Framework, Tools and Good Practices For Cybersecurity Curricula
Framework, Tools and Good Practices For Cybersecurity Curricula
Received June 2, 2021, accepted June 28, 2021, date of publication July 1, 2021, date of current version July 9, 2021.
Digital Object Identifier 10.1109/ACCESS.2021.3093952
ABSTRACT Cybersecurity education and training are essential prerequisites of achieving a secure and
privacy-friendly digital environment. Both professionals and the general public widely acknowledge the
need for high-quality university education programs and professional training courses. However, guides,
recommendations, practical tools, and good examples that could help institutions design appropriate cyber-
security programs are still missing. In particular, a comprehensive method to identify skills needed by
cybersecurity work roles offered on the job market is missing. This paper aims to provide practical tools
and strategies to help higher education providers design good cybersecurity curricula. First, we analyze the
content of 89 existing study programs worldwide, collect recommendations of renowned institutions within
and outside the EU, and provide a comprehensive survey accompanied by a dynamic web application called
Education Map. Based on the knowledge about the current state in cybersecurity education, we design the
SPARTA Cybersecurity Skills Framework that provides the currently missing link between work roles and
required expertise and shows how to develop a curriculum that reflects job market requirements. Finally,
we provide a practical tool that implements the framework and helps education and training providers design
new study programs and analyze existing ones by considering the requirements of cybersecurity work roles.
INDEX TERMS Cybersecurity education, cybersecurity skills framework, higher-education map, curricula
design, study programs.
This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see [Link]
VOLUME 9, 2021 94723
J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula
Through it, we make it possible for different universities and II. RELATED WORK
training institutions to define their study programs according The purpose of this section is to provide the initial mapping
to their needs and capabilities. Our idea is that by using of the existing curricular recommendations from renowned
the same framework, the universities will share the same institutions dealing with cybersecurity training and educa-
taxonomy of courses and the common procedure for selecting tion. The analysis serves as the input to the further activities,
Knowledge, Skills and Abilities (KSA) required for partic- in particular to the design of our curricula design method-
ular work roles, i.e., positions on the job market, at which ology and good-practice curricula. By reviewing the current
graduates are aiming. recommendations, we also aim to grasp how primary sub-
We further support our methodology by proposing a web jects (e.g. mathematics) can be linked to the KSAs expected
application, called Curricula Designer, to assist with the by the practitioners in the field of cybersecurity, as skills
creation of study programs (Section V-C). Its main feature frameworks usually are not reflecting fundamental subjects.
is to simplify the design of a study program composed Nowadays, new cybersecurity courses are developed by
of courses that match particular cybersecurity work roles academics in response to real world needs both in the public
requirements. and private sectors. However, there is no consolidated com-
By providing a unified approach for designing the curric- mon approach to define the requirements of a cybersecurity
ula, showing the good-practice curricula and developing a curriculum, in particular, which skills need to be taught and
practical software tool usable for curricula design, we hope which areas of expertise need to be covered. For this rea-
to boost new cybersecurity study programs at universities and son, many academics, computing societies, and governmental
training institutions while emphasizing the interdisciplinary organizations have proposed educational frameworks that
nature of cybersecurity. Furthermore, we hope that the new include recommendations, guidelines, and practices to drive
programs will be designed according to specific rules and the creation of new cybersecurity curricula. These frame-
standardized approaches reflecting the actual requirements of works help curriculum designers to understand the require-
particular cybersecurity positions. ments of cybersecurity disciplines and to define topics and
themes that are considered fundamental. Although signifi-
cant differences arise among these frameworks, they seem
A. OUR CONTRIBUTION to agree on the fundamental cybersecurity topics. Especially,
Our contribution is threefold. Firstly, this article revises the the common aspect is that they identify ‘‘interdisciplinarity’’
existing curricular recommendations from renowned insti- as the key term in determining the best security program:
tutions dealing with cybersecurity training and education. cybersecurity courses of study should offer classes in differ-
Secondly, using the SPARTA Cybersecurity Skills Frame- ent areas of computer science, engineering, management and
work (CSF) we have linked the cybersecurity skills to work law. Figure 1, taken from CyBOK [25], summarizes the areas
roles recognized on a job market. The established links enable of interest of the cybersecurity field and highlights orthog-
us to analyze a sample of 89 study programs and provide onality of different areas and multi-disciplinarity. However,
an overview of the current cybersecurity education status. the emphasis given to each topic varies among the various
Finally, our analyses are an instrument and a stimulus for educational frameworks.
designing higher-education study programs in cybersecurity In this section we provide a short survey of those
through a cybersecurity curricula designer tool. framewroks we consider the most relevant proposals and
Moreover, the collected data are visualized in a dynamic recommendations for establishing security courses of study.
web application to help students search for a cybersecurity
study program. A. JOINT TASK FORCE GUIDELINE
The rest of the paper is organized as follows. Section II At the end of 2017, the first set of global curricular
reviews related work on cybersecurity education. Section III recommendations in cybersecurity education has been
summarizes the cybersecurity skills framework used to define released by the Joint Task Force on Cybersecurity Education
good-practice cybersecurity curricula. Section IV provides (CSEC2017 JTF).
the analysis of existing cybersecurity Bachelor’s and Master’s This task force is an outcome of The Cyber Education
study programs. Section V shows the methodology for creat- Project (CEP) [11],1 an initiative supported by academic
ing novel curricula, the good-practice curricula, and the web institutions, governments and industries in the USA, to (1)
application for designing cybersecurity curricula. The final develop undergraduate curriculum guidelines for educational
section contains our conclusions. programs in the Cyber Sciences, and (2) establish a case for
This article summarizes and builds upon the results the accreditation of educational programs. The term Cyber
of research activities conducted within the SPARTA Sciences refers to all disciplines that involve technology,
project [31]. Extended description of the methods and tools people, and processes to enable assured operation in the
presented in this paper, in particular the SPARTA Cyberse- presence of risks and adversaries.
curity Skills Framework and Good-Practice Cybersecurity
Curricula, is available in our technical reports on SPARTA 1 Currently, the access to [Link] seems to
CSF [27] and Curricula Descriptions [28]. be limited to USA’s IPs only.
define these topics but they specify only that they should For each pathway, NCSC indicates the topics that the syl-
be compatible with Core Body Of Knowledge (CBoK) for labus is expected to cover; the number of credits in Higher
ICT professionals [2]. The CBoK describes the essential Education Credit Framework for England (HEI) reserved for
ICT knowledge required for any ICT professional and it is each specific topic; and the skills that students are expected
structured in knowledge areas that include: to master when they finish their studies. The topics include
1) ICT Professional Knowledge (ethics, professional basics of computer science and foundations of cybersecurity.
expectations, teamwork concepts and issues, inter- The certification prescribes the skills that students should
personal communication, societal issues/legal issues/ have upon graduation, thus, it defines the learning outcomes
privacy and understanding the ICT profession); of a certified Bachelor’s degree. In particular, students must
2) ICT Problem Solving; Technology Resources be able to:
• demonstrate a sound understanding of the main areas
(hardware and software fundamentals, data and
of knowledge in cybersecurity and to exercise critical
information management, networking); Technology
Building (human factors, programming, systems judgment;
• critically analyze and apply essential concepts to
development, systems acquisition);
3) ICT Management (IT governance and organizational defined scenarios, selecting and using effective tools and
issues, service and project management, security techniques;
• analyze, design and develop a system, showing problem
management).
solving and evaluation skills; demonstrate generic skills
The ACS proposes two kinds of accreditations: Profes- about work organization as an individual and as a team
sional Specialist Accreditation in Cyber Security (PSACS) member and with minimum guidance;
and Advanced Professional Specialist Accreditation in Cyber • apply appropriate practices within a professional, legal
Security (APSACS). and ethical framework; identify mechanisms for contin-
• Degree programs that aim at PSACS must identify a spe- uing professional development and lifelong learning;
cific Cyber Security professional role they want to train • be creative and innovative in their application of the
for. Then, they need to address SFIA skills at level 3 by principles covered in the curriculum;
focusing on those that are specific for the professional • be able to exercise critical evaluation and review of both
role they identified; finally, the course of study must con- their own work and the work of others.
tain at least 8 subjects drawn from an appropriate Cyber Universities that want to certify their Bachelor’s degrees
Security body of knowledge compatible with CBoK. should select one of the available pathways to apply.
• Degree programs that aim at APSACS must first identify Depending on the pathway NCSC defines specific subjects
a specific Cyber Security professional role they want to areas that degrees should fully or partially cover.
train for. Then, they need to address SFIA skills at level For Pathway A, the syllabus of a candidate degree must
5 by focusing on the skills required for the identified provide from total 360 credits a minimum of 270 HCI
role. Finally, the course of study must contain at least (Human Computer Interface) credits in computer science,
8 subjects drawn from an appropriate Cyber Security where at least 240 can be mapped to specific topics detailed
body of knowledge compatible with CBoK. below. For Pathways B and C, a candidate degree must have
a minimum of 160 HCI credits in computer science, where at
least 135 must cover specific topics detailed below.
C. UK CYBERSECURITY CENTRE GUIDELINE
In particular, each pathway requires that candidates
The UK government has established the National Cyberse- degrees meet the following specific constraints:
curity Centre (NCSC) [30]. The NCSC understands cyber-
• For pathway A, a Bachelor’s degree must cover in
security, and distils its knowledge into practical guidance; it
good breadth and depth topics from basics of computer
uses industry and academic expertise to secure public and
science, like software engineering and system funda-
private sectors. It also certifies bachelor and master degrees in
mentals. It must also cover fundamental concepts of
cybersecurity and closely related fields. Although it does not security, as well as more advanced security topics like
explicitly provide an official educational framework, require- low level techniques and tools, and secure programming.
ments can be implicitly interpreted as guidelines for defining
Moreover, students must undertake an individual
high-level curricula in cybersecurity.
project and a dissertation relevant to cybersecurity for
At the bachelor’s level, NCSC provides three types of
20/40 credits.
certification (called pathways) for ‘‘Bachelor’s degrees with
• For pathway B, a Bachelor’s degree is required to
Honours in Computer Science’’ [19] that: have a minimum of 90 credits on topics related to
1) address underpinning computer science topics relevant cybersecurity, not necessarily specific for computer sci-
to cybersecurity (pathway A), ence, like information security management, informa-
2) provide a general, broad foundation in cybersecurity tion assurance methodologies and incident management.
(pathway B), Furthermore, topics related to computer science must
3) provide a foundation in Digital Forensics (pathway C). be covered in good breadth and depth. These topics
include software engineering, computer networks and include knowledge units that cover a specific quantity of
operating systems. Finally, students must undertake an mandatory academic content, like low level programming
individual project and a dissertation on a topic relevant languages, operating systems, etc., and a minimum of 10 of
to cybersecurity for 20 and 40 credits. the 17 optional academic content, e.g., wireless security.
• Pathway C is about Digital Forensics. A Bachelor’s
degree to be accredited must must provide 90 HCI E. NATIONAL INITIATIVE FOR CYBERSECURITY
credits in topics related to digital forensics. These top- EDUCATION (NICE)
ics must include the theoretical fundamentals of digital The National Initiative for Cybersecurity Education (NICE)
forensics with its applications and tools ( covered in is a U.S. partnership between government, academia and
good breadth and depth), information security, and all private sector led by the National Institute of Standards
the aspects relevant to the legal process. Furthermore, and Technology (NIST). Its main goal is to support U.S.
it has to cover also topics related to computer science, cybersecurity training and education providers through the
like software engineering, computer networks and oper- introduction of new standards and best practices. Besides
ating systems. Finally, students must undertake an indi- other documents, NICE created the NICE Framework that has
vidual project and a dissertation on a topic related to been already standardized as the NIST Special Publication
digital forensics. 800-181 revision 1, the Workforce Framework for Cyber-
security (NICE Framework) [20]. The NICE Framework
D. USA NATIONAL CENTERS OF ACADEMIC EXCELLENCE provides detailed description of main building blocks, i.e.
The National Security Agency (NSA) and Department of Knowledge, Skills and Tasks of cybersecurity Work Roles.
Homeland Security (DHS) support cybersecurity education Using the NICE Framework, it is possible to easily identify
in colleges and universities via an accreditation program, what knowledge and skills are required by particular work
called the National Centers of Academic Excellence (CAE) roles available on the cybersecurity job market. Besides the
in Cyber Defense [24]. Actually, they sponsor two types of standard, NICE initiative also published a supplemental doc-
CAE: one in Cyber Defense (CAE-CD) and one in Cyber ument called Reference Spreadsheet [21] that covers the
Operations (CAE-CO). These accreditation programs (called mapping between Work Roles and Tasks, Knowledge and
designations in the following and in the official documents) Skills.
ensure that an appropriate cybersecurity curriculum is avail-
able within the institution. The requirements that institutions F. THE CYBER SECURITY BODY OF KNOWLEDGE
and study plans need to meet can also be interpreted as The CyBOK [25] is a project funded by the National Cyber
guidelines and best practices to define a high-level curriculum Security Program and led by the University of Bristol whose
in cybersecurity. goal is to codify the foundational and generally recognized
The CAE-CD program comprises two designations: CAE knowledge on cybersecurity. The problem the project is try-
in Cyber Defense Education (CAE-CDE) for Associate, ing to address is the fragmented and incoherent founda-
Bachelor, Masters and Doctoral Programs; CAE in Cyber tional knowledge for the cybersecurity field. It takes inspira-
Defense Research (CAE-R) for those institutions that do tion from mature scientific disciplines, such as mathematics,
research in cybersecurity. All regionally accredited two-year, physics, chemistry, and biology that have long-established
four-year, and graduate level institutions in the US can apply foundational knowledge and clear learning steps from sec-
to become a CAE-CD school and receive the designation if ondary school to undergraduate degrees at university, and
they meet specific criteria. Since we are interested in edu- beyond. Its long-term goal is to be a guide to the body of
cational guidelines, we omit any discussion about CAE-R. knowledge and to work as the basis on which educational pro-
For the designation of Bachelor, Master, and Doctoral, appli- grams, ranging from secondary and undergraduate education
cants must be a regionally accredited four-year college or to postgraduate can then be developed.
graduate-level university. Besides an evaluation concern- The knowledge that it codifies already exists in litera-
ing organizational aspects (see CAE-CDE Criteria [22]), ture such as textbooks, academic research articles, technical
it is required that institution’s curricula adhere to CAE-CD reports, white papers and standards. The focus is, therefore,
Knowledge Units. These Knowledge Units describe the top- on mapping established knowledge and not fully replicating
ics to be covered and the goals they have to achieve. In partic- everything that has ever been written on the subject.
ular, the program must be mapped to the Foundational, Core The CyBOK project managed to identify 19 Knowledge
and selected Optional KUs. Areas (KAs) and to organize them into coherent framework.
The CAE-CO program is a technical education program The KAs are not orthogonal, indeed there are a number of
firmly grounded in computer science, computer engineer- dependencies across them. Moreover, they are grouped into
ing, and/or electrical engineering disciplines. It complements five broad categories, as summarized visually in Figure 1.
CAE-CD, putting specific emphasis on technologies and These five categories are:
techniques. Programs must meet a set of academic require- 1) Software and Platform Security;
ments and programmatic criteria which measure the depth 2) Systems Security;
and maturity of the programs. A CAE-CO program must 3) Attacks and Defences;
components of the NICE Framework. There are four providers to review their curricula in a structured and
Competence Groups: systematic manner. They have a recognized framework
• Technical Competence Group - compiles the instru- to be used as the main benchmark instrument.
mental KSAs and covers the ‘‘what is to be done’’ aspect • Improve - can be done based on the evaluation exercise.
within the Framework; This is especially important considering the emerging
• Operational Competence Group - compiling KSAs needs of practitioners. The Framework is able to transmit
from other critical areas, defining ‘‘how activities should arising requests at an early stage, providing Academia
be done’’; with the foresight to improve and develop their curricula
• Professional Competence Group - compiling expected further.
‘‘soft skills’’; • Focus - education provided by universities may dif-
• Leadership Competence Group - compiling KSAs fer in the way they address core competencies. Some
needed for the managerial part of the organization. might be more focused on specific technological sub-
Each Competence Group is associated with a Competence jects, some on law, others on forensics, etc. Having an
Level, providing a direct link to the KSAs. In this way, integrated Framework to work with, they can map their
competencies can also be linked to other components of core competencies onto various subject areas, important
the Framework structure. Table 1 shows the list of NICE for defined roles. This enables the institution to develop
competencies divided according to the group they belong to. more effective targeted programs in house around the
Clearly, technical competencies are dominating, being main competencies.
cybersecurity a highly technical field. At this point it is important to describe the Framework and
Possible applicability of SPARTA CSF for Academia is its relationship to professional training and education.
described fully in D9.1 Chapter 6.2 Use of the Framework Professional training providers can use the Framework
[27]. Here, we provide the main activities to be executed: directly, as they are aware of the KSAs required by prac-
• Evaluate - the right granularity of requested knowl- titioners and how those are interlinked with the work roles
edge/skills/abilities allows education and training performed.
Links with Education are less obvious, as the Framework 3) New trends are identified. Some of the Educational
describes KSAs requested within a context of associated subjects might be based on specific technologies like,
activities, but it does not provide any indication of how those e.g., quantum computing ones. However, SPARTA CSF
links can be established. Education institutions compose their does not specify any particular technology, which may
curricula considering the complete path – they start with the be listed in a format of explanation of KSAs in some
fundamental capabilities that are required for the individual cases only, or may be described in the New Trends
to learn as a basis for the next set of follow-on subjects. This category.
is reflected in the SPARTA Topics (see Fig. 2) proposed as the We now provide an example of SPARTA Topics and
result of the analysis of current Education programs. SPARTA SPARTA CSF mapping, followed by some insights for the
Topics include all subjects required to get individuals ready development of curricula. The mapping is obtained by the
to enter the professional workforce, including fundamental three steps described below.
Topics, cyber security Topics and technology-related Topics.
Distribution of subjects within specific categories is obtained
through the following steps: A. STEP 1: DIVISION OF TOPICS
1) All subjects are classified as belonging to either Fun- All Topics are divided into three groups: Fundamental, Cyber
damental, Cyber Security or New Trends categories. Security and New Trends, see Figure 2.
Fundamental subjects are those not directly linked to As mentioned, Fundamental Topics do not have a direct
the Framework, but which serve as a prerequisite for link with SPARTA CSF competencies, but they serve as a nec-
further studies. Some Fundamentals can have a link essary prerequisite for other Topics. Some of the Fundamen-
to the competence block, but thereby only depict the tal subjects have links to NICE competencies (demonstrated
relevant link to further studies. For example, Funda- by dashed arrows in Figure 3), aiming to show further links,
mental Cryptology is the prerequisite for Cryptanalysis and areas for additional focus.
or Advanced Cryptology; Number Theory is necessary While developing the curricula, insights on what the Fun-
for most intermediate and advanced computer related damental subject should include to serve as a solid back-
subjects. ground for further studies content should also be provided.
2) The identified Cyber Security specific subjects are
linked to the competencies of the Framework according B. STEP 2: MAPPING OF SPARTA TOPICS TO
to the content of the individual subjects. This map- SPARTA CSF COMPETENCIES
ping reveals the exact competencies to be stressed or As cybersecurity is mainly considered as a technical disci-
considered. Since competencies are linked to KSAs pline (this is also demonstrated by the SPARTA CSF compe-
within the Framework, it is possible to obtain a detailed tence structure), the mapping is made using only Technical
list of KSAs expected by practitioners. In this way, and Operational Competencies (provided in Table 1). Pro-
the Framework helps to structure the topic for a better fessional and Leadership Competence groups are outside the
fit to the expected activities. domain of current SPARTA Topics and refer more properly to
FIGURE 3. Links between SPARTA topics and SPARTA CSF technical and operational competencies.
teaching methods, and additional modules offered to cyberse- Using the link in Figure 3 between Topics and com-
curity students. petencies (and thus between Topics and KSAs and work
Figure 3 provides an overall mapping of what SPARTA roles), we are now able to analyze the existing study pro-
CSF competencies should be included in SPARTA Topics. grams (Section IV) and propose new good-practice curricula
(The Topics that have no links are considered Fundamental (Section V).
or New Trends.) Each Topic in Figure 3 can be linked to a
KSA in the SPARTA CSF. This is illustrated by an example: IV. MAPPING HIGHER EDUCATION PROGRAMS
IN CYBERSECURITY
• SPARTA Topic - Probability and Statistics
Many cybersecurity study programs are nowadays offered
• Linked with CSF competence - Modeling and Simula-
around the world. Depending on the expertise of the man-
tion and Data Analysis
aging group and country environment, the curricula can be
The NICE list of KSAs gives a very detailed and extensive substantially different.
listing of expected outcomes. It clearly shows how this can In this section, we summarize data which cover
guide the development of general and topic specific curricula. 89 higher-education cybersecurity curricula (19 bachelors
In addition, links to roles and other components of the and 70 masters) spread over 19 countries, 5 of which are
Framework can be determined, if needed. non-European. These data are used to produce an educational
world map which is presented in Section IV-C.
C. STEP 3: NEW TRENDS
Quantum computing and Post-quantum cryptography are A. METHODOLOGY
topics not directly reflected in the Framework, as they are We start with a brief summary on how the data were collected.
technology specific. Integration of emerging KSAs into the Three documents were produced in order to simplify the
Framework is in progress and will be described separately. review:
FIGURE 4. First analysis template Excel file for the ‘‘Master in Mathematics of Cybersecurity’’ study program, Bristol University,
United Kingdom.
TABLE 3. Study programs features: language, ECTS credits and cost in Europe.
‘‘cryptography’’, ‘‘cryptology’’ or ‘‘privacy’’ words. Then, Denmark and Norway, passes to countries that charge for a
if more than 6 curricula appeared in the search, universities symbolic payment (mostly for the enrollment) as Germany,
were sorted using the Times Higher Education World Uni- and finishes with countries, like the United Kingdom, where
versity Rankings [29] and the first 6 higher ranked where a 2-year master can cost as much as 33,300 Euro.
considered. Assuming that the country’s leading universities
are more likely to represent the best proposals.
This collection was meant to produce a representative sam- 2) EUROPEAN LECTURES ANALYSES
ple of the current university offers in cybersecurity. For the Here, we show the results of the statistical analyses we
sake of time and resources, covering all existing curricula was performed on the collected subjects of European study pro-
not feasible. grams. Among the 6 considered European countries, only
14 curricula passed the criteria for being used in the statistical
analyses. Moreover, 11 analyzed countries have a master
1) EU COUNTRIES curricula and only 44 curricula are eligible for statistical
In the following, we summarize the results of the collected analyses (the total number of curricula can be found in Table 9
data over 61 European cybersecurity curricula. In particular, in Appendix A).
15 bachelors and 46 masters curricula were meeting the con- Indeed, in order to be used in analyses, a curriculum must
strains identified in Section IV-A. A list of the study programs offer compulsory subjects and must not be too general.
split by country can be found in Table 9 in Appendix A. For each study program, the total percentages computed
These study programs are spread over 14 European coun- in ‘‘first analysis template’’ document are considered (see
tries and run by 38 different universities. Table 2 counts Section IV-A for more details). These percentages give an
which faculties/departments/schools are mainly involved in idea of how the mandatory subjects are divided among the
teaching cybersecurity. Some curricula are jointly taught by identified cybersecurity areas, which are computer science,
different entities in the same university, therefore, the total cryptography, humanistic and social science, mathematics,
number of providers is not proportional to the number of privacy, and security.
involved universities. The focus is on mandatory subjects since these are the
Table 3 shows the number of study programs in English, ones considered of main importance for a cybersecurity study
their ECTS credits and their average cost. Bachelor curricula program. In fact, depending on the department (or faculty) the
are taught in the native language of the country, in fact the offer of elective subjects (when present) can be really differ-
2 bachelors in English are taught in the United Kingdom. ent and makes the curriculum more specialized in the areas
Masters are split according to their duration: 1 and 2 years. of interest of the hosting department. Accordingly, since we
This differentiation is important since masters in 1 year are want to identify the basic knowledge that needs to be taught
normally thought as specialization post-master (the 2 years in a cybersecurity curriculum, this more detailed information
ones) and they are not sufficient for entering a Ph.D. study is not relevant for our preliminary study.
program. Figures 5 and 6 depicts the statistical analyses for European
In theory, the ECTS number should be 180 for bachelors, bachelor and master curricula divided by country and then
120 for 2-years masters, and 60 for 1-year masters. Germany summarized in the ‘‘Europe’’ chart. For instance, in Figure 5
has 5 bachelors of 210 ECTS, 1 2-year master of 180, and the ‘‘United Kingdom’’ chart shows the mean of the areas
1 1-year master of 90 ECTS since they last 1 semesters more percentage of the 2 bachelor curricula taught in this country,
than the usual programs. Moreover, in the United Kingdom while the ‘‘Europe’’ chart shows the mean of all the collected
all the considered 6 masters account for 90 ECTS. European bachelor study programs. These plots show how the
Regarding the cost of a study program, the range starts areas percentages change depending on the country. However,
from free of charge in countries like Czech Republic, we are mostly interested in the general behaviour which is
FIGURE 5. Analysis of European cybersecurity bachelor study programs. ‘‘Computer Sc.’’ stands for computer science area,
‘‘Crypto’’ for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for
security area, and ‘‘Privacy’’ for privacy area.
TABLE 4. Practical lectures in Europe. ‘‘NA’’ stands for not available. the last column of the table shows the average percentage
among the available data.
Practical lectures are present in all study programs and,
in fact, they are of vital importance for cybersecurity. Master
study programs have higher average of practical lectures
compared to bachelors ones.
FIGURE 6. Analysis of European cybersecurity master study programs. ‘‘Computer Sc.’’ stands for computer science area, ‘‘Crypto’’
for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for security
area, and ‘‘Privacy’’ for privacy area.
It is important to notice that the duration of the 4 bachelors USA masters is not available on their web pages and therefore
is not fixed to 3 years as in European ones. It could be they could not be classified in Tables 5 and 6.
6 months (USA), 2 years (Canada), and 4 years (Canada and The cost of a study program is really higher with respect
Japan). Moreover, 3 masters have no specified duration and to the European proposals (see Table 3 for more details).
the 2-years masters cover a duration of 16 to 24 months. In particular, we could not find free-of-charge study pro-
Table 5 shows the number of study programs in English, grams. In the bachelor average, the 6-months curriculum is
their ECTS credits and their average cost. Unluckily, not counted because the information was not available.
the information was harder to find, therefore, our collected
data has more ‘‘NA’’. For instance, since ECTS is a European 4) NON-EUROPEAN LECTURES ANALYSES
standard, this field is empty in all programs. Moreover the In the following section, we show the results of the sta-
language as well as the cost of the 3 South-Korean masters tistical analyses we carried out on the collected subjects
is not available on their web pages. Finally, the duration of 2 of non-European study programs. Among the considered
TABLE 5. Study programs features: language, ECTS credits and cost in Here, the security area is clearly considered the main basis of
non-European countries. ‘‘NA’’ stands for not available and ‘‘y.’’ for year.
The average cost is given in euro. cybersecurity bachelors, followed by computer science. Note
that in the European analyses, computer science and security
are also of main interest, see Figure 5.
Figure 6 depicts the master curricula analyses, where secu-
rity and humanities grow at the expense of mathematics and
computer science with respect to bachelors charts. The same
behaviour can be found in the European charts, see Figure 6
for more details.
TABLE 6. Non-European practical lectures. ‘‘NA’’ stands for not available. At last, Table 6 shows the percentage of mandatory prac-
tical lectures given in each study program, i.e. the columns
values ‘‘NA’’ and from ‘‘0’’ to ‘‘100’’. In particular, this
is a lower bound of the total taught practical lectures, see
Section IV-A2 for more details. In case, this information is
not available, the related study program is labeled as ‘‘NA’’.
Moreover, the last column of the table shows the average
percentage among the available data. Here the difference is
non-European countries, all curricula are eligible for statis- substantial with respect to the European proposals where
tical analyses. The methodology of the analyses is the same more importance is given to practical lectures.
as described in Section IV-A2. Therefore, percentages are
computed on mandatory subjects and are divided among the B. SUMMARY OF EXISTING PROGRAM ANALYSIS
identified cybersecurity areas, which are computer science, The collected 89 cybersecurity curricula (19 bachelors and
cryptography, humanistic and social science, mathematics, 70 masters) offer a first glimpse at the current world offer in
privacy, and security. cybersecurity education. The study shows how cybersecurity
Figures 7 and 8 depicts the statistical analyses for education is still not standardized and strictly depending
non-European bachelor and master curricula divided by coun- on countries and universities. In several cases, curricula are
try and then unified in the ‘‘Non-Europe’’ chart. These plots jointly taught by different departments/faculties which is due
show how the areas percentages change depending on the to the interdisciplinary nature of cybersecurity that requires
country. However, we are mostly interested in the general involving several areas. Therefore, interdisciplinary curricula
behaviour which is represented in ‘‘Non-Europe’’ charts. should be encouraged.
FIGURE 7. Analysis of non-European cybersecurity bachelor study programs. ‘‘Computer Sc.’’ stands for computer science
area, ‘‘Crypto’’ for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area,
‘‘Security’’ for security area, and ‘‘Privacy’’ for privacy area.
FIGURE 8. Analysis of non-European cybersecurity master study programs. ‘‘Computer Sc.’’ stands for computer science area, ‘‘Crypto’’
for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for security area, and
‘‘Privacy’’ for privacy area.
Furthermore, there is a lack of bachelor study programs subject description (when available) was analyzed to see
focused on cybersecurity. In fact, among 89 cybersecurity if a topic was at least partially covered. Table ‘‘Topics’’
curricula, only 19 bachelors had been found. In order to train in Figure 4 collects this information for one study program.
cybersecurity experts, the students should have the possibility Note that more topics can belong to the same subject.
to study cybersecurity subjects from the first year of their Checking the percentages, a bachelor should include
studies. It is important to notice that all the analyzed bachelors ‘‘Computer Networks’’, ‘‘Computer Systems’’ and ‘‘Funda-
are taught in the native language of the country, therefore, mental of Cryptography’’ topics (strongly recommended),
an internationalization of these curricula is also necessary. and also consider ‘‘Theoretical Computer Science’’,
Regarding cybersecurity areas and topics, computer sci- ‘‘Algebra and Discrete Mathematics’’ and ‘‘Probability and
ence has a primary position among the necessary basic Statistics’’ (suggested). Moreover, the first consideration of
knowledge. In particular, the analyses of European and security topics is suggested. In case of masters, recommen-
non-European bachelors lectures highlight computer science dations are more dependent on the specialization that the
topics as the main fundamental background, followed by study program follows. However, ‘‘Hardware and Software
humanistic and social science, and mathematics. Moreover, Security’’, ‘‘Network Security’’ ‘‘System Security’’ and
security is also a significant component of the training, par- ‘‘Security Management and Risk Analysis’’ are a good
ticularly in non-European curricula. In case of masters cur- starting points for a master in cybersecurity (see Table 7 for
ricula, humanistic and social science, security and cryptology additional details).
are strong components in both European and non-European Last but not least, a solid cybersecurity study program
programs. It is important to notice that privacy still remains should provide ample space for practical lectures. In fact,
an area only partially covered in most of the programs. practical lectures are already strongly present in the analyzed
No substantial difference between European and non- European curricula, where each study program has on aver-
European proposals has been encountered. Among the age 30% practical lectures for bachelors and 40% for masters.
European universities, the diversity of the curricula depends In particular, several universities (i.e. 4 over 15 bachelors and
on the leading department more than on the country itself. 9 over 23 2-year masters) have more than 75% of practical
Furthermore, Table 7 shows how much a topic is taught as lectures. Reflecting the need for practical training, we iden-
a percentage of the collected data. In this case, all (mandatory tify cyber ranges as a promising new technology which gives
and optional) subjects are considered. In particular, each students access to virtual environments where they can train.
TABLE 7. Topics analysis on all the collected curricula. ‘‘B.’’ stands for bachelor and ‘‘M.’’ stands for master.
C. EDUCATION MAP universities to adapt and build their own customized study
This subsection describes the process of creation of a programs in cybersecurity and evaluate their validity with
dynamic web application for the visualization of data describ- respect to the requirements of specific cybersecurity work
ing existing study programs focused on cybersecurity. This roles.
application was developed as a part of the existing study pro-
A. DESIGN METHODOLOGY
grams mapping activity. The web application contains the list
Design of cybersecurity curricula is strongly linked to pre-
of universities and their study programs and provides users
vious activities dealing with SPARTA CSF design and with
with the functionality for viewing, filtering using specific
work by key EU institutions, such as ENISA, European Cyber
criteria and localization of programs/universities on a map.
Security Organization (ECSO), and relies also on inputs
The web application also contains the administration part,
from other Cyber Competence Network (CCN) pilots. The
which can be used by the administrators to add and modify
methodology is depicted in Figure 10, identifying the inputs,
the records about the study programs and universities.
the main activity and the outcomes.
The web application is split into two parts: a client and a
The inputs significantly influence the design process and
server. The client is realized as a front-end Javascript appli-
are described in details. The Curricula Design task involves
cation for data view. Data are collected from the server part
the selection of the topics needed for curricula reflecting the
through the HTTP (Hypertext Transfer Protocol) requests.
actual KSA and their integration into courses to be included
Compared to only PDF reports, the interactive map
in the study programs. The outcomes are good-practice cur-
represents a more interactive and comprehensive way
ricula, i.e. the recommendation on courses to be included in
of results presentation. The app is publicly available at
the study programs and their composition into bachelor’s and
[Link] and is currently dis-
master’s degree programs.
tributed to university students, mostly Erasmus, interested
in international study programs. The home page is shown 1) DESIGN INPUTS
in Figure 9. The inputs that significantly influenced the curricula design
and selection of topics/subjects are the following:
V. METHODOLOGY AND RECOMMENDATIONS ON
CREATING CYBERSECURITY CURRICULA a: SPARTA Cybersecurity Skills Framework
In this section, we describe the methodology for design- The framework links KSA with work roles, thus defines the
ing higher-education study programs in cybersecurity, pro- necessary topics for students planning to work in the cyberse-
vide sample study programs for bachelor’s and master’s curity area. During the creation of the curricula, we used the
degree and give recommendations on creating curricula. pivot concepts of work roles, identifying the typical positions
These guidelines are aimed to support universities in creating on the job market, and competencies, grouping the KSA
their own cybersecurity study programs and serve as a good necessary for work on cybersecurity positions. Using the
practice for such activities. Furthermore, the outputs include CSF, it is possible to easily identify the KSAs necessary for
the SPARTA Curricula Designer Tool, a software that enables individual positions to be included in the study programs.
Guideline, guidelines from UK’s NCSC, CyBOK or rec- nificant role during the design of our good-practice curricula.
ommendations from computing associations (Section II). The virtualization technologies and training methods based
However, some of these recommendations are from regions on games, involving CTF, Red Blue teaming or table-top
outside EU and need at least some adaptation to the EU exercises should be considered as significant enhancements
environment (e.g., reflecting the EU ECTS system, different of existing training methods and could provide hands-on
legal environment and industry composition). experiences not only for pure technical courses but also for
courses focused, e.g., on legal or social aspects of cybersecu-
d: Related Program Analysis
rity. Another new trend in training is the use of ‘‘bug bounty’’
The analysis of related programs identified supporting tools programs, where cybersecurity trainees are motivated to find
that would make cybersecurity programs more visible, attrac- security vulnerabilities in existing software/hardware and
tive to students and that have the potential to enhance edu- thus improve their skills and knowledge about these systems.
cation and training with new activities. As examples of
emerging tools, we would like to mention the Bug Bounty g: Practical Aspects
platforms, e.g., Intigriti,2 YesWeHack,3 that may motivate
University study programs are usually not designed from
students to do practical exercises involving modern tools
scratch, they are often reusing existing study courses, build-
and technologies. Furthermore, the Massive Open Online
ing upon specific expertise of professors and utilizing par-
Courses (MOOC) can be seen as a suitable supplement to
ticular existing equipment of laboratories. Rather than com-
traditional education methods. To stimulate students and
pletely new composition of courses, the cybersecurity study
make them aware of cybersecurity study programs, compe-
programs are often created as modifications and updates of
titions should be considered, as they proved very useful in
existing study programs in computer science, electrical engi-
large-scale deployments, such as Italian [Link].4
neering, etc. While this decision is not perfect for the course
e: Recommendations from key institutions composition, we need to consider this pragmatic approach
During the curricula creation, recommendations from key EU as it has been identified during our discussion with universi-
partners, such as ENISA and ECSO, have been considered. ties, training institutions and even reviewers as the dominant
In particular, the recommendations included in the ENISA approach.
Cybersecurity Skills Development in the EU report [14] and
the outcome of ECSO Results of Simulation-based Com-
petence Development Survey [9] were considered. Namely,
we explicitly reflected the recommendations on enough cred-
its dedicated to cybersecurity courses, gamification of educa-
tion, presence of lectures from industry representatives, inter-
disciplinarity, international collaboration and prioritization of
hands-on practical training. Besides EU recommendations,
the NIST NICE initiative [20] served as an important source
of information.
f: New trends, tools and opportunities
In addition to the recommendations and the analysis of exist-
ing programs, new trends in cybersecurity and training were
also identified and reflected during the curricula design.
Modern curricula should reflect current research and
development trends in cybersecurity and integrate top-
ics such as quantum technologies, critical infrastructure
protection, IoT technologies, industrial networks, fake FIGURE 11. Cybersecurity program creation using SPARTA CSF and
news, privacy-enhancing technologies and more. We used existing courses.
the official EU’s strategic documents [5] and Horizon Using our methodology based on SPARTA CSF, it is possi-
Europe/Digital Europe program plans [6], [7] for the identi- ble to start with an incomplete backbone consisting of exist-
fication of new trends for our good-practice curricula, but this ing courses and then add new courses reflecting the needs of
task needs to be run individually for each new study program particular work roles to which the study program aims. The
at the actual time of its design. whole process of curricula creation is depicted in Figure 11
Furthermore, a successful study program must also involve and described by the following steps:
modern technologies for education and training. In particular, 1) Identification of existing courses suitable for the
considering cyber ranges for practical training played a sig- program;
2 [Link] 2) Labeling of existing study courses by SPARTA Topics;
3 [Link] 3) Creation of the backbone of the study program, i.e.
4 [Link] selection of existing courses for use;
94740 VOLUME 9, 2021
J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula
TABLE 8. Connection between ‘‘Information Security’’ bachelor study program and NICE competencies.
4) Analysis of Topics, competencies and KSAs provided Our proposal of a good-practice curricula and its analysis
by the backbone program using SPARTA CSF; are presented in several figures and tables:
5) Selection of work roles that are targeted by the study • Tables 12, 13 and 14 in Appendix B depict the cur-
program; riculum, filled with 1st , 2nd and 3rd year courses. This
6) Identification of missing Topics; curriculum has been created taking into account all the
7) Addition of new courses containing necessary Topics; factors described in Section II and including the analyses
8) Finalization and analysis of the program, identification from Section IV.
of supported work roles; • Figure 8 shows the percentage of SPARTA Topics cov-
B. GOOD-PRACTICE CURRICULA ered by the study program and their linking to NICE
In this section, the process of designing cybersecurity bache- competencies. Note that NICE competencies can be
lor’s and master’s study programs is described. This process connected to NICE work roles and vice versa. There-
leads to a dynamic application which allows any university to fore, students and universities may, for instance, know
generate a cybersecurity curriculum from scratch or from an the Topics necessary to become a ‘‘Security Archi-
existing one. tect’’. The connection between NICE competencies
The application permits to analyze and link subjects to and NICE work roles is fully described in SPARTA
cybersecurity SPARTA Topics which are identified as basic D9.1 [27].
cybersecurity knowledge, see Section IV-A for more details. As shown in Table 12, the second column of the template
Moreover, SPARTA Topics are linked to NICE competencies is filled with the desired curriculum subjects, which are five
and therefore, to NICE work roles, see Section III for more and all compulsory for the ‘‘1st year, Winter’’. Optional
details. This last feature allows curricula developers to target subjects (if any) can be listed after the mandatory ones. For
their curricula to the desired work role. instance, the ‘‘Language’’ subject is optional in the ‘‘1st year,
Our application can also be used to analyze an existing Summer’’. One or more SPARTA Topics can be assigned
study program and understand the missing cybersecurity top- to each subject. The assignment will reflect the knowledge
ics. It can thus be used as a tool to transform general study (abilities, skills) covered. The points assigned to each subject
programs into cybersecurity ones. is exactly 1 and this value can be split into several SPARTA
As shown in Section IV, there is a lack of bachelor study Topics assigning them 0.25, 0.5, 0.75 or 1. These values
programs focused on cybersecurity (only 19 bachelors over represent the subject ratio dedicated to the related SPARTA
89 analyzed cybersecurity curricula). Therefore, bachelor’s Topic. For instance, the ‘‘Mathematics 1’’ subject equally
programs are of our particular interest. covers ‘‘Algebra and Discrete Mathematics’’ and ‘‘Topology
The analyses of bachelors’ topics shows that computer and Analysis’’ Topics.
science is a fundamental component, followed by humanities, The third column in the table allows to assign the ECTS
social science, and mathematics. These areas are particularly credits to each subject. Following the European standard,
important in bachelor’s curricula since they cover the basic a bachelor study program should have 180 credits, and there-
skills necessary for the understanding of any future cyber- fore around 30 credits per semester.
security study. Accordingly, an appropriate balance between Tables 13 and 14 depict 2nd and 3rd years of our
these topics should be considered when designing a study good-practice bachelor program. In particular, Table 14 has
program. the summary of the assigned ECTS credits to each SPARTA
FIGURE 13. SPARTA topics and NICE competencies necessary to become a Database Administrator marked in blue and red. Red
competencies and topics are the ones to be added to ‘‘Information Security’’ bachelor curriculum in order to become a Database
Administrator.
Topic and according to the SPARTA Area. In particular, Note that the ECTS credits are assigned in 20% to Human-
the row ‘‘Total’’ collects the ECTS credits of each SPARTA istic and Social Science, 16% to Computer Science, and 17%
Topic and the related percentage. to Mathematics according to the suggested balance among
TABLE 10. Higher-education entities that run a study program in cybersecurity in Europe. ‘‘y.’’ stands for year.
FIGURE 14. NICE Framework showing NICE competencies and NICE work roles for Database Administrator.
Awesome Style Sheets Cascading Style Sheets (SASS CSS) Finally, in the Statistics section on the right side, the
pre-processor and NPM package manager. following information is visualized:
The left section of the tool (see Figure 12) contains the list • a pie chart with the distribution of SPARTA Areas
of courses. New courses can be added and edited here. The supported by the program,
courses are visualized as floating cards, which can be moved • a table with the percentage distribution of ECTS credits
using the mouse (‘‘drag and drop’’) to a concrete position covering particular SPARTA Topics in the program,
in the curricula in the middle section. The systems marks • a list of the work roles currently supported by the study
the areas to which the courses may be dropped. Using the program according to NICE.
information about the course, the system prevents the user
from dropping the course to a wrong semester. VI. CONCLUSION
The curricula component allows one to export user-defined In this article, we have proposed an approach to reduce the
curricula to a file that may be used in future sessions, to get gap between the supply of cybersecurity experts and the need
back to previously saved work. of industries and society. In particular, using SPARTA CSF
we have linked cybersecurity education to work roles. The Moreover, a tool for visualizing the collected data in an
mapping enables us to identify the topics that are fundamental interactive map has been developed. Our dynamic web appli-
for a cybersecurity carrier. Moreover, it permits comparing cation can help students when looking for a cybersecurity
existing study programs, improving them, and producing study program. Finally, related program analysis, SPARTA
guidelines for the creation of new cybersecurity curricula. CSF, and curricula recommendations are used to design
Indeed, a sample of 89 cybersecurity study programs was good-practice higher-education study programs in cybersecu-
analyzed in order to produce an overview of cybersecurity rity and propose a cybersecurity curricula designer tool. The
disciplines and topics. The analyses show that 23% of the tool automatically analyses curricula and discovers missing
curricula are taught jointly and involve multiple faculties. topics and/or unsupported work roles and thus helps program
This collaboration is due to the interdisciplinary nature of administrators to design study programs reflecting the cyber-
cybersecurity. Furthermore, we have argued that there is a security job market requirements.
lack of Bachelor’s study programs focused on cybersecurity In the future, we would like to continue to update the
(just 19 of the 89 courses we have considered). In order to SPARTA CSF to reflect new trends and directions in cyber-
train more cybersecurity experts, a more significant number security. A batch of new competencies will be added to
of students need to have the possibility to study cybersecurity reflect also interdisciplinary aspects. Furthermore, we plan
subjects from the first year of their careers. to extend the tools, and specifically the Curricula Designer,
to support more Cybersecurity Skills Frameworks (hopefully [18] J. Hallett, R. Larson, and A. Rashid, ‘‘Mirror, mirror, on the wall:
the EU CSF when it is ready) and to add functionality for What are we teaching them all? Characterising the focus of cyberse-
curity curricular frameworks,’’ in Proc. USENIX Workshop Adv. Secur.
professional training design. Educ., W.-C. Feng and A. L. Podhradsky, Eds., Baltimore, MD, USA:
USENIX Association, Aug. 2018, pp. 1–9. [Online]. Available: https://
[Link]/conference/ase18/presentation/hallett
APPENDIX A [19] NCSC. (2019). NCSC Degree Certification—Call for New Appli-
CURRICULA ANALYSIS cants. [Online]. Available: [Link]
See Tables 9–11 and Figure 14. degree-certification-call-new-applicants-0
[20] R. Petersen, D. Santos, M. C. Smith, K. A. Wetzel, and G. Witte.
(Nov. 2020). NIST Special Publication 800-181 Revision 1: Work-
APPENDIX B force Framework for Cybersecurity (NICE Framework). [Online]. Avail-
GOOD-PRACTICE CURRICULA able: [Link]
[Link]
See Tables 12–14. [21] NIST. (Jul. 2020). NICE Framework Supplemental Material. [Online].
Available: [Link]
framework-resource-center/nice-framework-supplemental-material
REFERENCES [22] NSA. (2019). National Centers of Academic Excellence in Cyber Defense
[1] (2017). ACM, IEEE, AIS SIGSEC & IFIP. ACM/IEEE/AIS Education Program (CAE-CDE) Criteria for Measurement Bachelor, Mas-
SIGSEC/IFIP Cybersecurity Curricular Guideline CSEC 2017. [Online]. ter, and Doctoral Level. [Online]. Available: [Link]
Available: [Link] documents/Requirements/CAE_CDE_criteria.pdf
newcover_csec2017.pdf [23] NSA. (2019). Academic Requirements for Designation as a CAE
[2] Australian Computer Society. (2015). The ACS Core Body of Knowledge in Cyber Operations Fundamental. [Online]. Available: https://
for ICT Professionals CBOK. [Online]. Available: [Link] [Link]/Resources/Students-Educators/centers-academic-
au/content/dam/acs/acs-skills/The-ACS-Core-Body-of-Knowledge-for- excellence/cae-co-fundamental/requirements/
[Link] [24] NSA. (2019). National Centers of Academic Excellence. [Online].
[3] Australian Computer Society. (Oct. 2019). ACS—The Professional Asso- Available: [Link] students-educators/centers-
ciation for Australia’s ICT Sector. [Online]. Available: [Link] academic-excellence/
[Link]/ [25] A. Rashid, H. Chivers, G. Danezis, E. L. Imperial, and A. Martin.
[4] (2017). Australian Government—Department of Education. Academic (Oct. 2019). The Cyber Security Body Of Knowledge. [Online]. Available:
Centres of Cyber Security Excellence Program Guidelines. [Online]. Avail- [Link]
able: [Link] accse_program [26] SFIA Foundation. (2018). The SFIA Framework. [Online]. Available:
_guidelines_february_2017_final.pdf [Link]
[5] ENISA. (2021). Exploring Research Directions in Cybersecurity. [Online]. [27] SPARTA. D9.1—Cybersecurity Skills Framework. Accessed: Jun. 1, 2021.
Available: [Link] [Online]. Available: [Link]
research-directions-in-cybersecurity. [Link]
[6] European Commision. (2021). Horizon Europe. [Online]. Available: [28] SPARTA. D9.2—Curricula Descriptions. Accessed: Jun. 1, 2021.
[Link] [Online]. Available: [Link]
[Link]
[7] European Commision. (2021). Digital Europe. [Online]. Available: https:
[29] (2020). The Times Higher Education World University Rankings. [Online].
//[Link]/en/activities/digital-programme
Available: [Link]
[8] (Oct. 2019). Australian Government—Department of Education. Academic
rankings/2020/world-ranking#!/page/0/length/25/sort_by/rank/sort_
Centres of Cyber Security Excellence (ACCSE). [Online]. Available: https:
order/asc/cols/stats
//[Link]/academic-centres-cyber-security-excellence-
[30] UK Government. (2019). The National Cyber Security Centre. [Online].
accse.
Available: [Link]
[9] (2020). ECSO, Report: Results of Simulation-Based Competence [31] (2021). SPARTA H2020 Project: Special Projects for Advanced Research
Development Survey. [Online]. Available: [Link] and Technology in Europe. [Online]. Available: [Link]
documents/publications/[Link]
[10] (2020). University of Bristol, MSc Mathematics of Cybersecurity. [Online].
Available: [Link]
mathematics-of-cybersecurity/
[11] CEP. (Oct. 2019). The Cyber Education Project. [Online]. Available:
[Link]
[12] (2018). ECSO: Gaps in European Cyber Education and Profes-
sional Training. [Online]. Available: [Link]
publications/[Link]
[13] (2017). ENISA: Stocktaking of Information Security Training
Needs in Critical Sectors. [Online]. Available: [Link]
[Link]/news/enisa-news/stocktaking-of-information-security-training-
needs-in-critical-sectors
[14] (Mar. 26, 2020). ENISA. Cybersecurity Skills Development in the EU.
JAN HAJNY is currently an Associate Professor
[Online]. Available: [Link]
with the Faculty of Electrical Engineering and
of-cyber-security-education-in-the-european-union
Communication, Brno University of Technology,
[15] ENISA. Cybersecurity Higher Education Database. Accessed:
Jun. 1, 2021. [Online]. Available: [Link]
Czech Republic. He is the Co-Founder and the
cybersecurity-education/education-map Leader of the Cryptology Research Group, where
[16] (2019). (ISC)2 : Cyber Security Workforce Study 2019: Strategies for Build- he is responsible for managing the Information
ing and Growing Strong Cyber Security Teams. [Online]. Available: https:// Security Study Program. He is the author of more
[Link]/Research/-/media/6573BE9062B64FC7B4B91F20ECC5 than 80 scientific publications. He deals with
[Link] privacy-enhancing cryptographic systems. His
[17] Rupert Grayston. (Aug. 2019). Specialist Accreditation in Cyber Security. research is focused on the design of new authen-
[Online]. Available: [Link] tication protocols, credential schemes, and privacy-protection systems. He is
accreditation/ACS%20Information%20Sheet%20- also responsible for IT infrastructure benchmarking, stress testing, security
%20Cyber%20Security%20Specialist%20Accreditation%[Link] audits, penetration testing, and vulnerability scanning.
SARA RICCI received the [Link]. degree in LETTERIO GALLETTA is currently an Assistant
mathematics from the University of Pisa, Italy, Professor with the IMT School for Advanced Stud-
and the Ph.D. degree in computer engineering ies and a member of the CINI National Laboratory
and mathematics security from Universitat Rovira for Cybersecurity. Previously, he held a postdoc-
i Virgili, Spain. She is currently a Postdoctoral toral position with the Department of Computer
Researcher with the Brno University of Tech- Science, University of Pisa. His research activity
nology, Czech Republic. Her research interests mainly focuses on language-based security, and
include theoretical cryptography, in particular using techniques from programming languages,
lattice-based and elliptic curve cryptography, and compilers, and formal verification to address secu-
data privacy and security. She is also focused on rity problems. He applied these techniques to
the design of new privacy-preserving cryptographic protocols and their different fields, like adaptive software, the Internet of Things, secure
security analyses. compilation, firewalls, and smart contracts.