SP-ARC-002 Security Architect

Conceptualizes, designs, procures, and/or builds secure information technology (IT) systems, with responsibility for aspects of system and/or network development.

Develops system concepts and works on the capabilities phases of the systems development life cycle; translates technology and environmental conditions (e.g., law and regulation) into system and security designs and processes.

Ensures that the stakeholder security requirements necessary to protect the organization’s mission and business processes are adequately addressed in all aspects of enterprise architecture including reference models, segment and solution architectures, and the resulting systems supporting those missions and business processes.

Knowledges 70

Code Description Work Roles
K0001 Knowledge of computer networking concepts and protocols, and network security methodologies. 52
K0002 Knowledge of risk management processes (e.g., methods for assessing and mitigating risk). 52
K0003 Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy. 52
K0004 Knowledge of cybersecurity and privacy principles. 52
K0005 Knowledge of cyber threats and vulnerabilities. 52
K0006 Knowledge of specific operational impacts of cybersecurity lapses. 52
K0007 Knowledge of authentication, authorization, and access control methods. 4
K0008 Knowledge of applicable business processes and operations of customer organizations. 5
K0009 Knowledge of application vulnerabilities. 6
K0010 Knowledge of communication methods, principles, and concepts that support the network infrastructure. 3
K0011 Knowledge of capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and related hardware. 3
K0012 Knowledge of capabilities and requirements analysis. 3
K0013 Knowledge of cyber defense and vulnerability assessment tools and their capabilities. 5
K0015 Knowledge of computer algorithms. 6
K0018 Knowledge of encryption algorithms 11
K0019 Knowledge of cryptography and cryptographic key management concepts 8
K0024 Knowledge of database systems. 7
K0026 Knowledge of business continuity and disaster recovery continuity of operations plans. 5
K0027 Knowledge of organization's enterprise information security architecture. 9
K0030 Knowledge of electrical engineering as applied to computer architecture (e.g., circuit boards, processors, chips, and computer hardware). 4
K0035 Knowledge of installation, integration, and optimization of system components. 6
K0036 Knowledge of human-computer interaction principles. 12
K0037 Knowledge of Security Assessment and Authorization process. 5
K0043 Knowledge of industry-standard and organizationally accepted analysis principles and methods. 7
K0044 Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). 14
K0052 Knowledge of mathematics (e.g. logarithms, trigonometry, linear algebra, calculus, statistics, and operational analysis). 6
K0055 Knowledge of microprocessors. 4
K0056 Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML). 11
K0057 Knowledge of network hardware devices and functions. 2
K0059 Knowledge of new and emerging information technology (IT) and cybersecurity technologies. 12
K0060 Knowledge of operating systems. 13
K0061 Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]). 11
K0063 Knowledge of parallel and distributed computing concepts. 6
K0071 Knowledge of remote access technology concepts. 2
K0074 Knowledge of key concepts in security management (e.g., Release Management, Patch Management). 4
K0082 Knowledge of software engineering. 7
K0091 Knowledge of systems testing and evaluation methods. 6
K0092 Knowledge of technology integration processes. 2
K0093 Knowledge of telecommunications concepts (e.g., Communications channel, Systems Link Budgeting, Spectral efficiency, Multiplexing). 8
K0102 Knowledge of the systems engineering process. 7
K0170 Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations. 12
K0180 Knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools. 9
K0198 Knowledge of organizational process improvement concepts and process maturity models (e.g., Capability Maturity Model Integration (CMMI) for Development, CMMI for Services, and CMMI for Acquisitions). 6
K0200 Knowledge of service management concepts for networks and related standards (e.g., Information Technology Infrastructure Library, current version [ITIL]). 11
K0202 Knowledge of the application firewall concepts and functions (e.g., Single point of authentication/audit/policy enforcement, message scanning for malicious content, data anonymization for PCI and PII compliance, data loss protection scanning, accelerated cryptographic operations, SSL security, REST/JSON processing). 4
K0211 Knowledge of confidentiality, integrity, and availability requirements. 2
K0212 Knowledge of cybersecurity-enabled software products. 4
K0214 Knowledge of the Risk Management Framework Assessment Methodology. 2
K0227 Knowledge of various types of computer architectures. 4
K0240 Knowledge of multi-level security systems and cross domain solutions. 2
K0260 Knowledge of Personally Identifiable Information (PII) data security standards. 16
K0261 Knowledge of Payment Card Industry (PCI) data security standards. 17
K0262 Knowledge of Personal Health Information (PHI) data security standards. 17
K0264 Knowledge of program protection planning (e.g. information technology (IT) supply chain security/risk management policies, anti-tampering techniques, and requirements). 2
K0275 Knowledge of configuration management techniques. 3
K0277 Knowledge of current and emerging data encryption (e.g., Column and Tablespace Encryption, file and disk encryption) security features in databases (e.g. built-in cryptographic key management features). 2
K0286 Knowledge of N-tiered typologies (e.g. including server and client operating systems). 2
K0287 Knowledge of an organization's information classification program and procedures for information compromise. 18
K0291 Knowledge of the enterprise information technology (IT) architectural concepts and patterns (e.g., baseline, validated design, and target architectures.) 2
K0293 Knowledge of integrating the organization’s goals and objectives into the architecture. 2
K0320 Knowledge of organization's evaluation and validation criteria. 1
K0322 Knowledge of embedded systems. 10
K0323 Knowledge of system fault tolerance methodologies. 2
K0325 Knowledge of Information Theory (e.g., source coding, channel coding, algorithm complexity theory, and data compression). 6
K0326 Knowledge of demilitarized zones. 2
K0332 Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services. 14
K0333 Knowledge of network design processes, to include understanding of security objectives, operational objectives, and trade-offs. 6
K0336 Knowledge of access authentication methods. 3
K0374 WITHDRAWN: Knowledge of basic structure, architecture, and design of modern digital and telephony networks. (See K0599) 1
K0565 Knowledge of the common networking and routing protocols (e.g. TCP/IP), services (e.g., web, mail, DNS), and how they interact to provide network communications. 11

Skills 17

Code Description Work Roles
S0005 Skill in applying and incorporating information technologies into proposed solutions. 4
S0022 Skill in designing countermeasures to identified security risks. 5
S0024 Skill in designing the integration of hardware and software solutions. 5
S0027 Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes. 7
S0050 Skill in design modeling and building use cases (e.g., unified modeling language). 3
S0059 Skill in using Virtual Private Network (VPN) devices and encryption. 3
S0061 Skill in writing test plans. 2
S0076 Skill in configuring and utilizing software-based computer protection tools (e.g., software firewalls, antivirus software, anti-spyware). 3
S0116 Skill in designing multi-level security/cross domain solutions. 1
S0122 Skill in the use of design methods. 2
S0138 Skill in using Public-Key Infrastructure (PKI) encryption and digital signature capabilities into applications (e.g., S/MIME email, SSL traffic). 5
S0139 Skill in applying security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model). 1
S0152 Skill in translating operational requirements into protection needs (i.e., security controls). 1
S0168 Skill in setting up physical or logical sub-networks that separate an internal local area network (LAN) from other untrusted networks. 1
S0170 Skill in configuring and utilizing computer protection components (e.g., hardware firewalls, servers, routers, as appropriate). 2
S0367 Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). 14
S0374 Skill to identify cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations. 3

Abilities 14

Code Description Work Roles
A0008 Ability to apply the methods, standards, and approaches for describing, analyzing, and documenting an organization's enterprise information technology (IT) architecture (e.g., Open Group Architecture Framework [TOGAF], Department of Defense Architecture Framework [DoDAF], Federal Enterprise Architecture Framework [FEAF]). 3
A0014 Ability to communicate effectively when writing. 3
A0015 Ability to conduct vulnerability scans and recognize vulnerabilities in security systems. 8
A0027 Ability to apply an organization's goals and objectives to develop and maintain architecture. 3
A0038 Ability to optimize systems to meet enterprise performance requirements. 2
A0048 Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth). 2
A0049 Ability to apply secure system design tools, methods and techniques. 2
A0050 Ability to apply system design tools, methods, and techniques, including automated systems analysis and design tools. 2
A0061 Ability to design architectures and frameworks. 2
A0123 Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). 15
A0148 Ability to serve as the primary liaison between the enterprise architect and the systems security engineer and coordinates with system owners, common control providers, and system security officers on the allocation of security controls as system-specific, hybrid, or common controls. 1
A0149 Ability, in close coordination with system security officers, advise authorizing officials, chief information officers, senior information security officers, and the senior accountable official for risk management/risk executive (function), on a range of security-related issues (e.g. establishing system boundaries; assessing the severity of weaknesses and deficiencies in the system; plans of action and milestones; risk mitigation approaches; security alerts; and potential adverse effects of identified vulnerabilities). 1
A0170 Ability to identify critical infrastructure systems with information communication technology that were designed without system security considerations. 11
A0172 Ability to set up a physical or logical sub-networks that separates an internal local area network (LAN) from other untrusted networks. 2

Tasks 22

Code Description Work Roles
T0268 Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. 2
T0307 Analyze candidate architectures, allocate security services, and select security mechanisms. 2
T0314 Develop a system security context, a preliminary system security Concept of Operations (CONOPS), and define baseline system security requirements in accordance with applicable cybersecurity requirements. 2
T0328 Evaluate security architectures and designs to determine the adequacy of security design and architecture proposed or provided in response to requirements contained in acquisition documents. 2
T0338 Write detailed functional specifications that document the architecture development process. 2
T0427 Analyze user needs and requirements to plan architecture. 2
T0448 Develop enterprise architecture or system components required to meet user needs. 2
T0473 Document and update as necessary all definition and architecture activities. 2
T0484 Determine the protection needs (i.e., security controls) for the information system(s) and network(s) and document appropriately. 1
T0542 Translate proposed capabilities into technical requirements. 2
T0050 Define and prioritize essential system capabilities or business functions required for partial or full system restoration after a catastrophic failure event. 1
T0051 Define appropriate levels of system availability based on critical system functions and ensure that system requirements identify appropriate disaster recovery and continuity of operations requirements to include any appropriate fail-over/alternate site requirements, backup requirements, and material supportability requirements for system recover/restoration. 2
T0071 Develop/integrate cybersecurity designs for systems and networks with multilevel security requirements or requirements for the processing of multiple classification levels of data primarily applicable to government organizations (e.g., UNCLASSIFIED, SECRET, and TOP SECRET). 1
T0082 Document and address organization's information security, cybersecurity architecture, and systems security engineering requirements throughout the acquisition life cycle. 1
T0084 Employ secure configuration management processes. 2
T0090 Ensure that acquired or developed system(s) and architecture(s) are consistent with organization's cybersecurity architecture guidelines. 2
T0108 Identify and prioritize critical business functions in collaboration with organizational stakeholders. 2
T0177 Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. 3
T0196 Provide advice on project costs, design concepts, or design changes. 4
T0203 Provide input on security requirements to be included in statements of work and other appropriate procurement documents. 1
T0205 Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). 6
T0556 Assess and design security management functions as related to cyberspace. 1