Where ASTRA Ready examination objectives relate to concepts in published frameworks. A crosswalk is our own mapping. It is not accreditation, endorsement, equivalence or proof that a credential holder implements the framework.
Crosswalk version 0.2 · reviewed 7 October 2026 · Issued by ASTRA Ready
How to read a row
Direct
— the assessed ASTRA task substantially matches the cited concept at the stated commercial-judgement boundary.
Supporting
— the objective develops judgement relevant to the concept but does not assess performance of the complete framework outcome.
Partial
— one defined aspect overlaps, while substantial professional or operational responsibilities remain outside the ASTRA assessment.
ASTRA Ready has mapped the published examination objectives to concepts in the FinOps Framework 2026 where a real relationship exists. The crosswalk covers areas such as cost units, licensing, forecasting, commitments, governance, architecture decisions and technology value. It helps learners, employers, partners and reviewers see where ASTRA Ready commercial-judgement objectives touch established FinOps practice. It does not mean ASTRA Ready programmes are FinOps Foundation certifications, that the Foundation has reviewed or endorsed ASTRA Ready, or that an ASTRA Ready credential shows full FinOps practitioner competence. Objectives with no FinOps row sit outside the Framework's scope. Labels show whether the connection is Direct, Supporting or Partial. ASTRA Ready records the Framework version and review date and will reassess affected rows when the Framework or the objectives change.
Given a scenario, identify the cost meter, period, usage owner and forecast exposure behind a quote.
ASTRA directly assesses whether the candidate can identify the cost meter, period, usage owner, and forecast exposure; that decision matches FinOps capability Unit Economics at the published assessment boundary.
AdvisorAdvisor D2.6Relationship: Supporting
Given a scenario, calculate commercial economics without merging subscription and partner-service revenue.
The requirement to calculate commercial economics without merging subscription and partner-service revenue supports FinOps capability Unit Economics; ASTRA assesses the related judgement, not full operational ownership.
AdvisorAdvisor D2.7Relationship: Direct
Given a scenario, calculate released operational capacity while separating model from realised return.
This objective directly assesses whether candidates can calculate released operational capacity while separating model from realised return; the task matches FinOps capability Unit Economics within ASTRA's scope.
Given a scenario, interpret entitlements, rights and commitment terms under changing demand.
Here ASTRA directly assesses whether the candidate can interpret entitlements, rights and commitment terms under changing demand; the assessed decision aligns with FinOps capability Licensing & SaaS at the stated boundary.
AssociateAssociate D2.2Relationship: Direct
Given a scenario, separate software rights, one-time delivery and recurring service commitments.
This objective directly assesses whether the candidate can separate software rights, one-time delivery and recurring service commitments; the task matches FinOps capability Licensing & SaaS within ASTRA's commercial scope.
AssociateAssociate D2.4Relationship: Direct
Given a scenario, compare alternative user quantities across an equivalent term.
This objective directly assesses whether the candidate can compare alternative user quantities across an equivalent term; the task matches FinOps capability Licensing & SaaS within ASTRA's commercial scope.
Given a scenario, reconcile a usage record to a defined billing line and find a mismatch.
This objective directly assesses whether candidates can reconcile a usage record to its billing line and identify a mismatch; the task matches FinOps capability Invoicing & Chargeback within ASTRA's scope.
AssociateAssociate D2.3Relationship: Direct
Given a scenario, derive a billable quantity under the specified usage rule.
The objective directly assesses whether the candidate can derive a billable quantity under the specified usage rule; this corresponds to FinOps capability Invoicing & Chargeback within ASTRA's customer-decision scope.
Given a scenario, calculate stepped or tiered charges and the cost of unused commitment.
This objective directly assesses whether candidates can calculate stepped or tiered charges and the cost of unused commitment; the task matches FinOps capability Rate Optimization within ASTRA's scope.
AssociateAssociate D2.6Relationship: Direct
Given a scenario, interpret commitment thresholds and identify unverified financial assumptions.
ASTRA directly assesses whether the candidate can interpret commitment thresholds and identify unverified financial assumptions; that decision matches FinOps capability Rate Optimization at the published assessment boundary.
Given a scenario, compare scenarios without treating demand assumptions as confirmed savings.
ASTRA directly assesses whether the candidate can compare scenarios without treating demand assumptions as confirmed savings; that decision matches FinOps capability Forecasting at the published assessment boundary.
AssociateAssociate D2.6Relationship: Supporting
Given a scenario, interpret commitment thresholds and identify unverified financial assumptions.
This objective supports FinOps capability Forecasting: candidates must interpret commitment thresholds and identify unverified financial assumptions, using related judgement within ASTRA's commercial scope.
Given a scenario, link budget, admission and approval controls to cost and service continuity.
Requiring candidates to link budget and approval controls to cost and continuity supports FinOps capability Governance, Policy & Risk; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, classify a cloud offer by what its provider and customer actually operate.
The requirement to classify a cloud offer by what its provider and customer actually operate supports FinOps capability Architecting & Workload Placement; ASTRA assesses the related judgement, not full operational ownership.
AssociateAssociate D2.1Relationship: Direct
Given a scenario, compare cloud service boundaries against the customer’s ability to operate them before comparing prices.
The objective directly assesses whether the candidate can compare cloud service boundaries with the customer's operating capability; this corresponds to FinOps capability Architecting & Workload Placement within ASTRA's customer-decision scope.
Given a scenario, distinguish a spending notification from an enforced limit and sequence the approved response.
Requiring candidates to distinguish a spending notification from an enforced limit and sequence the approved response supports FinOps capability Budgeting; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, recommend a conditional offer using operating fit, cost and documented gates.
The requirement to recommend a conditional offer using operating fit, cost and documented gates supports FinOps capability Planning & Estimating; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, calculate the commercial effect of a stated security-volume change and identify whether the effect changes price, coverage, service capacity or more than one of these.
Requiring candidates to calculate the effect of volume change across price, coverage, or service capacity supports FinOps capability Usage Optimization; ASTRA tests the related decision rather than complete operational practice.
Attribution and reuse+
Framework used: FinOps Framework 2026, including the March 2026 update; reviewed 7 October 2026. The crosswalk uses selected Framework capability names and URLs. The FinOps Foundation licenses Framework content under Creative Commons Attribution 4.0 International (CC BY 4.0), which permits sharing and adaptation, including commercial use, with credit, a licence link and an indication of changes. Attribution: "FinOps Framework by FinOps Foundation." ASTRA Ready adapted selected capability references under CC BY 4.0 and made the mapping judgements independently. ASTRA Ready does not use FinOps Foundation trademarks to suggest endorsement. Mapping an objective to a capability does not make an ASTRA Ready programme or credential a FinOps Foundation programme or certification. Links: https://www.finops.org/framework/ · https://creativecommons.org/licenses/by/4.0/
NIST Cybersecurity Framework (CSF) 2.0
Version 2.0 · 2024 · Reuse: NIST publication (CSWP 29); U.S. Government work, not subject to copyright in the United States; source credit given · Reviewed 7 October 2026
ASTRA Ready has mapped the published examination objectives to concepts in the NIST Cybersecurity Framework (CSF) 2.0 where the assessed commercial judgement relates to a CSF outcome. The crosswalk uses CSF Functions and Categories covering governance, roles and authorities, risk, assets, identity, data security, resilience, incident response and recovery. It helps readers see how selected ASTRA Ready objectives connect to a widely used cybersecurity risk vocabulary. It is not a statement that NIST has reviewed, approved, accredited, certified or endorsed ASTRA Ready or its credentials, and passing an ASTRA Ready examination does not show implementation of the CSF or operation of a cybersecurity programme. Rows are omitted where the relationship would be stretched. ASTRA Ready records the framework version and review date so rows can be reassessed when objectives or CSF resources change.
Given a scenario, trace the producer, consumer, integrator and business approver through a proposed flow.
This objective supports NIST CSF concept GV.RR: candidates must trace the producer, consumer, integrator and business approver through a proposed flow; broader operational ownership is not assessed.
AdvisorAdvisor D3.3Relationship: Direct
Given a scenario, assign control operation, disclosure and customer-exception decisions to their authorised owners.
This objective directly assesses whether candidates can assign control operation, disclosure and customer-exception decisions to their authorised owners; the task matches NIST CSF concept GV.RR within ASTRA's scope.
AssociateAssociate D6.2Relationship: Supporting
Given a scenario, identify who can approve each business, technical and commercial decision.
The requirement to identify who can approve each business, technical and commercial decision supports NIST CSF concept GV.RR; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, identify supported least-privilege and diagnostic controls, and what remains unproven.
This objective supports NIST CSF concept PR.PS: candidates must identify supported least-privilege and diagnostic controls, and what remains unproven, using related judgement within ASTRA's commercial scope.
Given a scenario, identify the operating dependencies required for a security capability to deliver its stated outcome and mark any dependency not evidenced in the deal record.
This objective supports NIST CSF concept PR.PS: candidates must identify operating dependencies required for a security capability to deliver its outcome; broader operational ownership is not assessed.
Given a scenario, translate a scoped security questionnaire into claim-specific evidence requests.
This objective supports NIST CSF concept GV.OV: candidates must translate a scoped security questionnaire into claim-specific evidence requests, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D3.4Relationship: Supporting
Given a scenario, interpret an assurance report within its period, tested services and exceptions.
This objective supports NIST CSF concept GV.OV because candidates must interpret an assurance report within its period, tested services and exceptions; the assessment stays within the published commercial task.
AdvisorAdvisor D3.7Relationship: Supporting
Given a scenario, respond to an assurance objection without extending supplier evidence to a customer tenant.
This objective supports NIST CSF concept GV.OV because candidates must answer an assurance objection without extending supplier evidence beyond its scope; the assessment stays within the published commercial task.
Given a scenario, sequence remediation, retest, customer acceptance and approved messaging.
The requirement to sequence remediation, retest, customer acceptance and approved messaging supports NIST CSF concept ID.IM; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, interpret a security POC result within its tested data, environment, duration and success criteria without generalising it to production-wide effectiveness.
This objective supports NIST CSF concept ID.IM: candidates must interpret a security POC within its data, environment, duration, and success criteria; broader operational ownership is not assessed.
Given a scenario, use an equivocal or failed security POC result to choose among retest, scope change, remediation, commercial hold or no-go, with the evidence required for that next action.
The requirement to choose the next action after an equivocal or failed security POC supports NIST CSF concept ID.IM; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, calculate incident reporting time using the specified clock trigger and authorisation.
Requiring candidates to calculate incident reporting time using the specified clock trigger and authorisation supports NIST CSF concept RS.CO; ASTRA tests the related decision rather than complete operational practice.
AssociateAssociate D8.2Relationship: Supporting
Given a scenario, sequence the authorised response to a reported incident without inventing impact findings.
Requiring candidates to sequence an authorised incident response without inventing impact findings supports NIST CSF concept RS.CO; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, judge whether a seller claim about supporting CERT-In incident reporting is supported by the product or service scope, without transferring the customer’s reporting responsibility to the seller.
This objective supports NIST CSF concept RS.CO: candidates must bound an incident-reporting sales claim to the supplied service scope, using related judgement within ASTRA's commercial scope.
Given a scenario, evaluate retention and subprocessor evidence across the actual data lifecycle.
This objective supports NIST CSF concept PR.DS: candidates must evaluate retention and subprocessor evidence across the actual data lifecycle, using related judgement within ASTRA's commercial scope.
AssociateAssociate D3.3Relationship: Supporting
Given a scenario, trace the actual location and access boundary for each relevant data store or path.
Requiring candidates to trace location and access boundaries across relevant data stores and paths supports NIST CSF concept PR.DS; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, distinguish authentication from permission for a named operation.
Here ASTRA directly assesses whether the candidate can distinguish authentication from permission for a named operation; the assessed decision aligns with NIST CSF concept PR.AA at the stated boundary.
AssociateAssociate D3.2Relationship: Direct
Given a scenario, evaluate who is included in an identity-control test and identify coverage exceptions.
ASTRA directly assesses whether the candidate can identify identity-control test coverage and exceptions; that decision matches NIST CSF concept PR.AA at the published assessment boundary.
Given a scenario, translate a described security event into the customer consequence and a testable requirement.
Requiring candidates to translate a security event into customer consequence and a testable requirement supports NIST CSF concept ID.RA; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, prioritise security sales discovery using the supplied business-service criticality, consequence tolerance and dependency evidence without inferring technical likelihood.
The requirement to prioritise security discovery from service criticality, consequence tolerance, and dependency evidence supports NIST CSF concept ID.RA; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, write an evidence-bounded risk-reduction proposition linking the buyer’s threat concern, business consequence, control objective, seller scope and residual exposure.
This objective supports NIST CSF concept ID.RA: candidates must link threat, consequence, control, scope, and residual exposure, using related judgement within ASTRA's commercial scope.
Given a scenario, distinguish service restoration time from the point to which data can be restored.
The requirement to separate service restoration time from the recoverable-data point supports NIST CSF concept PR.IR; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, distinguish service restoration time from the point to which data can be restored.
This objective supports NIST CSF concept RC.RP because candidates must separate service restoration time from the recoverable-data point; the assessment stays within the published commercial task.
Given a scenario, reconcile conflicting success criteria from security, IT, operations, privacy or legal, procurement and the business sponsor before advancing the deal.
This objective supports NIST CSF concept GV.OC because candidates must reconcile conflicting criteria across security, operations, privacy, procurement, and business sponsors; the assessment stays within the published commercial task.
Given a scenario, classify which stated business consequences are supported by the supplied incident evidence and which remain assumptions or seller inference.
This objective supports NIST CSF concept RS.AN because candidates must separate evidenced incident consequences from assumptions and seller inference; the assessment stays within the published commercial task.
Given a scenario, classify a security offer by the primary job its supplied capabilities perform rather than by the vendor’s category label.
This objective supports NIST CSF concept ID.AM: candidates must classify a security offer by the primary job its supplied capabilities perform; broader operational ownership is not assessed.
Given a scenario, distinguish a product capability shown in documentation from the portion of the customer environment where that capability is actually deployed and active.
This objective supports NIST CSF concept ID.AM: candidates must separate documented product capability from the customer environment where it is active; broader operational ownership is not assessed.
Given a scenario, calculate effective deployed coverage from the supplied eligible population, exclusions, licensed quantity, deployment status and reporting status.
The requirement to calculate effective deployed coverage from population, exclusions, licences, and deployment status supports NIST CSF concept ID.AM; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, allocate vendor, distributor, reseller and MSSP responsibilities for quoting, implementation, managed operation and escalation from supplied agreements while preserving the customer as the decision-maker.
This objective supports NIST CSF concept GV.SC because candidates must allocate vendor, distributor, reseller, and MSSP responsibilities while preserving customer authority; the assessment stays within the published commercial task.
Attribution and reuse+
Framework used: The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 26 February 2024; reviewed 7 October 2026. The crosswalk maps selected objectives to CSF Functions and Categories (for example GV.RR, ID.RA, PR.AA, RS.CO, RC.RP). It is ASTRA Ready's interpretation and is not an official NIST Informative Reference. NIST Technical Series works authored by NIST employees are not subject to copyright protection in the United States; NIST asks for source credit. Source credit: "Based on The NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology, U.S. Department of Commerce." NIST has not reviewed, approved, certified, accredited or endorsed ASTRA Ready. The crosswalk is not CSF implementation evidence. Links: https://doi.org/10.6028/NIST.CSWP.29 · https://www.nist.gov/copyrights-disclaimers
NIST AI RMF 1.0
Version 1.0 · 2023; revision in progress as of 2026-10-07 · Reuse: NIST publication (AI 100-1); U.S. Government work, not subject to copyright in the United States; source credit given · Reviewed 7 October 2026
ASTRA Ready has mapped the published examination objectives to concepts in the NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0 where the learning and assessment address AI context, governance, measurement, oversight, provider risk or deployment decisions. The crosswalk uses the GOVERN, MAP, MEASURE and MANAGE functions and selected categories. It makes relationships transparent without presenting ASTRA Ready as an AI governance authority or technical AI assurance scheme. NIST has not reviewed, approved, accredited, certified or endorsed ASTRA Ready. Passing an ASTRA Ready examination does not establish organisation-wide implementation of AI RMF outcomes. NIST is revising AI RMF 1.0; ASTRA Ready marks the version used and will review affected rows after the revision is published.
Given a scenario, frame an AI-supported workflow by decision consequence, source and permitted action.
This objective directly assesses whether candidates can frame an AI workflow by consequence, source, and permitted action; the task matches NIST AI RMF concept MAP 1.1 within ASTRA's scope.
AssociateAssociate D4.1Relationship: Direct
Given a scenario, select a bounded AI use case consistent with approved inputs, reviewer availability and action authority.
This objective directly assesses whether candidates can select an authorised bounded AI use case; the task matches NIST AI RMF concept MAP 1.1 within ASTRA's scope.
Given a scenario, evaluate a measured model result for the intended population and operating threshold.
This objective supports NIST AI RMF concept MEASURE 1: candidates must evaluate a measured model result for the intended population and operating threshold; broader operational ownership is not assessed.
Given a scenario, define allowed data, processing purpose, retention and deletion evidence.
The requirement to define allowed data, processing purpose, retention and deletion evidence supports NIST AI RMF concept GOVERN 1; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, interpret intervention metrics and choose the owner-led response to drift.
Requiring candidates to interpret intervention metrics and choose the owner-led response to drift supports NIST AI RMF concept MEASURE 3; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, distinguish model intent, tool execution and reviewer authority in an AI control event.
This objective directly assesses whether candidates can separate model intent, tool execution, and reviewer authority; the task matches NIST AI RMF concept MANAGE 1.1 within ASTRA's scope.
AssociateAssociate D8.5Relationship: Direct
Given a scenario, convert AI marketing claims into a bounded proposal with evidenced results and open release gates.
This objective directly assesses whether candidates can turn AI marketing claims into a bounded, evidence-based proposal; the task matches NIST AI RMF concept MANAGE 1.1 within ASTRA's scope.
Given a scenario, prepare a conditional deployment handover with monitoring and reversal gates.
The requirement to prepare a conditional deployment handover with monitoring and reversal gates supports NIST AI RMF concept MANAGE 4; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, distinguish AI assurance evidence from claims it does not establish.
This objective supports NIST AI RMF concept MEASURE 2 because candidates must distinguish AI assurance evidence from claims it does not establish; the assessment stays within the published commercial task.
AssociateAssociate D4.4Relationship: Supporting
Given a scenario, test an AI answer against the cited evidence rather than confidence language.
This objective supports NIST AI RMF concept MEASURE 2: candidates must test an AI answer against the cited evidence rather than confidence language; broader operational ownership is not assessed.
Given a scenario, assign business, data, model and execution approval decisions to the correct owners.
This objective supports NIST AI RMF concept GOVERN 2: candidates must assign business, data, model and execution approval decisions to the correct owners; broader operational ownership is not assessed.
AdvisorAdvisor D8.6Relationship: Supporting
Given a scenario, sequence the review, version binding and release checks for a consequential action.
This objective supports NIST AI RMF concept GOVERN 2: candidates must sequence the review, version binding and release checks for a consequential action, using related judgement within ASTRA's commercial scope.
AssociateAssociate D4.6Relationship: Supporting
Given a scenario, distinguish an instruction embedded in content from valid execution authority.
The requirement to distinguish an instruction embedded in content from valid execution authority supports NIST AI RMF concept GOVERN 2; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, decide which provider or model changes require retest before deployment.
This objective supports NIST AI RMF concept GOVERN 6 because candidates must decide which provider or model changes require retest before deployment; the assessment stays within the published commercial task.
Given a scenario, separate retrieved source evidence from model-generated content and unsupported assertions.
The requirement to separate retrieved source evidence from model-generated content and unsupported assertions supports NIST AI RMF concept MAP 2; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, choose task-sufficient inputs under the stated data-use contract.
Requiring candidates to choose task-sufficient inputs under the stated data-use contract supports NIST AI RMF concept MAP 4; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, calculate a measured workflow outcome after human review and rework.
Requiring candidates to calculate a measured workflow outcome after human review and rework supports NIST AI RMF concept MAP 3; ASTRA tests the related decision rather than complete operational practice.
Attribution and reuse+
Framework used: NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0, 26 January 2023; reviewed 7 October 2026. NIST has stated that AI RMF 1.0 is being revised; ASTRA Ready will re-review affected rows after the revision is published. The crosswalk maps selected objectives to GOVERN, MAP, MEASURE and MANAGE concepts. NIST's own crosswalk pages state that inclusion of a crosswalk does not imply NIST endorsement or comprehensive coverage; ASTRA Ready applies the same boundary. Source credit: "Based on the NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0, National Institute of Standards and Technology, U.S. Department of Commerce." NIST has not reviewed, approved, certified, accredited or endorsed ASTRA Ready. Links: https://www.nist.gov/itl/ai-risk-management-framework · https://airc.nist.gov/airmf-resources/playbook/
NICE Workforce Framework for Cybersecurity
Version SP 800-181 Rev.1; Components v2.2.0 · 2026 · Reuse: NIST publication (SP 800-181 Rev. 1, Components v2.2.0); U.S. Government work, not subject to copyright in the United States; source credit given · Reviewed 7 October 2026
ASTRA Ready has mapped the published examination objectives to concepts in the NICE Workforce Framework for Cybersecurity where ASTRA Cybersecurity Sales Specialist objectives and selected ASTRA Tech Sales Advisor objectives overlap established cybersecurity Work Roles or Competency Areas. The crosswalk uses NIST SP 800-181 Rev. 1 with NICE Framework Components v2.2.0. It describes occupational proximity; it does not turn ASTRA Ready credentials into NICE Work Roles, job qualifications or cybersecurity certifications. NIST and the NICE Program Office have not reviewed, approved, accredited, certified or endorsed ASTRA Ready. ASTRA Tech Sales Associate objectives are not mapped to NICE. ASTRA Ready will review the crosswalk when NICE Framework Components change.
Given a scenario, trace the producer, consumer, integrator and business approver through a proposed flow.
Asking candidates to trace the producer, consumer, integrator and business approver through a proposed flow partially overlaps NICE Work Role DD-WRL-006, while full role or framework performance remains outside ASTRA.
Given a scenario, recommend a bounded security category fit using the buyer’s concern, environment, operating model and observed coverage gaps, while naming what the category does not address.
This objective partially overlaps NICE Work Role DD-WRL-006: candidates must recommend bounded category fit from concern, environment, operating model, and coverage gaps, while full professional practice remains outside ASTRA.
Given a scenario, identify supported least-privilege and diagnostic controls, and what remains unproven.
The requirement to identify supported least-privilege and diagnostic controls, and what remains unproven partially overlaps NICE Work Role DD-WRL-001, while full professional practice remains outside the ASTRA assessment.
Given a scenario, translate a scoped security questionnaire into claim-specific evidence requests.
The requirement to translate a scoped security questionnaire into claim-specific evidence requests partially overlaps NICE Work Role OG-WRL-012, while full professional practice remains outside the ASTRA assessment.
AdvisorAdvisor D3.4Relationship: Partial
Given a scenario, interpret an assurance report within its period, tested services and exceptions.
Asking candidates to interpret an assurance report within its period, tested services and exceptions partially overlaps NICE Work Role OG-WRL-012, while full role or framework performance remains outside ASTRA.
AdvisorAdvisor D3.5Relationship: Partial
Given a scenario, sequence remediation, retest, customer acceptance and approved messaging.
This objective partially overlaps NICE Work Role OG-WRL-012 through the need to sequence remediation, retest, customer acceptance and approved messaging, while broader operational practice remains outside ASTRA.
Given a scenario, assign control operation, disclosure and customer-exception decisions to their authorised owners.
This objective partially overlaps NICE Work Role OG-WRL-014: candidates must assign control operation, disclosure and customer-exception decisions to their authorised owners, while full framework practice remains outside ASTRA.
Given a scenario, prioritise security sales discovery using the supplied business-service criticality, consequence tolerance and dependency evidence without inferring technical likelihood.
This objective partially overlaps NICE Work Role OG-WRL-014 through the need to prioritise security discovery from service criticality, consequence tolerance, and dependency evidence, while broader operational practice remains outside ASTRA.
Given a scenario, write an evidence-bounded risk-reduction proposition linking the buyer’s threat concern, business consequence, control objective, seller scope and residual exposure.
The requirement to link threat, consequence, control, scope, and residual exposure partially overlaps NICE Work Role OG-WRL-014, while full professional practice remains outside the ASTRA assessment.
Given a scenario, calculate incident reporting time using the specified clock trigger and authorisation.
This objective partially overlaps NICE Work Role PD-WRL-003: candidates must calculate incident reporting time using the specified clock trigger and authorisation, while full framework practice remains outside ASTRA.
Given a scenario, classify which stated business consequences are supported by the supplied incident evidence and which remain assumptions or seller inference.
Asking candidates to separate evidenced incident consequences from assumptions and seller inference partially overlaps NICE Work Role PD-WRL-003, while full role or framework performance remains outside ASTRA.
Given a scenario, judge whether a seller claim about supporting CERT-In incident reporting is supported by the product or service scope, without transferring the customer’s reporting responsibility to the seller.
The requirement to bound an incident-reporting sales claim to the supplied service scope partially overlaps NICE Work Role PD-WRL-003, while full professional practice remains outside the ASTRA assessment.
Given a scenario, frame an AI-supported workflow by decision consequence, source and permitted action.
The requirement to frame an AI workflow by consequence, source, and permitted action partially overlaps NICE Competency Area NF-COM-002, while full professional practice remains outside the ASTRA assessment.
AdvisorAdvisor D4.2Relationship: Partial
Given a scenario, evaluate a measured model result for the intended population and operating threshold.
Asking candidates to evaluate a measured model result for the intended population and operating threshold partially overlaps NICE Competency Area NF-COM-002, while full role or framework performance remains outside ASTRA.
AdvisorAdvisor D4.3Relationship: Partial
Given a scenario, define allowed data, processing purpose, retention and deletion evidence.
This objective partially overlaps NICE Competency Area NF-COM-002 through the need to define allowed data, processing purpose, retention and deletion evidence, while broader operational practice remains outside ASTRA.
Given a scenario, evaluate retention and subprocessor evidence across the actual data lifecycle.
The requirement to evaluate retention and subprocessor evidence across the actual data lifecycle partially overlaps NICE Work Role OG-WRL-008, while full professional practice remains outside the ASTRA assessment.
Given a scenario, use the supplied commencement notice and rule extract to distinguish India data-protection provisions already in force from future-dated duties and bound the sales message accordingly.
Asking candidates to distinguish current from future data-protection duties using the supplied commencement notice partially overlaps NICE Work Role OG-WRL-008, while full role or framework performance remains outside ASTRA.
Given a scenario, distinguish a stakeholder’s influence from the authority to accept security risk, approve architecture, release budget or commit the organisation.
This objective partially overlaps NICE Work Role OG-WRL-013: candidates must separate stakeholder influence from authority over risk, architecture, budget, and commitment, while full framework practice remains outside ASTRA.
Given a scenario, classify a security offer by the primary job its supplied capabilities perform rather than by the vendor’s category label.
This objective partially overlaps NICE Work Role IO-WRL-006: candidates must classify a security offer by the primary job its supplied capabilities perform, while full framework practice remains outside ASTRA.
Given a scenario, distinguish a product capability shown in documentation from the portion of the customer environment where that capability is actually deployed and active.
Asking candidates to separate documented product capability from the customer environment where it is active partially overlaps NICE Work Role IO-WRL-006, while full role or framework performance remains outside ASTRA.
Given a scenario, calculate effective deployed coverage from the supplied eligible population, exclusions, licensed quantity, deployment status and reporting status.
This objective partially overlaps NICE Work Role IO-WRL-006 through the need to calculate effective deployed coverage from population, exclusions, licences, and deployment status, while broader operational practice remains outside ASTRA.
Given a scenario, evaluate an alleged replacement or consolidation claim by separating overlapping features from the distinct security jobs, dependencies and uncovered use cases.
This objective partially overlaps NICE Work Role OG-WRL-015: candidates must test a replacement claim against feature overlap, dependencies, and uncovered security jobs, while full framework practice remains outside ASTRA.
Given a scenario, prepare a renewal commercial view that separates price movement, protected-population change, service-scope change and evidence of security outcome.
This objective partially overlaps NICE Work Role OG-WRL-015: candidates must separate renewal price, protected population, service scope, and outcome evidence, while full framework practice remains outside ASTRA.
Given a scenario, separate product entitlement from managed-service responsibilities, service hours, response commitments and customer-retained duties.
This objective partially overlaps NICE Work Role OG-WRL-009: candidates must separate product entitlement from service responsibilities, hours, commitments, and retained duties, while full framework practice remains outside ASTRA.
Given a scenario, define a security POC as a buyer decision test by specifying the buyer decision, the success criteria and an explicit stop condition before testing begins.
This objective partially overlaps NICE Work Role DD-WRL-007: candidates must define a security POC around a buyer decision, success criteria, and stop condition, while full professional practice remains outside ASTRA.
Given a scenario, design safe, representative POC test conditions using supplied data, controlled operating conditions and explicit exclusions, and record which production conditions remain untested.
This objective partially overlaps NICE Work Role DD-WRL-007: candidates must design representative POC conditions and record untested production conditions, while full framework practice remains outside ASTRA.
Given a scenario, use an equivocal or failed security POC result to choose among retest, scope change, remediation, commercial hold or no-go, with the evidence required for that next action.
This objective partially overlaps NICE Work Role DD-WRL-007 through the need to choose the next action after an equivocal or failed security POC, while broader operational practice remains outside ASTRA.
Given a scenario, allocate vendor, distributor, reseller and MSSP responsibilities for quoting, implementation, managed operation and escalation from supplied agreements while preserving the customer as the decision-maker.
Asking candidates to allocate vendor, distributor, reseller, and MSSP responsibilities while preserving customer authority partially overlaps NICE Work Role OG-WRL-017, while full role or framework performance remains outside ASTRA.
Given a scenario, prepare a security POC-to-production and sales-to-delivery handover that preserves coverage baseline, integrations, tuning, staffing, service hours, escalation paths, exclusions and unresolved customer actions.
The requirement to prepare a POC-to-production handover covering coverage, integrations, staffing, exclusions, and open actions partially overlaps NICE Work Role OG-WRL-011, while full professional practice remains outside the ASTRA assessment.
Attribution and reuse+
Framework used: Workforce Framework for Cybersecurity (NICE Framework), NIST SP 800-181 Rev. 1, with NICE Framework Components v2.2.0 (28 April 2026); reviewed 7 October 2026. The crosswalk maps ASTRA Cybersecurity Sales Specialist objectives and selected ASTRA Tech Sales Advisor objectives to Work Roles and, where relevant, Competency Areas. ASTRA Tech Sales Associate objectives are not mapped to NICE. Work Roles describe areas of work, not job titles, and NIST notes that assessment typically occurs at the Task level; ASTRA Ready therefore records Work Role relationships as Partial unless a narrower relationship is stated. Source credit: "Based on the NICE Workforce Framework for Cybersecurity, National Institute of Standards and Technology, U.S. Department of Commerce." NIST and the NICE Program Office have not reviewed, approved, certified, accredited or endorsed ASTRA Ready. A mapping does not establish that a credential holder performs the full Work Role. Links: https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center/nice-framework-current-versions
ASTRA Ready has mapped the published examination objectives to concepts in ESCO, the European classification of Skills, Competences, Qualifications and Occupations, where a defensible relationship exists to ICT sales occupations or skills. The crosswalk uses ESCO v1.2.1 and its concept URIs for occupations and skills such as ICT account management, ICT business development, presales, customer-needs analysis, business analysis, project management and ICT risk management. It makes the relevance of assessed activities easier to understand across roles and countries. It does not state that the European Commission has approved, accredited, certified or endorsed ASTRA Ready, and an ESCO relationship does not mean an ASTRA Ready credential qualifies a holder for an occupation. This publication uses the ESCO classification of the European Commission.
Given a scenario, frame a scoped technical-commercial pilot from the required outcome and unknown interface capabilities.
This objective supports ESCO occupation "ICT presales engineer": candidates must frame a scoped technical-commercial pilot from the required outcome and unknown interface capabilities; broader operational ownership is not assessed.
AdvisorAdvisor D1.2Relationship: Supporting
Given a scenario, trace the producer, consumer, integrator and business approver through a proposed flow.
This objective supports ESCO occupation "ICT presales engineer": candidates must trace the producer, consumer, integrator and business approver through a proposed flow, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D4.1Relationship: Supporting
Given a scenario, frame an AI-supported workflow by decision consequence, source and permitted action.
This objective supports ESCO occupation "ICT presales engineer" because candidates must frame an AI workflow by consequence, source, and permitted action; the assessment stays within the published commercial task.
Given a scenario, choose an integration pattern that meets timing, replay and duplicate constraints.
The requirement to choose an integration pattern that meets timing, replay and duplicate constraints supports ESCO skill "define integration strategy"; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, interpret reliability test measures without hiding retries or failed records.
This objective supports ESCO skill "perform data analysis" because candidates must interpret reliability test measures without hiding retries or failed records; the assessment stays within the published commercial task.
AdvisorAdvisor D2.3Relationship: Supporting
Given a scenario, reconcile a usage record to a defined billing line and find a mismatch.
This objective supports ESCO skill "perform data analysis": candidates must reconcile a usage record to its billing line and identify a mismatch; broader operational ownership is not assessed.
AdvisorAdvisor D4.2Relationship: Supporting
Given a scenario, evaluate a measured model result for the intended population and operating threshold.
This objective supports ESCO skill "perform data analysis": candidates must evaluate a measured model result for the intended population and operating threshold, using related judgement within ASTRA's commercial scope.
Given a scenario, resolve identifier, status, timestamp and version semantics in a two-party data contract.
This objective supports ESCO skill "interpret technical requirements": candidates must resolve identifier, status, timestamp and version semantics in a two-party data contract; broader operational ownership is not assessed.
AdvisorAdvisor D1.6Relationship: Supporting
Given a scenario, trace technical and approval boundaries across a candidate workflow.
The requirement to trace technical and approval boundaries across a candidate workflow supports ESCO skill "interpret technical requirements"; ASTRA assesses the related judgement, not full operational ownership.
AssociateAssociate D1.3Relationship: Supporting
Given a scenario, interpret the sending and receiving API contracts and identify necessary field or meaning translations.
This objective supports ESCO skill "interpret technical requirements": candidates must interpret the sending and receiving API contracts and identify necessary field or meaning translations; broader operational ownership is not assessed.
Given a scenario, identify the cost meter, period, usage owner and forecast exposure behind a quote.
This objective supports ESCO skill "perform business analysis" because candidates must identify the cost meter, period, usage owner, and forecast exposure; the assessment stays within the published commercial task.
AdvisorAdvisor D2.2Relationship: Supporting
Given a scenario, interpret entitlements, rights and commitment terms under changing demand.
This objective supports ESCO skill "perform business analysis": candidates must interpret entitlements, rights and commitment terms under changing demand, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D2.4Relationship: Supporting
Given a scenario, calculate stepped or tiered charges and the cost of unused commitment.
This objective supports ESCO skill "perform business analysis": candidates must calculate stepped or tiered charges and the cost of unused commitment, using related judgement within ASTRA's commercial scope.
Given a scenario, identify supported least-privilege and diagnostic controls, and what remains unproven.
This objective partially overlaps ESCO skill "implement ICT risk management": candidates must identify supported least-privilege and diagnostic controls, and what remains unproven, while full professional practice remains outside ASTRA.
AdvisorAdvisor D3.3Relationship: Partial
Given a scenario, assign control operation, disclosure and customer-exception decisions to their authorised owners.
This objective partially overlaps ESCO skill "implement ICT risk management": candidates must assign control operation, disclosure and customer-exception decisions to their authorised owners, while full professional practice remains outside ASTRA.
AdvisorAdvisor D3.5Relationship: Partial
Given a scenario, sequence remediation, retest, customer acceptance and approved messaging.
Asking candidates to sequence remediation, retest, customer acceptance and approved messaging partially overlaps ESCO skill "implement ICT risk management", while full role or framework performance remains outside ASTRA.
Given a scenario, translate a scoped security questionnaire into claim-specific evidence requests.
This objective partially overlaps ESCO skill "manage IT security compliances" through the need to translate a scoped security questionnaire into claim-specific evidence requests, while broader operational practice remains outside ASTRA.
AdvisorAdvisor D3.4Relationship: Partial
Given a scenario, interpret an assurance report within its period, tested services and exceptions.
This objective partially overlaps ESCO skill "manage IT security compliances": candidates must interpret an assurance report within its period, tested services and exceptions, while full framework practice remains outside ASTRA.
AssociateAssociate D3.5Relationship: Partial
Given a scenario, match assurance evidence to the exact control, population, period and claim.
This objective partially overlaps ESCO skill "manage IT security compliances": candidates must match assurance evidence to the exact control, population, period and claim, while full professional practice remains outside ASTRA.
Given a scenario, define allowed data, processing purpose, retention and deletion evidence.
Requiring candidates to define allowed data, processing purpose, retention and deletion evidence supports ESCO skill "manage ICT data classification"; ASTRA tests the related decision rather than complete operational practice.
AssociateAssociate D3.3Relationship: Partial
Given a scenario, trace the actual location and access boundary for each relevant data store or path.
This objective partially overlaps ESCO skill "manage ICT data classification": candidates must trace location and access boundaries across relevant data stores and paths, while full framework practice remains outside ASTRA.
AssociateAssociate D4.3Relationship: Supporting
Given a scenario, choose task-sufficient inputs under the stated data-use contract.
This objective supports ESCO skill "manage ICT data classification": candidates must choose task-sufficient inputs under the stated data-use contract, using related judgement within ASTRA's commercial scope.
Given a scenario, distinguish model intent, tool execution and reviewer authority in an AI control event.
The requirement to separate model intent, tool execution, and reviewer authority supports ESCO skill "identify ICT security risks"; ASTRA assesses the related judgement, not full operational ownership.
AssociateAssociate D4.6Relationship: Supporting
Given a scenario, distinguish an instruction embedded in content from valid execution authority.
This objective supports ESCO skill "identify ICT security risks" because candidates must distinguish an instruction embedded in content from valid execution authority; the assessment stays within the published commercial task.
Given a scenario, deliver a bounded architecture recommendation with explicit exit criteria.
This objective supports ESCO skill "propose ICT solutions to business problems": candidates must deliver a bounded architecture recommendation with explicit exit criteria, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D5.2Relationship: Supporting
Given a scenario, compare options under complete first-year costs and nonfinancial gates.
This objective supports ESCO skill "propose ICT solutions to business problems": candidates must compare options under complete first-year costs and nonfinancial gates; broader operational ownership is not assessed.
AdvisorAdvisor D5.3Relationship: Supporting
Given a scenario, give a conditional purchasing decision with named triggers and accountable owners.
This objective supports ESCO skill "propose ICT solutions to business problems": candidates must give a conditional purchasing decision with named triggers and accountable owners; broader operational ownership is not assessed.
Given a scenario, deliver a governed customer/partner handover with review and exit conditions.
Requiring candidates to deliver a governed customer/partner handover with review and exit conditions supports ESCO skill "perform project management"; ASTRA tests the related decision rather than complete operational practice.
AdvisorAdvisor D5.6Relationship: Supporting
Given a scenario, sequence reversible pilot gates and the earliest evidence-backed next action.
Requiring candidates to sequence reversible pilot gates and the earliest evidence-backed next action supports ESCO skill "perform project management"; ASTRA tests the related decision rather than complete operational practice.
AdvisorAdvisor D6.2Relationship: Supporting
Given a scenario, prepare a conditional deployment handover with monitoring and reversal gates.
Requiring candidates to prepare a conditional deployment handover with monitoring and reversal gates supports ESCO skill "perform project management"; ASTRA tests the related decision rather than complete operational practice.
Given a scenario, calculate and order dependent testing, security and acceptance activities.
Requiring candidates to calculate and order dependent testing, security and acceptance activities supports ESCO skill "perform customers' needs analysis"; ASTRA tests the related decision rather than complete operational practice.
AdvisorAdvisor D6.4Relationship: Supporting
Given a scenario, frame a customer decision with technical, financial and governance constraints.
The requirement to frame a customer decision with technical, financial and governance constraints supports ESCO skill "perform customers' needs analysis"; ASTRA assesses the related judgement, not full operational ownership.
AdvisorAdvisor D6.5Relationship: Supporting
Given a scenario, target discovery questions to the owner and the gate each answer changes.
This objective supports ESCO skill "perform customers' needs analysis": candidates must target discovery questions to the owner and the gate each answer changes; broader operational ownership is not assessed.
Given a scenario, define a partner motion while preserving the customer and supplier boundaries.
This objective supports ESCO occupation "ICT business development manager": candidates must define a partner motion while preserving the customer and supplier boundaries, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D7.2Relationship: Supporting
Given a scenario, apply deal-registration and conflict evidence before allocating attribution.
Requiring candidates to apply deal-registration and conflict evidence before allocating attribution supports ESCO occupation "ICT business development manager"; ASTRA tests the related decision rather than complete operational practice.
AdvisorAdvisor D7.3Relationship: Supporting
Given a scenario, distinguish sourced, influenced and disputed co-sell evidence.
The requirement to distinguish sourced, influenced and disputed co-sell evidence supports ESCO occupation "ICT business development manager"; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, prepare a governed channel handover with economics, owners, gaps and expiry.
This objective supports ESCO skill "manage ICT project": candidates must prepare a governed channel handover with economics, owners, gaps and expiry, using related judgement within ASTRA's commercial scope.
AdvisorAdvisor D8.5Relationship: Supporting
Given a scenario, assign business, data, model and execution approval decisions to the correct owners.
The requirement to assign business, data, model and execution approval decisions to the correct owners supports ESCO skill "manage ICT project"; ASTRA assesses the related judgement, not full operational ownership.
AdvisorAdvisor D8.6Relationship: Supporting
Given a scenario, sequence the review, version binding and release checks for a consequential action.
This objective supports ESCO skill "manage ICT project": candidates must sequence the review, version binding and release checks for a consequential action; broader operational ownership is not assessed.
Given a scenario, link budget, admission and approval controls to cost and service continuity.
This objective supports ESCO skill "conduct impact evaluation of ICT processes on business": candidates must link budget and approval controls to cost and continuity; broader operational ownership is not assessed.
Given a scenario, distinguish authentication from permission for a named operation.
This objective supports ESCO skill "manage digital identity": candidates must distinguish authentication from permission for a named operation, using related judgement within ASTRA's commercial scope.
AssociateAssociate D3.2Relationship: Partial
Given a scenario, evaluate who is included in an identity-control test and identify coverage exceptions.
This objective partially overlaps ESCO skill "manage digital identity" through the need to identify identity-control test coverage and exceptions, while broader operational practice remains outside ASTRA.
Given a scenario, separate product entitlement from managed-service responsibilities, service hours, response commitments and customer-retained duties.
The requirement to separate product entitlement from service responsibilities, hours, commitments, and retained duties supports ESCO occupation "ICT account manager"; ASTRA assesses the related judgement, not full operational ownership.
Given a scenario, prepare a renewal commercial view that separates price movement, protected-population change, service-scope change and evidence of security outcome.
The requirement to separate renewal price, protected population, service scope, and outcome evidence supports ESCO occupation "ICT account manager"; ASTRA assesses the related judgement, not full operational ownership.
Attribution and reuse+
Classification used: ESCO v1.2.1, last updated 10 December 2025; reviewed 7 October 2026. The crosswalk uses selected ESCO occupation and skill concepts and their persistent URIs. ESCO is developed by the European Commission, which allows ESCO to be linked with other classifications for mapping purposes. Under Commission Decision 2011/833/EU the classification may be reused free of charge subject to acknowledgement and clear indication of adaptations. Acknowledgement: "This publication uses the ESCO classification of the European Commission." ASTRA Ready's relationship labels and rationales are ASTRA Ready's adaptations, not statements by the European Commission, which has not approved, accredited, certified or endorsed ASTRA Ready. An ESCO occupation mapping does not mean a credential qualifies a holder for that occupation. Links: https://esco.ec.europa.eu/en/use-esco · https://eur-lex.europa.eu/eli/dec/2011/833/oj
What this page is not
Not accreditation by any framework owner.
Not an informative reference accepted by NIST.
Not a FinOps Foundation programme.
Not a NICE work-role qualification.
Not an ESCO occupational qualification.
ASTRA Ready credentials are issued by ASTRA Ready and verified at /verify.
This publication uses the ESCO classification of the European Commission. FinOps Framework by FinOps Foundation, CC BY 4.0. Based on the NIST Cybersecurity Framework (CSF) 2.0, the NIST AI Risk Management Framework 1.0 and the NICE Workforce Framework for Cybersecurity, National Institute of Standards and Technology, U.S. Department of Commerce. NIST, the FinOps Foundation and the European Commission have not reviewed, approved or endorsed ASTRA Ready.