Showing posts with label IFIP. Show all posts
Showing posts with label IFIP. Show all posts

Friday, September 15, 2017

Draft Cybersecurity Curricula from IFIP, ACM, IEEE-CS AIS SIGSEC

A 74 page Draft Cybersecurity Curricula 2017, Version 0.75  is available (12 June 2017) from the Joint Task Force on Cybersecurity Education (JTF). The task force has representation from the IFIP Technical Committee on Information Security Education (IFIP WG 11.8), as well as ACM, IEEE Computer Society and AIS SIGSEC. A final curricula recommendation is due in December. It is not clear how the curricula relates to the cyber-security certifications recently announced by ACS and IFIP.

The 12 June draft of the task force divides the Curricular Content into six "Knowledge Areas":
  1. Data Security
  2. Software Security 
  3. System Security 
  4. Human Security 
  5. Organizational Security 
  6. Societal Security
Recommended study hours per knowledge area have not yet been specified.

The report contains a curious section 5.1 on "The Academic Myth" (page 58):
"Students who graduate from a four-year university program assume that the baccalaureate degree is a sufficient qualification to attain a position. This understanding may be true in some fields, but not necessarily in the computing disciplines nor specifically in cybersecurity. Belief in this myth has stymied many a job hunter worldwide. The degree credential is growing in importance, but it is not a sufficient condition for a position. A general understanding exists in cybersecurity and other fields that a successful professional must be a good communicator, a strong team player, and a person with passion to succeed. Hence, having a degree is not sufficient to secure employment."
The report goes on in the next section to detail Non-technical Skills (Section 5.2, Page 58):
"Non-technical (sometimes called “soft”) skills are vital to the success of cybersecurity professionals. The ability to work in a team, communicate technical topics to non-technical audiences, successfully argue for resource allocations, hone situational awareness, and operate within disparate organizational cultures are just a few of these skills. The US Chief Human Capital Officers Council (CHCO), among other bodies, has developed a list of non-technical competencies pertinent to the cybersecurity workforce. The list includes: accountability, attention to detail, resilience, conflict management, reasoning, verbal and written communication, and teamwork. The full list of competencies is available in the Competency Model for Cybersecurity. Professional associations such as (ISC) and ISACA also provide recommendations for non-technical skills required for cybersecurity professionals."
The report's authors seem to assume that that these soft skills have no place in a baccalaureate degree program. However, those are the skills I, and my colleagues, are teaching to computer science and engineering students at the Australian National University. As part of team projects and individual internships, the students have to learn to work together, communicate with a real client, negotiate for resources and present their work. Obviously, students with limited work-place experience can only learn so much and there is a continual discussion of the role of higher degrees for improving skills and smaller sub-degree courses. That approach fits with the ACS' approach to certification, which recognizes experience alongside formal qualifications.

Global CyberSecurity Certification by IFIP

The International Federation for Information Processing (IFIP) have announced a CyberSecurity Specialism as part of their International Professional Practice Partnership (IP3). This allows participating national computing bodies to issue a globally recognized certification for cyber-security practitioners. The IP3 new Specialism is based on work by the Australian Computer Society (ACS) which launched a cyber-security certification on 6 September. IP3 say the new Specialism will incorporate ISACA and ISC 2 certification.

It is not clear how the IP3 and ACS certifications will relate to the work of the Joint Task Force on Cybersecurity Education (JTF). See next post on the Task Force.

ps: The IFIP announcement was made at a conference in Colombo. A spot a can recommend. ;-)

Wednesday, February 1, 2017

Cybersecurity Degree Guidelines

The Association for Computing Machinery (ACM) have released a draft "Cybersecurity Curricula 2017: Curriculum Guidelines for Undergraduate Degree Programs in Cybersecurity" for comment by 14 February 2017. The security areas focused on are: Data, Software, System, Human, Organizational and Societal. Discipline areas ares: Computer Science (CS); Computer Engineering (CE); Software Engineering (SE); Information Technology (IT); Information Systems (IS); and Mixed Disciplinary majors (MD). This draft has not got to the point of setting hours for knowledge areas, but is a good start.

I have submitted this comment:
"The Cybersecurity Curricula is well thought out. The only surprise for me was section 5.1 "The Academic Myth" (p. 33). This polemic against the value of baccalaureate degrees and assessment standards is not appropriate. If the authors believe that a first degree does not provide the skills required for Cybersecurity, then they should be preparing a curriculum which includes a mandatory graduate component. If the authors truly believe that "... having a degree is not sufficient to secure employment.", then they should set down the curriculum for the additional non-degree training and education required.

Setting out to specify a baccalaureate curricula which does not meet the required need seems a pointless activity. In my view a baccalaureate degree is a vocationally useful qualification. However, no single qualification will provide everything everyone needs. The authors of the Cybersecurity Curricula should not set themselves an impossible task. Such a curricula will be useful when designing educational programs, at the sub-degree, degree and also graduate levels. I suggest deleting section  5.1."