This, I feel, reflects the information security world of the past - blighted with too many people who write abstruse policies which no one reads and are heard to continually say "no you can't do that".
I feel it's time for a change so I proposed the following three areas:
- Security Architecture
- Strategy
- Governance
- Policy framework, policy and process design
- Security architecture: security architecture patterns
- Security API design and analysis
- Operational infrastructure design and implementation
- Product selection procurement
- Process design
- Information Security Operations
- Process implementation and operation
- SLA, compliance monitoring and reporting
- Information Security Analytics
- KRI production, trends, outlier analysis, event correlation, ad hoc reports, event visualisation
- Forensic evidence capture, expert witness
- Risk Assessment