In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
Ability to analyze business impact and exposure (based on emerging security threats, vulnerabilities and risks) to recommend IT solutions.
Experience and knowledge of procedures for incident handling, particularly for analyzing incident-related data and determining the appropriate response.
Experience developing policies and documenting work processes to support and enforce security standards.
Experience developing and maintaining technology and disaster recovery plans including preliminary planning, business impact analysis, alternate site selection, recovery strategies, and training and exercise development to support the overall Business Continuity Plan.
Experience monitoring and assessing security controls in the information system on an ongoing basis, documenting changes, conducting security impact analyses, and reporting system security statuses to the organization.
Ability to effectively communicate both in writing and verbally.