Technology for Assessing the Readiness of Information Security Specialists in the System of Continuing Education Using Game Approaches
摘要
The relevance of high-quality training of information security specialists is currently growing due to an acute shortage of qualified personnel. Existing models for the implementation of education in the field of information security often provide a traditional solution to the task at hand, and cannot provide a comprehensive solution to the root causes of the shortage of professional skills. Gamification as an education tool aims to increase the efficiency of interaction between the region’s education system and employers in the modern labor market in the field of information security. The article provides a justification for the implementation of gamification in accordance with the requirements for the implementation of the main professional educational programs of higher education. It is justified that gamification is compatible with the educational process of the university and can be implemented in the cycle of continuing education. The experiment consisted of participants were offered part of the virtual infrastructure of the enterprise, on which a real vector of attack on the supply chain was simulated with the preliminary compromise of the source code storage using a known vulnerability (CVE). The result of the stage is a list of commands executed by the attacker, determination of the attacker’s tactics and techniques (according to MITRE ATT&CK), determination of the key reason for the success of actions.