50 lines
3.2 KiB
Markdown
50 lines
3.2 KiB
Markdown
# Tasks & work activities — ethical hacker
|
|
|
|
Source: O*NET 30.3, occupation 15-1299.04 (Penetration Testers).
|
|
|
|
## Task statements
|
|
|
|
- **[nan]** Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
|
|
- **[nan]** Collect stakeholder data to evaluate risk and to develop mitigation strategies.
|
|
- **[nan]** Conduct network and security system audits, using established criteria.
|
|
- **[nan]** Configure information systems to incorporate principles of least functionality and least access.
|
|
- **[nan]** Design security solutions to address known device vulnerabilities.
|
|
- **[nan]** Develop and execute tests that simulate the techniques of known cyber threat actors.
|
|
- **[nan]** Develop infiltration tests that exploit device vulnerabilities.
|
|
- **[nan]** Develop presentations on threat intelligence.
|
|
- **[nan]** Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
|
|
- **[nan]** Discuss security solutions with information technology teams or management.
|
|
- **[nan]** Document penetration test findings.
|
|
- **[nan]** Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
|
|
- **[nan]** Gather cyber intelligence to identify vulnerabilities.
|
|
- **[nan]** Identify new threat tactics, techniques, or procedures used by cyber threat actors.
|
|
- **[nan]** Identify security system weaknesses, using penetration tests.
|
|
- **[nan]** Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
|
|
- **[nan]** Keep up with new penetration testing tools and methods.
|
|
- **[nan]** Maintain up-to-date knowledge of hacking trends.
|
|
- **[nan]** Prepare and submit reports describing the results of security fixes.
|
|
- **[nan]** Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
|
|
- **[nan]** Update corporate policies to improve cyber security.
|
|
- **[nan]** Write audit reports to communicate technical and procedural findings and recommend solutions.
|
|
|
|
## Detailed work activities
|
|
|
|
- Analyze risks to minimize losses or damages.
|
|
- Analyze security of systems, network, or data.
|
|
- Develop computer or information security policies or procedures.
|
|
- Develop computer or information systems.
|
|
- Develop organizational policies or programs.
|
|
- Develop testing routines or procedures.
|
|
- Discuss design or technical features of products or services with technical personnel.
|
|
- Evaluate characteristics of equipment or systems.
|
|
- Examine records or other types of data to investigate criminal activities.
|
|
- Interpret design or operational test results.
|
|
- Investigate illegal or suspicious activities.
|
|
- Prepare analytical reports.
|
|
- Prepare scientific or technical reports or presentations.
|
|
- Prepare technical or operational reports.
|
|
- Search files, databases or reference materials to obtain needed information.
|
|
- Stay informed about current developments in field of specialization.
|
|
- Test computer system operations to ensure proper functioning.
|
|
- Test performance of electrical, electronic, mechanical, or integrated systems or equipment.
|