Julia Mullaney So the way I see this, you start from the wide and then you go to specific. For example, there are a lot of KSAs. I found 16 knowledge, skills, and abilities inside of NICE that were common to every single work role. We start from the general, which might be knowledge of a threat actor or attack pattern; then you break that down into the eaches.
In your example, phishing is a problem that affects everybody. But other things like sanitizing code and preventing different injection patterns will be important for our software developers.
Looking at each, we go back to Bloom's taxonomy: how much does that person need to know? For your risk executive function, they need to know a lot: they probably need to be up at level five or six of Bloom's taxonomy. But your average user probably only needs to be at two or three. This helps us decompose it and ask what "apply" means for a particular knowledge, skill and ability. For an average user, it means "don't click a link."
And now a warning: it's easy to go crazy with any framework. I've had my own mad scientist moments, and I have to remind myself to step back and take a breath. My colleagues from my time at the Software Engineering Institute will remember my mantra that any framework has to live in the real world. A framework can be academically elegant but if it doesn't solve a human problem, it's not going to help.