Cybersecurity 2017
Version 1.0 Report
CSEC2017
31 December 2017
5
Table of Contents
Chapter 1: Introduction
to Cybersecurity Education
9
1.1 The Joint Task Force
9
1.1.1 The Vision
10
1.1.2 The Mission
10
1.1.3 The Goals
11
1.2 The Audience
11
1.3 Sources
12
1.4
Global Community Engagement
12
1.4.1 International Workshops
13
1.4.2 Global Stakeholder Survey
13
1.4.3 Contributor Acknowledgement
14
1.5 Cybersecurity as a Discipline
14
1.6 Report Structure
15
Chapter 2: The Cybersecurity Discipline
16
2.1 The Rise of Cyberthreats
16
2.2 The Emergence of Cybersecurity as a Discipline
17
2.3 Characteristics of a Cybersecurity Program
18
Chapter 3: Cybersecurity Curricular Framework
19
3.1
Philosophy and Approach
19
3.2 Thought Model
19
3.2.1 Knowledge Areas
20
3.2.2 Crosscutting Concepts
21
3.2.3 Disciplinary Lens
22
Chapter 4: Content of the Cybersecurity Curricular Framework
23
4.1 Knowledge Area: Data
Security
24
4.1.1
Knowledge Units and Topics
24
4.1.2 Essentials and Learning Outcomes
30
4.2 Knowledge Area: Software Security
31
4.2.1 Knowledge Units and Topics
31
4.2.2 Essentials and Learning Outcomes
36
4.3 Knowledge Area: Component Security
37
4.3.1 Knowledge Units and Topics
37
4.3.2 Essentials and Learning Outcomes
39
Cybersecurity 2017
Version 1.0 Report
CSEC2017
31 December 2017
6
4.4 Knowledge Area: Connection Security
40
4.4.1 Knowledge Units and Topics
40
4.4.2 Essentials and Learning Outcomes
46
4.5 Knowledge Area: System Security
47
4.5.1 Knowledge Units and Topics
47
4.5.2 Essentials and Learning Outcomes
51
4.6 Knowledge Area: Human Security
52
4.6.1 Knowledge Units and Topics
52
4.6.2 Essentials and Learning Outcomes
58
4.7 Knowledge Area: Organizational Security
59
4.7.1 Knowledge Units and Topics
59
4.7.2 Essentials and Learning Outcomes
69
4.8 Knowledge Area: Societal Security
70
4.8.1 Knowledge Units and Topics
70
4.8.2 Essentials and Learning Outcomes
76
Chapter 5: Industry Perspectives on Cybersecurity
78
5.1 The Technical – Business Skills Continuum
78
5.2 Career Focus
79
5.3 Linking Cybersecurity Curriculum to Professional Practice
80
5.3.1 Application Areas
80
5.3.2 Training and Certifications
82
5.4 Workforce Frameworks
82
5.4.1 NCWF Implementation Roadmaps
82
5.4.2
Overview
84
5.4.3 Relevant Courses
84
5.4.4 KSA Acquisition Strategies
84
5.4.5 Challenges
85
References
86
Appendix A: Contributors
89
The Global Advisory Board To the Joint Task Force on Cybersecurity Education
89
The Industrial Advisory Board To the Joint Task Force on Cybersecurity Education 91
Knowledge Area Working Groups
93
Knowledge Area: Data Security
93
Knowledge Area: Software Security
94
Cybersecurity 2017
Version 1.0 Report
CSEC2017
31 December 2017
7
Knowledge Area: Component Security
95
Knowledge Area: Connection Security
96
Knowledge Area: System Security
97
Knowledge Area: Human Security
98
Knowledge Area: Organizational Security
99
Knowledge Area: Societal Security
100
Contributing Reviewers
101
Appendix B: Essentials Table Overview
111
Appendix C: Exemplars
112
Curricular
Exemplar Template
112
Workforce Exemplar Template
116
Course Exemplar Template
118