This chapter discusses in detail the topic of technical cybersecurity training. First, we define a taxonomy of cybersecurity training programs that is based on several characteristics, such as training purpose, training approach, as well as other features of the training. This underlines the complex dependencies that exist between the training method, the target skills, training scenario, and environment types. We also discuss several frameworks in relation with cybersecurity workforce skills, such as the NICE Framework. Then, the effectiveness of training programs is analyzed by formulating a set of requirements for ensuring the effectiveness of a program, and discussing how these requirements can be mapped into actual training platform implementation features. Lastly, Hardening Project is presented, which is a competition with many benefits in terms of training approach that, for example, makes it possible to address all types of cybersecurity skills. This discussion also represents a case study of applying the taxonomy we introduced to an actual training program, thus illustrating how this taxonomy can be used in practice.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Technical Cybersecurity Training

  • Razvan Beuran

摘要

This chapter discusses in detail the topic of technical cybersecurity training. First, we define a taxonomy of cybersecurity training programs that is based on several characteristics, such as training purpose, training approach, as well as other features of the training. This underlines the complex dependencies that exist between the training method, the target skills, training scenario, and environment types. We also discuss several frameworks in relation with cybersecurity workforce skills, such as the NICE Framework. Then, the effectiveness of training programs is analyzed by formulating a set of requirements for ensuring the effectiveness of a program, and discussing how these requirements can be mapped into actual training platform implementation features. Lastly, Hardening Project is presented, which is a competition with many benefits in terms of training approach that, for example, makes it possible to address all types of cybersecurity skills. This discussion also represents a case study of applying the taxonomy we introduced to an actual training program, thus illustrating how this taxonomy can be used in practice.