentication and authorization tools and techniques 21
K0701 Knowledge of data backup and recovery policies and procedures 8
K0710 Knowledge of enterprise cybersecurity architecture principles and practices 20
K0716 Knowledge of host access control (HAC) systems and software 10
K0717 Knowledge of network access control (NAC) systems and software 10
K0724 Knowledge of incident response principles and practices 8
K0725 Knowledge of incident response tools and techniques 8
K0726 Knowledge of incident handling tools and techniques 8
K0728 Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices 20
K0729 Knowledge of non-repudiation principles and practices 20
K0730 Knowledge of cyber safety principles and practices 20
K0734 Knowledge of Risk Management Framework (RMF) requirements 14
K0746 Knowledge of policy-based access controls 15
K0747 Knowledge of Risk Adaptive (Adaptable) Access Controls (RAdAC) 15
K0751 Knowledge of system threats 40
K0752 Knowledge of system vulnerabilities 40
K0770 Knowledge of system administration principles and practices 14
K0778 Knowledge of enterprise information technology (IT) architecture principles and practices 20
K0781 Knowledge of virtual private network (VPN) systems and software 4
K0783 Knowledge of network attack characteristics 7
K0791 Knowledge of defense-in-depth principles and practices 19
K0792 Knowledge of network configurations 9
K0811 Knowledge of web filtering systems and software 2
K0829 Knowledge of account creation policies and procedures 6
K0830 Knowledge of password policies and procedures 6
K0837 Knowledge of hardening tools and techniques 14
K0870 Knowledge of enterprise architecture (EA) reference models and frameworks 20
K0871 Knowledge of enterprise architecture (EA) principles and practices 20
K0881 Knowledge of learning assessment tools and techniques 7
K0891 Knowledge of the Open Systems Interconnect (OSI) reference model 13
K0915 Knowledge of network architecture principles and practices 21
K0925 Knowledge of wireless communication tools and techniques 6
K0926 Knowledge of signal jamming tools and techniques 6
K0950 Knowledge of Intrusion Detection System (IDS) tools and techniques 2
K0951 Knowledge of Intrusion Prevention System (IPS) tools and techniques 2
K0983 Knowledge of computer networking principles and practices 39
K1014 Knowledge of network security principles and practices 40
K1211 Knowledge of security assessment authorization requirements 1
Code Description Work Roles
S0077 Skill in securing network communications 3
S0552 Skill in applying host access controls 1
S0553 Skill in applying network access controls 1
S0592 Skill in tuning network sensors 2
S0593 Skill in handling incidents 4
S0596 Skill in encrypting network communications 3
S0615 Skill in protecting a network against malware 3
S0643 Skill in applying hardening techniques 2
S0645 Skill in troubleshooting cyber defense infrastructure anomalies 2
S0831 Skill in configuring hardware 1
S0898 Skill in testing hardware 1