0% found this document useful (0 votes)
8 views25 pages

Framework, Tools and Good Practices For Cybersecurity Curricula

This document outlines a framework and tools for designing effective cybersecurity curricula in higher education. It identifies the need for quality education and training in cybersecurity, analyzes existing programs, and introduces the SPARTA Cybersecurity Skills Framework to align curricula with job market requirements. Additionally, it provides a web application to assist institutions in creating and evaluating cybersecurity study programs.

Uploaded by

23x51a05m3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views25 pages

Framework, Tools and Good Practices For Cybersecurity Curricula

This document outlines a framework and tools for designing effective cybersecurity curricula in higher education. It identifies the need for quality education and training in cybersecurity, analyzes existing programs, and introduces the SPARTA Cybersecurity Skills Framework to align curricula with job market requirements. Additionally, it provides a web application to assist institutions in creating and evaluating cybersecurity study programs.

Uploaded by

23x51a05m3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IEEE EDUCATION SOCIETY SECTION

Received June 2, 2021, accepted June 28, 2021, date of publication July 1, 2021, date of current version July 9, 2021.
Digital Object Identifier 10.1109/ACCESS.2021.3093952

Framework, Tools and Good Practices for


Cybersecurity Curricula
JAN HAJNY 1 , SARA RICCI 1 , EDMUNDAS PIESARSKAS2 , OLIVIER LEVILLAIN3 ,
LETTERIO GALLETTA 4 , AND ROCCO DE NICOLA 4
1 Advanced Cybersecurity Group, Brno University of Technology, 601 90 Brno, Czech Republic
2 LithuanianCybercrime Center of Excellence for Training Research and Education, LT-14288 Vilnius, Lithuania
3 Télécom SudParis, Institut Polytechnique de Paris, 91764 Palaiseau, France
4 CINI National Laboratory for Cybersecutity, IMT School for Advanced Studies Lucca, 55100 Lucca, Italy

Corresponding author: Jan Hajny (hajny@[Link])


This work was supported in part by the European Union’s Horizon 2020 Research and Innovation Program through the
Strategic Programs for Advanced Research and Technology in Europe (SPARTA) under Grant 830892, and in part by the Ministry of the
Interior of the Czech Republic under Grant VJ01030001.

ABSTRACT Cybersecurity education and training are essential prerequisites of achieving a secure and
privacy-friendly digital environment. Both professionals and the general public widely acknowledge the
need for high-quality university education programs and professional training courses. However, guides,
recommendations, practical tools, and good examples that could help institutions design appropriate cyber-
security programs are still missing. In particular, a comprehensive method to identify skills needed by
cybersecurity work roles offered on the job market is missing. This paper aims to provide practical tools
and strategies to help higher education providers design good cybersecurity curricula. First, we analyze the
content of 89 existing study programs worldwide, collect recommendations of renowned institutions within
and outside the EU, and provide a comprehensive survey accompanied by a dynamic web application called
Education Map. Based on the knowledge about the current state in cybersecurity education, we design the
SPARTA Cybersecurity Skills Framework that provides the currently missing link between work roles and
required expertise and shows how to develop a curriculum that reflects job market requirements. Finally,
we provide a practical tool that implements the framework and helps education and training providers design
new study programs and analyze existing ones by considering the requirements of cybersecurity work roles.

INDEX TERMS Cybersecurity education, cybersecurity skills framework, higher-education map, curricula
design, study programs.

I. INTRODUCTION focused on cybersecurity are currently emerging. However,


The labour market lacks qualified cybersecurity profession- these new degrees are often viewed as an add-on to computer
als. This fact is stated in official reports, unofficial surveys science ones and fail to realize the critical importance of the
among employers and easily visible in job databases. For interdisciplinary nature of this area [12].
instance, the cybersecurity Workforce Study 2019 [16] esti- This paper presents the methodology for creating cyber-
mates that there is a shortfall of 4.07 million cybersecurity security study curricula for higher education. The presented
experts. Moreover, ENISA [13] affirms that current train- methodology is based on (1) a mapping of expected capa-
ing courses do not sufficiently address different cybersecu- bilities of the cybersecurity workforce, (2) a deep analysis
rity sub-sectors such as the critical infrastructures and the of existing recommendations for curricula designs (including
implementation of the General Data Protection Regulation recommendations from computing associations and national
(GDPR). One solution to these problems is to enhance cyber- guidelines), and (3) an analysis of existing study programs
security education and training so that more cybersecurity covering 89 undergraduate and graduate programs in total and
experts can fill in the vacancies. Indeed, many curricula their mapping to work role requirements.
We design our methodology using the Cybersecurity Skills
The associate editor coordinating the review of this manuscript and Framework [27] developed within the Strategic Programs for
approving it for publication was Rebecca Strachan . Advanced Research and Technology in Europe (SPARTA).

This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see [Link]
VOLUME 9, 2021 94723
J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

Through it, we make it possible for different universities and II. RELATED WORK
training institutions to define their study programs according The purpose of this section is to provide the initial mapping
to their needs and capabilities. Our idea is that by using of the existing curricular recommendations from renowned
the same framework, the universities will share the same institutions dealing with cybersecurity training and educa-
taxonomy of courses and the common procedure for selecting tion. The analysis serves as the input to the further activities,
Knowledge, Skills and Abilities (KSA) required for partic- in particular to the design of our curricula design method-
ular work roles, i.e., positions on the job market, at which ology and good-practice curricula. By reviewing the current
graduates are aiming. recommendations, we also aim to grasp how primary sub-
We further support our methodology by proposing a web jects (e.g. mathematics) can be linked to the KSAs expected
application, called Curricula Designer, to assist with the by the practitioners in the field of cybersecurity, as skills
creation of study programs (Section V-C). Its main feature frameworks usually are not reflecting fundamental subjects.
is to simplify the design of a study program composed Nowadays, new cybersecurity courses are developed by
of courses that match particular cybersecurity work roles academics in response to real world needs both in the public
requirements. and private sectors. However, there is no consolidated com-
By providing a unified approach for designing the curric- mon approach to define the requirements of a cybersecurity
ula, showing the good-practice curricula and developing a curriculum, in particular, which skills need to be taught and
practical software tool usable for curricula design, we hope which areas of expertise need to be covered. For this rea-
to boost new cybersecurity study programs at universities and son, many academics, computing societies, and governmental
training institutions while emphasizing the interdisciplinary organizations have proposed educational frameworks that
nature of cybersecurity. Furthermore, we hope that the new include recommendations, guidelines, and practices to drive
programs will be designed according to specific rules and the creation of new cybersecurity curricula. These frame-
standardized approaches reflecting the actual requirements of works help curriculum designers to understand the require-
particular cybersecurity positions. ments of cybersecurity disciplines and to define topics and
themes that are considered fundamental. Although signifi-
cant differences arise among these frameworks, they seem
A. OUR CONTRIBUTION to agree on the fundamental cybersecurity topics. Especially,
Our contribution is threefold. Firstly, this article revises the the common aspect is that they identify ‘‘interdisciplinarity’’
existing curricular recommendations from renowned insti- as the key term in determining the best security program:
tutions dealing with cybersecurity training and education. cybersecurity courses of study should offer classes in differ-
Secondly, using the SPARTA Cybersecurity Skills Frame- ent areas of computer science, engineering, management and
work (CSF) we have linked the cybersecurity skills to work law. Figure 1, taken from CyBOK [25], summarizes the areas
roles recognized on a job market. The established links enable of interest of the cybersecurity field and highlights orthog-
us to analyze a sample of 89 study programs and provide onality of different areas and multi-disciplinarity. However,
an overview of the current cybersecurity education status. the emphasis given to each topic varies among the various
Finally, our analyses are an instrument and a stimulus for educational frameworks.
designing higher-education study programs in cybersecurity In this section we provide a short survey of those
through a cybersecurity curricula designer tool. framewroks we consider the most relevant proposals and
Moreover, the collected data are visualized in a dynamic recommendations for establishing security courses of study.
web application to help students search for a cybersecurity
study program. A. JOINT TASK FORCE GUIDELINE
The rest of the paper is organized as follows. Section II At the end of 2017, the first set of global curricular
reviews related work on cybersecurity education. Section III recommendations in cybersecurity education has been
summarizes the cybersecurity skills framework used to define released by the Joint Task Force on Cybersecurity Education
good-practice cybersecurity curricula. Section IV provides (CSEC2017 JTF).
the analysis of existing cybersecurity Bachelor’s and Master’s This task force is an outcome of The Cyber Education
study programs. Section V shows the methodology for creat- Project (CEP) [11],1 an initiative supported by academic
ing novel curricula, the good-practice curricula, and the web institutions, governments and industries in the USA, to (1)
application for designing cybersecurity curricula. The final develop undergraduate curriculum guidelines for educational
section contains our conclusions. programs in the Cyber Sciences, and (2) establish a case for
This article summarizes and builds upon the results the accreditation of educational programs. The term Cyber
of research activities conducted within the SPARTA Sciences refers to all disciplines that involve technology,
project [31]. Extended description of the methods and tools people, and processes to enable assured operation in the
presented in this paper, in particular the SPARTA Cyberse- presence of risks and adversaries.
curity Skills Framework and Good-Practice Cybersecurity
Curricula, is available in our technical reports on SPARTA 1 Currently, the access to [Link] seems to
CSF [27] and Curricula Descriptions [28]. be limited to USA’s IPs only.

94724 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

several types of controls. The specific system to be presented


in the course is left to the course designer. Furthermore,
KUs do not necessarily correspond to courses or course
units, but courses typically contain topics from multiple KUs.
Furthermore, KAs are not mutually exclusive, because KUs
are relevant for, and logically placed in, multiple knowledge
areas.
The document introduces eight KAs:
1) Data Security;
2) Software Security;
3) Component Security;
4) Connection Security;
5) System Security;
6) Human Security;
7) Organizational Security;
8) Societal Security.
For overview of the content for each KA, reporting the
essential concepts students should learn and the KUs, we refer
FIGURE 1. The 19 knowledge areas in the CyBOK.
the reader to the CSEC2107 volume [1].

B. AUSTRALIAN COMPUTER SOCIETY GUIDELINE


The mission of the CSEC2017 JTF is to devise curricular
Australian Computer Society (ACS) [3], the largest profes-
recommendations and to produce a volume [1] that structures
sional body in Australia representing the Information and
the cybersecurity discipline and drives institutions to develop
Communication Technology (ICT) sector, started offering
or modify a broad range of programs in Cyber Sciences. The
Specialist Accreditation in Cyber Security for courses that
CSEC2017 volume highlights the interdisciplinary nature of
prepare graduates for specialist roles in cybersecurity [17].
a course of study, and stresses that, although fundamentally
Although ACS does not formally provide curricula guide-
computing-based, the studies need to include aspects of law,
lines, the requirements for accreditation can be used as best
policy, human factors, ethics, and risk management. In par-
practices. In addition, programs seeking specialist accredi-
ticular, the CSEC2017 volume advocates for curricula to
tation in Cyber Security are also required to meet the ACS
include:
criteria for ICT accreditation.
• A computing-based foundation (e.g., computer science, These criteria are based on the Skills Framework for the
information technology); Information Age (SFIA) [26]. The framework is used as a
• Concepts that are crosscutting and broadly applicable model for describing and managing skills and competencies
across the range of specializations (e.g., cybersecurity’s for ICT professionals. It consists of professional skills with
inherent adversarial mindset); seven levels of responsibility and competence, and describes
• Essential cybersecurity knowledge and skills; the professional skills required at the various levels. The lev-
• An emphasis on the ethical conduct and professional els that are relevant for the ACS accreditation in cybersecurity
responsibilities in the field. are level 3 and level 5. Level 3 requires that the IT profes-
Furthermore, the CSEC2017 volume suggests that cyber- sional is able to complete work packages, escalate problems
security programs need to provide content that includes under his own discretion, work with suppliers and customers
the theoretical and conceptual knowledge essential to and have some supervisory responsibility. Level 5 requires
understanding the discipline, and activities to develop the that the Information Technology (IT) professional is able
practical skills by application of the theoretical knowledge. to decide broad direction and supervisory, to set objectives,
CSEC2017 is organized around the idea of Knowledge to influence organizations, to be self sufficient in business
Areas (KAs). Collectively, KAs represent the full body of skills. Level 3 is required for Professional Specialist Accred-
knowledge within the field of cybersecurity. Thus, the goal itation in Cyber Security: this accreditation seems requiring
is that essential concepts of each KA capture the cyber- professionals to show a certain level of autonomy in complet-
security proficiency that every student needs to achieve. ing tasks but that are not required to have any management
KAs are structured in Knowledge Units (KUs), e.g. thematic skills. Level 5 is required for Advanced Professional Spe-
groupings of related topics. cialist Accreditation in Cyber Security that demands profes-
The thematic topics do not cover the actual content of a sionals to show a good level of management and supervisory
course but they must be instantiated to the specific material skills.
that the course wants to cover. For example, in the Data Furthermore, the ACS criteria require specific courses for
Security KA there is a KU about Access Control that reports teaching cybersecurity topics. The criteria do not explicitly

VOLUME 9, 2021 94725


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

define these topics but they specify only that they should For each pathway, NCSC indicates the topics that the syl-
be compatible with Core Body Of Knowledge (CBoK) for labus is expected to cover; the number of credits in Higher
ICT professionals [2]. The CBoK describes the essential Education Credit Framework for England (HEI) reserved for
ICT knowledge required for any ICT professional and it is each specific topic; and the skills that students are expected
structured in knowledge areas that include: to master when they finish their studies. The topics include
1) ICT Professional Knowledge (ethics, professional basics of computer science and foundations of cybersecurity.
expectations, teamwork concepts and issues, inter- The certification prescribes the skills that students should
personal communication, societal issues/legal issues/ have upon graduation, thus, it defines the learning outcomes
privacy and understanding the ICT profession); of a certified Bachelor’s degree. In particular, students must
2) ICT Problem Solving; Technology Resources be able to:
• demonstrate a sound understanding of the main areas
(hardware and software fundamentals, data and
of knowledge in cybersecurity and to exercise critical
information management, networking); Technology
Building (human factors, programming, systems judgment;
• critically analyze and apply essential concepts to
development, systems acquisition);
3) ICT Management (IT governance and organizational defined scenarios, selecting and using effective tools and
issues, service and project management, security techniques;
• analyze, design and develop a system, showing problem
management).
solving and evaluation skills; demonstrate generic skills
The ACS proposes two kinds of accreditations: Profes- about work organization as an individual and as a team
sional Specialist Accreditation in Cyber Security (PSACS) member and with minimum guidance;
and Advanced Professional Specialist Accreditation in Cyber • apply appropriate practices within a professional, legal
Security (APSACS). and ethical framework; identify mechanisms for contin-
• Degree programs that aim at PSACS must identify a spe- uing professional development and lifelong learning;
cific Cyber Security professional role they want to train • be creative and innovative in their application of the
for. Then, they need to address SFIA skills at level 3 by principles covered in the curriculum;
focusing on those that are specific for the professional • be able to exercise critical evaluation and review of both
role they identified; finally, the course of study must con- their own work and the work of others.
tain at least 8 subjects drawn from an appropriate Cyber Universities that want to certify their Bachelor’s degrees
Security body of knowledge compatible with CBoK. should select one of the available pathways to apply.
• Degree programs that aim at APSACS must first identify Depending on the pathway NCSC defines specific subjects
a specific Cyber Security professional role they want to areas that degrees should fully or partially cover.
train for. Then, they need to address SFIA skills at level For Pathway A, the syllabus of a candidate degree must
5 by focusing on the skills required for the identified provide from total 360 credits a minimum of 270 HCI
role. Finally, the course of study must contain at least (Human Computer Interface) credits in computer science,
8 subjects drawn from an appropriate Cyber Security where at least 240 can be mapped to specific topics detailed
body of knowledge compatible with CBoK. below. For Pathways B and C, a candidate degree must have
a minimum of 160 HCI credits in computer science, where at
least 135 must cover specific topics detailed below.
C. UK CYBERSECURITY CENTRE GUIDELINE
In particular, each pathway requires that candidates
The UK government has established the National Cyberse- degrees meet the following specific constraints:
curity Centre (NCSC) [30]. The NCSC understands cyber-
• For pathway A, a Bachelor’s degree must cover in
security, and distils its knowledge into practical guidance; it
good breadth and depth topics from basics of computer
uses industry and academic expertise to secure public and
science, like software engineering and system funda-
private sectors. It also certifies bachelor and master degrees in
mentals. It must also cover fundamental concepts of
cybersecurity and closely related fields. Although it does not security, as well as more advanced security topics like
explicitly provide an official educational framework, require- low level techniques and tools, and secure programming.
ments can be implicitly interpreted as guidelines for defining
Moreover, students must undertake an individual
high-level curricula in cybersecurity.
project and a dissertation relevant to cybersecurity for
At the bachelor’s level, NCSC provides three types of
20/40 credits.
certification (called pathways) for ‘‘Bachelor’s degrees with
• For pathway B, a Bachelor’s degree is required to
Honours in Computer Science’’ [19] that: have a minimum of 90 credits on topics related to
1) address underpinning computer science topics relevant cybersecurity, not necessarily specific for computer sci-
to cybersecurity (pathway A), ence, like information security management, informa-
2) provide a general, broad foundation in cybersecurity tion assurance methodologies and incident management.
(pathway B), Furthermore, topics related to computer science must
3) provide a foundation in Digital Forensics (pathway C). be covered in good breadth and depth. These topics

94726 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

include software engineering, computer networks and include knowledge units that cover a specific quantity of
operating systems. Finally, students must undertake an mandatory academic content, like low level programming
individual project and a dissertation on a topic relevant languages, operating systems, etc., and a minimum of 10 of
to cybersecurity for 20 and 40 credits. the 17 optional academic content, e.g., wireless security.
• Pathway C is about Digital Forensics. A Bachelor’s
degree to be accredited must must provide 90 HCI E. NATIONAL INITIATIVE FOR CYBERSECURITY
credits in topics related to digital forensics. These top- EDUCATION (NICE)
ics must include the theoretical fundamentals of digital The National Initiative for Cybersecurity Education (NICE)
forensics with its applications and tools ( covered in is a U.S. partnership between government, academia and
good breadth and depth), information security, and all private sector led by the National Institute of Standards
the aspects relevant to the legal process. Furthermore, and Technology (NIST). Its main goal is to support U.S.
it has to cover also topics related to computer science, cybersecurity training and education providers through the
like software engineering, computer networks and oper- introduction of new standards and best practices. Besides
ating systems. Finally, students must undertake an indi- other documents, NICE created the NICE Framework that has
vidual project and a dissertation on a topic related to been already standardized as the NIST Special Publication
digital forensics. 800-181 revision 1, the Workforce Framework for Cyber-
security (NICE Framework) [20]. The NICE Framework
D. USA NATIONAL CENTERS OF ACADEMIC EXCELLENCE provides detailed description of main building blocks, i.e.
The National Security Agency (NSA) and Department of Knowledge, Skills and Tasks of cybersecurity Work Roles.
Homeland Security (DHS) support cybersecurity education Using the NICE Framework, it is possible to easily identify
in colleges and universities via an accreditation program, what knowledge and skills are required by particular work
called the National Centers of Academic Excellence (CAE) roles available on the cybersecurity job market. Besides the
in Cyber Defense [24]. Actually, they sponsor two types of standard, NICE initiative also published a supplemental doc-
CAE: one in Cyber Defense (CAE-CD) and one in Cyber ument called Reference Spreadsheet [21] that covers the
Operations (CAE-CO). These accreditation programs (called mapping between Work Roles and Tasks, Knowledge and
designations in the following and in the official documents) Skills.
ensure that an appropriate cybersecurity curriculum is avail-
able within the institution. The requirements that institutions F. THE CYBER SECURITY BODY OF KNOWLEDGE
and study plans need to meet can also be interpreted as The CyBOK [25] is a project funded by the National Cyber
guidelines and best practices to define a high-level curriculum Security Program and led by the University of Bristol whose
in cybersecurity. goal is to codify the foundational and generally recognized
The CAE-CD program comprises two designations: CAE knowledge on cybersecurity. The problem the project is try-
in Cyber Defense Education (CAE-CDE) for Associate, ing to address is the fragmented and incoherent founda-
Bachelor, Masters and Doctoral Programs; CAE in Cyber tional knowledge for the cybersecurity field. It takes inspira-
Defense Research (CAE-R) for those institutions that do tion from mature scientific disciplines, such as mathematics,
research in cybersecurity. All regionally accredited two-year, physics, chemistry, and biology that have long-established
four-year, and graduate level institutions in the US can apply foundational knowledge and clear learning steps from sec-
to become a CAE-CD school and receive the designation if ondary school to undergraduate degrees at university, and
they meet specific criteria. Since we are interested in edu- beyond. Its long-term goal is to be a guide to the body of
cational guidelines, we omit any discussion about CAE-R. knowledge and to work as the basis on which educational pro-
For the designation of Bachelor, Master, and Doctoral, appli- grams, ranging from secondary and undergraduate education
cants must be a regionally accredited four-year college or to postgraduate can then be developed.
graduate-level university. Besides an evaluation concern- The knowledge that it codifies already exists in litera-
ing organizational aspects (see CAE-CDE Criteria [22]), ture such as textbooks, academic research articles, technical
it is required that institution’s curricula adhere to CAE-CD reports, white papers and standards. The focus is, therefore,
Knowledge Units. These Knowledge Units describe the top- on mapping established knowledge and not fully replicating
ics to be covered and the goals they have to achieve. In partic- everything that has ever been written on the subject.
ular, the program must be mapped to the Foundational, Core The CyBOK project managed to identify 19 Knowledge
and selected Optional KUs. Areas (KAs) and to organize them into coherent framework.
The CAE-CO program is a technical education program The KAs are not orthogonal, indeed there are a number of
firmly grounded in computer science, computer engineer- dependencies across them. Moreover, they are grouped into
ing, and/or electrical engineering disciplines. It complements five broad categories, as summarized visually in Figure 1.
CAE-CD, putting specific emphasis on technologies and These five categories are:
techniques. Programs must meet a set of academic require- 1) Software and Platform Security;
ments and programmatic criteria which measure the depth 2) Systems Security;
and maturity of the programs. A CAE-CO program must 3) Attacks and Defences;

VOLUME 9, 2021 94727


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

4) Infrastructure Security; Furthermore, in order to promote cybersecurity education


5) Human, Organisational, and Regulatory Aspects. and help with solving CSSS, ENISA has created the Cyber-
Furthermore, the CyBOK was used by Hallet et al. [18] security Higher Education Database [15], which aims to
as the basis for comparing different cybersecurity curricu- become the main reference for all persons looking to improve
lar frameworks. In particular, they compared four curricular their cybersecurity knowledge and skills.
frameworks and for each of them they mapped its topics and
learning outcomes onto CyBOK knowledge areas. H. SUMMARY ON EXISTING GUIDELINES
Their analysis shows that, although the different frame- We presented some of the most relevant curricular guide-
works consider a common corpus of topics, they differ in the lines for cybersecurity studies. These guidelines constitute
emphasis put on each topic. For example, CSEC 2017 JTF requirements that courses of study must meet to receive an
(see Section II-A) focuses more on Human, Organisational, accreditation by governments or computing societies. These
and Regulatory Aspects. The reader is referred to [18] for accreditation programs aim at certifying that the content of a
details on the comparisons. course of study and the skills acquired by graduates meet the
G. ENISA’s CYBERSECURITY SKILLS expected standards.
DEVELOPMENT IN THE EU Although significant differences arise among these frame-
works, especially regarding the emphasis to put on each topic,
In this subsection, we consider a document from ENISA [14],
they seem to agree on the fundamental choices about what
which deals with CyberSecurity Skills Shortage (CSSS). The
to teach to train cybersecurity experts. Furthermore, they
main goal of this report is to identify the main reasons of skill
identify ‘‘interdisciplinarity’’ as one of the key terms for
shortage, considered not just an EU problem, but a world-
cybersecurity education. They agree on the fact that cyber-
wide one. The report focuses on the status of the cybersecu-
security courses of study should offer classes in different
rity education system and on the mismatch of expectations
areas ranging from computer science to management, and
between the main stakeholders, namely industry, academia,
from engineering to law. In addition, hands-on training, use of
and government. ENISA acknowledges that cybersecurity
cyber ranges, tight connections to industry, and gamification
skills shortage is a multidimensional policy issue and argues
are aspects that resonate through multiple frameworks and
that today’s educational systems are unable to attract more
recommendations.
students to cybersecurity studies and to produce graduates
with ‘‘the right set of cybersecurity skills and knowledge’’.
According to ENISA, actions must be taken in order to form III. CYBERSECURITY SKILLS FRAMEWORK
these graduates and effectively solve, even if only partially, Efforts to fill the skills gap requires EU, governments,
the CSSS issue. academia, industry, as well as societies and professionals
As part of their analysis, ENISA dedicates attention to four to take an active role. To undertake such concerted efforts,
states – Australia, France, United Kingdom, and the United however, will require a common language which would allow
States, which have approached the problem by proposing for productive cybersecurity-related skills discussions across
certification of cybersecurity degrees. Based on this data and the Member States, industry, academia and professionals,
other relevant sources like statistics, governmental statements so that actors can unambiguously understand each other.
from European Economic Area (EEA) countries and rele- So, the SPARTA project designates its efforts to analyze
vant quotes from firms in the industry (e.g. Kaspersky Lab), the state of knowledge on skills management, reviewing
ENISA provides recommendations and considerations for the best practices and proposing the way forward with the
main stakeholders and outlines their possible role in helping development of an EU based cybersecurity skills framework.
with CSSS. The SPARTA CSF [27] is based on the structure of the
As an outcome of the analysis of the existing certification NICE Framework [20], and takes into account the following
procedures of cybersecurity degrees, ENISA listed six major dimensions:
requirements that are recurrent and states that any higher
• Work Roles: general groupings of cybersecurity and
education cybersecurity degree should have:
related requirements which include a list of attributes in
1) enough specific credits dedicated to cybersecurity
the form of knowledge, skills, abilities (KSAs) and tasks
courses and activities,
required to perform these roles.
2) a structured curriculum, possibly including a practi-
• Knowledge, Skills, and Abilities (KSAs): the attributes
cal/training component or specific types of examina-
required to perform work roles, generally demonstrated
tions and activities such as cybersecurity competitions,
through relevant experience, education and training [20].
3) a high-quality teaching faculty, which might include
• Tasks: specifically defined pieces of work that, com-
lecturers from the industry,
bined with other identified Tasks, form the work in a
4) a broader multi-/inter-disciplinary focus,
specific specialty area or work role.
5) outreach activities and collaborations with the rest of
the national cybersecurity ecosystem, In addition to the main structure of the Framework,
6) information on academic and employment outcomes. KSAs are also linked to the competences in the secondary

94728 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 1. Competence list of the NICE / SPARTA CS frameworks.

components of the NICE Framework. There are four providers to review their curricula in a structured and
Competence Groups: systematic manner. They have a recognized framework
• Technical Competence Group - compiles the instru- to be used as the main benchmark instrument.
mental KSAs and covers the ‘‘what is to be done’’ aspect • Improve - can be done based on the evaluation exercise.
within the Framework; This is especially important considering the emerging
• Operational Competence Group - compiling KSAs needs of practitioners. The Framework is able to transmit
from other critical areas, defining ‘‘how activities should arising requests at an early stage, providing Academia
be done’’; with the foresight to improve and develop their curricula
• Professional Competence Group - compiling expected further.
‘‘soft skills’’; • Focus - education provided by universities may dif-
• Leadership Competence Group - compiling KSAs fer in the way they address core competencies. Some
needed for the managerial part of the organization. might be more focused on specific technological sub-
Each Competence Group is associated with a Competence jects, some on law, others on forensics, etc. Having an
Level, providing a direct link to the KSAs. In this way, integrated Framework to work with, they can map their
competencies can also be linked to other components of core competencies onto various subject areas, important
the Framework structure. Table 1 shows the list of NICE for defined roles. This enables the institution to develop
competencies divided according to the group they belong to. more effective targeted programs in house around the
Clearly, technical competencies are dominating, being main competencies.
cybersecurity a highly technical field. At this point it is important to describe the Framework and
Possible applicability of SPARTA CSF for Academia is its relationship to professional training and education.
described fully in D9.1 Chapter 6.2 Use of the Framework Professional training providers can use the Framework
[27]. Here, we provide the main activities to be executed: directly, as they are aware of the KSAs required by prac-
• Evaluate - the right granularity of requested knowl- titioners and how those are interlinked with the work roles
edge/skills/abilities allows education and training performed.

VOLUME 9, 2021 94729


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 2. Division of SPARTA topics.

Links with Education are less obvious, as the Framework 3) New trends are identified. Some of the Educational
describes KSAs requested within a context of associated subjects might be based on specific technologies like,
activities, but it does not provide any indication of how those e.g., quantum computing ones. However, SPARTA CSF
links can be established. Education institutions compose their does not specify any particular technology, which may
curricula considering the complete path – they start with the be listed in a format of explanation of KSAs in some
fundamental capabilities that are required for the individual cases only, or may be described in the New Trends
to learn as a basis for the next set of follow-on subjects. This category.
is reflected in the SPARTA Topics (see Fig. 2) proposed as the We now provide an example of SPARTA Topics and
result of the analysis of current Education programs. SPARTA SPARTA CSF mapping, followed by some insights for the
Topics include all subjects required to get individuals ready development of curricula. The mapping is obtained by the
to enter the professional workforce, including fundamental three steps described below.
Topics, cyber security Topics and technology-related Topics.
Distribution of subjects within specific categories is obtained
through the following steps: A. STEP 1: DIVISION OF TOPICS
1) All subjects are classified as belonging to either Fun- All Topics are divided into three groups: Fundamental, Cyber
damental, Cyber Security or New Trends categories. Security and New Trends, see Figure 2.
Fundamental subjects are those not directly linked to As mentioned, Fundamental Topics do not have a direct
the Framework, but which serve as a prerequisite for link with SPARTA CSF competencies, but they serve as a nec-
further studies. Some Fundamentals can have a link essary prerequisite for other Topics. Some of the Fundamen-
to the competence block, but thereby only depict the tal subjects have links to NICE competencies (demonstrated
relevant link to further studies. For example, Funda- by dashed arrows in Figure 3), aiming to show further links,
mental Cryptology is the prerequisite for Cryptanalysis and areas for additional focus.
or Advanced Cryptology; Number Theory is necessary While developing the curricula, insights on what the Fun-
for most intermediate and advanced computer related damental subject should include to serve as a solid back-
subjects. ground for further studies content should also be provided.
2) The identified Cyber Security specific subjects are
linked to the competencies of the Framework according B. STEP 2: MAPPING OF SPARTA TOPICS TO
to the content of the individual subjects. This map- SPARTA CSF COMPETENCIES
ping reveals the exact competencies to be stressed or As cybersecurity is mainly considered as a technical disci-
considered. Since competencies are linked to KSAs pline (this is also demonstrated by the SPARTA CSF compe-
within the Framework, it is possible to obtain a detailed tence structure), the mapping is made using only Technical
list of KSAs expected by practitioners. In this way, and Operational Competencies (provided in Table 1). Pro-
the Framework helps to structure the topic for a better fessional and Leadership Competence groups are outside the
fit to the expected activities. domain of current SPARTA Topics and refer more properly to

94730 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 3. Links between SPARTA topics and SPARTA CSF technical and operational competencies.

teaching methods, and additional modules offered to cyberse- Using the link in Figure 3 between Topics and com-
curity students. petencies (and thus between Topics and KSAs and work
Figure 3 provides an overall mapping of what SPARTA roles), we are now able to analyze the existing study pro-
CSF competencies should be included in SPARTA Topics. grams (Section IV) and propose new good-practice curricula
(The Topics that have no links are considered Fundamental (Section V).
or New Trends.) Each Topic in Figure 3 can be linked to a
KSA in the SPARTA CSF. This is illustrated by an example: IV. MAPPING HIGHER EDUCATION PROGRAMS
IN CYBERSECURITY
• SPARTA Topic - Probability and Statistics
Many cybersecurity study programs are nowadays offered
• Linked with CSF competence - Modeling and Simula-
around the world. Depending on the expertise of the man-
tion and Data Analysis
aging group and country environment, the curricula can be
The NICE list of KSAs gives a very detailed and extensive substantially different.
listing of expected outcomes. It clearly shows how this can In this section, we summarize data which cover
guide the development of general and topic specific curricula. 89 higher-education cybersecurity curricula (19 bachelors
In addition, links to roles and other components of the and 70 masters) spread over 19 countries, 5 of which are
Framework can be determined, if needed. non-European. These data are used to produce an educational
world map which is presented in Section IV-C.
C. STEP 3: NEW TRENDS
Quantum computing and Post-quantum cryptography are A. METHODOLOGY
topics not directly reflected in the Framework, as they are We start with a brief summary on how the data were collected.
technology specific. Integration of emerging KSAs into the Three documents were produced in order to simplify the
Framework is in progress and will be described separately. review:

VOLUME 9, 2021 94731


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 4. First analysis template Excel file for the ‘‘Master in Mathematics of Cybersecurity’’ study program, Bristol University,
United Kingdom.

• List of Topics, This document also states whether a subject is manda-


• First Analysis Template, tory and, therefore, considered of main importance for a
• University Template. cybersecurity study program by the university. Moreover,
it also shows if practical lectures (laboratories) are offered
The List of Topics was compiled using the SPARTA CSF.
during the courses. For instance, the ‘‘Data Science Toolbox’’
Figure 2 shows the SPARTA Topics covering the most rel-
subject is marked as practical (as reflected by the 1 in the
evant areas of interest in cybersecurity. Figure 3 depicts the
Practical Lecture column in Figure 4) since it requires the use
link between SPARTA Topics and the NICE competencies.
of particular languages like R and Python and software like
The First Analysis Template document allows to classify
Hadoop and Spark.
the subjects of a study program according to their belong-
Finally, the University Template Document synthesizes
ing to either one or more cybersecurity areas. Figure 4
the main information about the university and the related
depicts the ‘‘Master in Mathematics of Cybersecurity’’ study
study program that was collected from the web page of each
program analysis [10]. This study program is taught at Bristol
university:
University, United Kingdom.
If we consider, for instance, the ‘‘Introduction to Mathe- • the study program language,
matical Cybersecurity’’ subject which is described by: ‘‘this • its ECTS credits,
unit will cover the following topics: how the internet works; • its cost.
computer security and encryption; vulnerabilities and cyber The document also shows the covered topics and a summary
attacks; understanding the data; mathematical models such of the subjects analyses done in the first analysis template
as graphs and point processes; probabilistic reasoning’’, and document.
its aim is ‘‘students will gain literacy in mathematical aspects Instructions were provided to data suppliers (universities)
of fundamental cybersecurity concepts, and gain the ability to for filling of the documents as shown at the bottom
convert these ideas into mathematical descriptions’’, then this of Figure 4.
subject covers three areas: cryptography, mathematics and It is important to note that there is a large number of cur-
security. Moreover, it gives more importance to mathematical ricula that only partially focus on cybersecurity and present
models, therefore the main area is mathematics. In Figure 4, few courses on this topic. To avoid considering too general
0.25 point is assigned to both cryptography and security, curricula, the selection proceeded as follows: at first, a search
while 0.5 is assigned to mathematics. The sum of the values in the Internet per country was run looking for study programs
per row has to be 1 for each subject. that have in the title either ‘‘security’’, ‘‘cybersecurity’’,

94732 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 2. Higher-education entities that run a study program in cybersecurity in Europe.

TABLE 3. Study programs features: language, ECTS credits and cost in Europe.

‘‘cryptography’’, ‘‘cryptology’’ or ‘‘privacy’’ words. Then, Denmark and Norway, passes to countries that charge for a
if more than 6 curricula appeared in the search, universities symbolic payment (mostly for the enrollment) as Germany,
were sorted using the Times Higher Education World Uni- and finishes with countries, like the United Kingdom, where
versity Rankings [29] and the first 6 higher ranked where a 2-year master can cost as much as 33,300 Euro.
considered. Assuming that the country’s leading universities
are more likely to represent the best proposals.
This collection was meant to produce a representative sam- 2) EUROPEAN LECTURES ANALYSES
ple of the current university offers in cybersecurity. For the Here, we show the results of the statistical analyses we
sake of time and resources, covering all existing curricula was performed on the collected subjects of European study pro-
not feasible. grams. Among the 6 considered European countries, only
14 curricula passed the criteria for being used in the statistical
analyses. Moreover, 11 analyzed countries have a master
1) EU COUNTRIES curricula and only 44 curricula are eligible for statistical
In the following, we summarize the results of the collected analyses (the total number of curricula can be found in Table 9
data over 61 European cybersecurity curricula. In particular, in Appendix A).
15 bachelors and 46 masters curricula were meeting the con- Indeed, in order to be used in analyses, a curriculum must
strains identified in Section IV-A. A list of the study programs offer compulsory subjects and must not be too general.
split by country can be found in Table 9 in Appendix A. For each study program, the total percentages computed
These study programs are spread over 14 European coun- in ‘‘first analysis template’’ document are considered (see
tries and run by 38 different universities. Table 2 counts Section IV-A for more details). These percentages give an
which faculties/departments/schools are mainly involved in idea of how the mandatory subjects are divided among the
teaching cybersecurity. Some curricula are jointly taught by identified cybersecurity areas, which are computer science,
different entities in the same university, therefore, the total cryptography, humanistic and social science, mathematics,
number of providers is not proportional to the number of privacy, and security.
involved universities. The focus is on mandatory subjects since these are the
Table 3 shows the number of study programs in English, ones considered of main importance for a cybersecurity study
their ECTS credits and their average cost. Bachelor curricula program. In fact, depending on the department (or faculty) the
are taught in the native language of the country, in fact the offer of elective subjects (when present) can be really differ-
2 bachelors in English are taught in the United Kingdom. ent and makes the curriculum more specialized in the areas
Masters are split according to their duration: 1 and 2 years. of interest of the hosting department. Accordingly, since we
This differentiation is important since masters in 1 year are want to identify the basic knowledge that needs to be taught
normally thought as specialization post-master (the 2 years in a cybersecurity curriculum, this more detailed information
ones) and they are not sufficient for entering a Ph.D. study is not relevant for our preliminary study.
program. Figures 5 and 6 depicts the statistical analyses for European
In theory, the ECTS number should be 180 for bachelors, bachelor and master curricula divided by country and then
120 for 2-years masters, and 60 for 1-year masters. Germany summarized in the ‘‘Europe’’ chart. For instance, in Figure 5
has 5 bachelors of 210 ECTS, 1 2-year master of 180, and the ‘‘United Kingdom’’ chart shows the mean of the areas
1 1-year master of 90 ECTS since they last 1 semesters more percentage of the 2 bachelor curricula taught in this country,
than the usual programs. Moreover, in the United Kingdom while the ‘‘Europe’’ chart shows the mean of all the collected
all the considered 6 masters account for 90 ECTS. European bachelor study programs. These plots show how the
Regarding the cost of a study program, the range starts areas percentages change depending on the country. However,
from free of charge in countries like Czech Republic, we are mostly interested in the general behaviour which is

VOLUME 9, 2021 94733


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 5. Analysis of European cybersecurity bachelor study programs. ‘‘Computer Sc.’’ stands for computer science area,
‘‘Crypto’’ for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for
security area, and ‘‘Privacy’’ for privacy area.

TABLE 4. Practical lectures in Europe. ‘‘NA’’ stands for not available. the last column of the table shows the average percentage
among the available data.
Practical lectures are present in all study programs and,
in fact, they are of vital importance for cybersecurity. Master
study programs have higher average of practical lectures
compared to bachelors ones.

represented in the ‘‘Europe’’ charts. Here, computer science 3) NON-EU COUNTRIES


area is clearly considered the main basis of cybersecurity In the following section, we summarize the results of the
bachelors, followed by security. collected data from 26 non-European cybersecurity curricula.
The situation changes slightly if we compare this fig- In particular, 4 bachelors and 22 masters meet the constrains
ure with Figure 6 on master curricula, where security and identified in Section IV-A. A list of the study programs split
humanities grow at the expense of mathematics and computer by country can be found in Table 11 in Appendix A.
science. This is due to the fact that mathematics and computer These study programs are spread over 5 non-European
science are the basic skills necessary for the comprehen- countries and offered by 21 different universities. Table 10
sion of any cybersecurity knowledge, and therefore, they are in Appendix A lists which faculties/departments/schools are
expected to be taught in bachelors and to be assumed as manly involved in teaching cybersecurity. Some curricula are
known in masters. jointly taught by different entities in the same university,
In all the charts, a small portion of the teaching is dedicated therefore, the total number of providers is not proportional
to privacy topics in bachelor curricula, but it increases in to the number of involved universities.
masters. In Table 10 in Appendix A, no multi-university curricula
Finally, Table 4 shows the percentage of mandatory prac- were found among the collected data. Moreover, the col-
tical lectures given in each study program (i.e. the columns umn ‘‘Other’’ covers 1 Department of Professional Studies
values ‘‘NA’’ and from ‘‘0’’ to ‘‘100’’). In particular, this for a bachelor curriculum (USA) and 5 cybersecurity insti-
is a lower bound of the total taught practical lectures. This tutions/laboratories. Note that, like in Europe, departments
value is calculated in the ‘‘Practical Lecture’’ cell of the ‘‘first of Computer Science are the main offerer of cybersecurity
analysis template’’ document and rounded to the lower value curricula. A difference between European and non-European
among 0, 25, 50, 75 and 100%. For instance, a calculated offerers is that the Faculty of Social Science is present
33% becomes 25%. When this information is not available, in Table 2 but not in Table 10 in Appendix A, where School
the related study program is labeled as ‘‘NA’’. Moreover, of Business took its place.

94734 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 6. Analysis of European cybersecurity master study programs. ‘‘Computer Sc.’’ stands for computer science area, ‘‘Crypto’’
for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for security
area, and ‘‘Privacy’’ for privacy area.

It is important to notice that the duration of the 4 bachelors USA masters is not available on their web pages and therefore
is not fixed to 3 years as in European ones. It could be they could not be classified in Tables 5 and 6.
6 months (USA), 2 years (Canada), and 4 years (Canada and The cost of a study program is really higher with respect
Japan). Moreover, 3 masters have no specified duration and to the European proposals (see Table 3 for more details).
the 2-years masters cover a duration of 16 to 24 months. In particular, we could not find free-of-charge study pro-
Table 5 shows the number of study programs in English, grams. In the bachelor average, the 6-months curriculum is
their ECTS credits and their average cost. Unluckily, not counted because the information was not available.
the information was harder to find, therefore, our collected
data has more ‘‘NA’’. For instance, since ECTS is a European 4) NON-EUROPEAN LECTURES ANALYSES
standard, this field is empty in all programs. Moreover the In the following section, we show the results of the sta-
language as well as the cost of the 3 South-Korean masters tistical analyses we carried out on the collected subjects
is not available on their web pages. Finally, the duration of 2 of non-European study programs. Among the considered

VOLUME 9, 2021 94735


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 5. Study programs features: language, ECTS credits and cost in Here, the security area is clearly considered the main basis of
non-European countries. ‘‘NA’’ stands for not available and ‘‘y.’’ for year.
The average cost is given in euro. cybersecurity bachelors, followed by computer science. Note
that in the European analyses, computer science and security
are also of main interest, see Figure 5.
Figure 6 depicts the master curricula analyses, where secu-
rity and humanities grow at the expense of mathematics and
computer science with respect to bachelors charts. The same
behaviour can be found in the European charts, see Figure 6
for more details.
TABLE 6. Non-European practical lectures. ‘‘NA’’ stands for not available. At last, Table 6 shows the percentage of mandatory prac-
tical lectures given in each study program, i.e. the columns
values ‘‘NA’’ and from ‘‘0’’ to ‘‘100’’. In particular, this
is a lower bound of the total taught practical lectures, see
Section IV-A2 for more details. In case, this information is
not available, the related study program is labeled as ‘‘NA’’.
Moreover, the last column of the table shows the average
percentage among the available data. Here the difference is
non-European countries, all curricula are eligible for statis- substantial with respect to the European proposals where
tical analyses. The methodology of the analyses is the same more importance is given to practical lectures.
as described in Section IV-A2. Therefore, percentages are
computed on mandatory subjects and are divided among the B. SUMMARY OF EXISTING PROGRAM ANALYSIS
identified cybersecurity areas, which are computer science, The collected 89 cybersecurity curricula (19 bachelors and
cryptography, humanistic and social science, mathematics, 70 masters) offer a first glimpse at the current world offer in
privacy, and security. cybersecurity education. The study shows how cybersecurity
Figures 7 and 8 depicts the statistical analyses for education is still not standardized and strictly depending
non-European bachelor and master curricula divided by coun- on countries and universities. In several cases, curricula are
try and then unified in the ‘‘Non-Europe’’ chart. These plots jointly taught by different departments/faculties which is due
show how the areas percentages change depending on the to the interdisciplinary nature of cybersecurity that requires
country. However, we are mostly interested in the general involving several areas. Therefore, interdisciplinary curricula
behaviour which is represented in ‘‘Non-Europe’’ charts. should be encouraged.

FIGURE 7. Analysis of non-European cybersecurity bachelor study programs. ‘‘Computer Sc.’’ stands for computer science
area, ‘‘Crypto’’ for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area,
‘‘Security’’ for security area, and ‘‘Privacy’’ for privacy area.

94736 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 8. Analysis of non-European cybersecurity master study programs. ‘‘Computer Sc.’’ stands for computer science area, ‘‘Crypto’’
for cryptology area, ‘‘Humanistic’’ for humanistic and social science area, ‘‘Math’’ for mathematics area, ‘‘Security’’ for security area, and
‘‘Privacy’’ for privacy area.

Furthermore, there is a lack of bachelor study programs subject description (when available) was analyzed to see
focused on cybersecurity. In fact, among 89 cybersecurity if a topic was at least partially covered. Table ‘‘Topics’’
curricula, only 19 bachelors had been found. In order to train in Figure 4 collects this information for one study program.
cybersecurity experts, the students should have the possibility Note that more topics can belong to the same subject.
to study cybersecurity subjects from the first year of their Checking the percentages, a bachelor should include
studies. It is important to notice that all the analyzed bachelors ‘‘Computer Networks’’, ‘‘Computer Systems’’ and ‘‘Funda-
are taught in the native language of the country, therefore, mental of Cryptography’’ topics (strongly recommended),
an internationalization of these curricula is also necessary. and also consider ‘‘Theoretical Computer Science’’,
Regarding cybersecurity areas and topics, computer sci- ‘‘Algebra and Discrete Mathematics’’ and ‘‘Probability and
ence has a primary position among the necessary basic Statistics’’ (suggested). Moreover, the first consideration of
knowledge. In particular, the analyses of European and security topics is suggested. In case of masters, recommen-
non-European bachelors lectures highlight computer science dations are more dependent on the specialization that the
topics as the main fundamental background, followed by study program follows. However, ‘‘Hardware and Software
humanistic and social science, and mathematics. Moreover, Security’’, ‘‘Network Security’’ ‘‘System Security’’ and
security is also a significant component of the training, par- ‘‘Security Management and Risk Analysis’’ are a good
ticularly in non-European curricula. In case of masters cur- starting points for a master in cybersecurity (see Table 7 for
ricula, humanistic and social science, security and cryptology additional details).
are strong components in both European and non-European Last but not least, a solid cybersecurity study program
programs. It is important to notice that privacy still remains should provide ample space for practical lectures. In fact,
an area only partially covered in most of the programs. practical lectures are already strongly present in the analyzed
No substantial difference between European and non- European curricula, where each study program has on aver-
European proposals has been encountered. Among the age 30% practical lectures for bachelors and 40% for masters.
European universities, the diversity of the curricula depends In particular, several universities (i.e. 4 over 15 bachelors and
on the leading department more than on the country itself. 9 over 23 2-year masters) have more than 75% of practical
Furthermore, Table 7 shows how much a topic is taught as lectures. Reflecting the need for practical training, we iden-
a percentage of the collected data. In this case, all (mandatory tify cyber ranges as a promising new technology which gives
and optional) subjects are considered. In particular, each students access to virtual environments where they can train.

VOLUME 9, 2021 94737


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 7. Topics analysis on all the collected curricula. ‘‘B.’’ stands for bachelor and ‘‘M.’’ stands for master.

C. EDUCATION MAP universities to adapt and build their own customized study
This subsection describes the process of creation of a programs in cybersecurity and evaluate their validity with
dynamic web application for the visualization of data describ- respect to the requirements of specific cybersecurity work
ing existing study programs focused on cybersecurity. This roles.
application was developed as a part of the existing study pro-
A. DESIGN METHODOLOGY
grams mapping activity. The web application contains the list
Design of cybersecurity curricula is strongly linked to pre-
of universities and their study programs and provides users
vious activities dealing with SPARTA CSF design and with
with the functionality for viewing, filtering using specific
work by key EU institutions, such as ENISA, European Cyber
criteria and localization of programs/universities on a map.
Security Organization (ECSO), and relies also on inputs
The web application also contains the administration part,
from other Cyber Competence Network (CCN) pilots. The
which can be used by the administrators to add and modify
methodology is depicted in Figure 10, identifying the inputs,
the records about the study programs and universities.
the main activity and the outcomes.
The web application is split into two parts: a client and a
The inputs significantly influence the design process and
server. The client is realized as a front-end Javascript appli-
are described in details. The Curricula Design task involves
cation for data view. Data are collected from the server part
the selection of the topics needed for curricula reflecting the
through the HTTP (Hypertext Transfer Protocol) requests.
actual KSA and their integration into courses to be included
Compared to only PDF reports, the interactive map
in the study programs. The outcomes are good-practice cur-
represents a more interactive and comprehensive way
ricula, i.e. the recommendation on courses to be included in
of results presentation. The app is publicly available at
the study programs and their composition into bachelor’s and
[Link] and is currently dis-
master’s degree programs.
tributed to university students, mostly Erasmus, interested
in international study programs. The home page is shown 1) DESIGN INPUTS
in Figure 9. The inputs that significantly influenced the curricula design
and selection of topics/subjects are the following:
V. METHODOLOGY AND RECOMMENDATIONS ON
CREATING CYBERSECURITY CURRICULA a: SPARTA Cybersecurity Skills Framework
In this section, we describe the methodology for design- The framework links KSA with work roles, thus defines the
ing higher-education study programs in cybersecurity, pro- necessary topics for students planning to work in the cyberse-
vide sample study programs for bachelor’s and master’s curity area. During the creation of the curricula, we used the
degree and give recommendations on creating curricula. pivot concepts of work roles, identifying the typical positions
These guidelines are aimed to support universities in creating on the job market, and competencies, grouping the KSA
their own cybersecurity study programs and serve as a good necessary for work on cybersecurity positions. Using the
practice for such activities. Furthermore, the outputs include CSF, it is possible to easily identify the KSAs necessary for
the SPARTA Curricula Designer Tool, a software that enables individual positions to be included in the study programs.

94738 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 9. Education map application at [Link]

b: Existing programs analysis


In section IV, an extensive analysis of existing study pro-
grams worldwide was delivered. This analysis had significant
conclusions which affect the curricula design. The key
findings are:
• Cybersecurity education has a multidisciplinary nature,
thus various fields should be covered, including
technical, humanistic and social sciences.
• Most of the existing study programs in cybersecurity are
realized at the master’s level. The bachelor’s programs
are less frequent, though cybersecurity is a complex area
deserving focus from the first year of education.
• On the bachelor’s level, usually fundamental and
more generic courses (such as programming, network
FIGURE 10. Methodology for creating cybersecurity curricula.
security, cryptography) are included, while master’s
level allows for more specialization.
• The practical education including hands-on experience
Furthermore, the usage of work roles makes it easier to focus plays an important role in the design of curricula, though
study programs on certain areas in cybersecurity and build only 30% - 40% of existing courses have some form of
customized curricula according to the university profile and practical education.
specific needs. As the university study programs often have • Most EU universities are using the European ECTS
to remain general (in contrast to focused professional train- credit system requiring 180 credits for the bachelor’s
ing) and to cover also fundamental subjects, we do not use degree and 120 credits for the master’s degree. In our
competencies directly, but rather work with SPARTA Topics, recommendation, we will follow these guidelines.
which include also fundamental subjects such as mathe-
matics, electrical engineering and information theory. The c: Curricula Recommendations
SPARTA Topics are mapped to competencies as described There already exist recommendations for creating cyberse-
in Section III. curity curricula, such as the Australian Computer Society

VOLUME 9, 2021 94739


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

Guideline, guidelines from UK’s NCSC, CyBOK or rec- nificant role during the design of our good-practice curricula.
ommendations from computing associations (Section II). The virtualization technologies and training methods based
However, some of these recommendations are from regions on games, involving CTF, Red Blue teaming or table-top
outside EU and need at least some adaptation to the EU exercises should be considered as significant enhancements
environment (e.g., reflecting the EU ECTS system, different of existing training methods and could provide hands-on
legal environment and industry composition). experiences not only for pure technical courses but also for
courses focused, e.g., on legal or social aspects of cybersecu-
d: Related Program Analysis
rity. Another new trend in training is the use of ‘‘bug bounty’’
The analysis of related programs identified supporting tools programs, where cybersecurity trainees are motivated to find
that would make cybersecurity programs more visible, attrac- security vulnerabilities in existing software/hardware and
tive to students and that have the potential to enhance edu- thus improve their skills and knowledge about these systems.
cation and training with new activities. As examples of
emerging tools, we would like to mention the Bug Bounty g: Practical Aspects
platforms, e.g., Intigriti,2 YesWeHack,3 that may motivate
University study programs are usually not designed from
students to do practical exercises involving modern tools
scratch, they are often reusing existing study courses, build-
and technologies. Furthermore, the Massive Open Online
ing upon specific expertise of professors and utilizing par-
Courses (MOOC) can be seen as a suitable supplement to
ticular existing equipment of laboratories. Rather than com-
traditional education methods. To stimulate students and
pletely new composition of courses, the cybersecurity study
make them aware of cybersecurity study programs, compe-
programs are often created as modifications and updates of
titions should be considered, as they proved very useful in
existing study programs in computer science, electrical engi-
large-scale deployments, such as Italian [Link].4
neering, etc. While this decision is not perfect for the course
e: Recommendations from key institutions composition, we need to consider this pragmatic approach
During the curricula creation, recommendations from key EU as it has been identified during our discussion with universi-
partners, such as ENISA and ECSO, have been considered. ties, training institutions and even reviewers as the dominant
In particular, the recommendations included in the ENISA approach.
Cybersecurity Skills Development in the EU report [14] and
the outcome of ECSO Results of Simulation-based Com-
petence Development Survey [9] were considered. Namely,
we explicitly reflected the recommendations on enough cred-
its dedicated to cybersecurity courses, gamification of educa-
tion, presence of lectures from industry representatives, inter-
disciplinarity, international collaboration and prioritization of
hands-on practical training. Besides EU recommendations,
the NIST NICE initiative [20] served as an important source
of information.
f: New trends, tools and opportunities
In addition to the recommendations and the analysis of exist-
ing programs, new trends in cybersecurity and training were
also identified and reflected during the curricula design.
Modern curricula should reflect current research and
development trends in cybersecurity and integrate top-
ics such as quantum technologies, critical infrastructure
protection, IoT technologies, industrial networks, fake FIGURE 11. Cybersecurity program creation using SPARTA CSF and
news, privacy-enhancing technologies and more. We used existing courses.

the official EU’s strategic documents [5] and Horizon Using our methodology based on SPARTA CSF, it is possi-
Europe/Digital Europe program plans [6], [7] for the identi- ble to start with an incomplete backbone consisting of exist-
fication of new trends for our good-practice curricula, but this ing courses and then add new courses reflecting the needs of
task needs to be run individually for each new study program particular work roles to which the study program aims. The
at the actual time of its design. whole process of curricula creation is depicted in Figure 11
Furthermore, a successful study program must also involve and described by the following steps:
modern technologies for education and training. In particular, 1) Identification of existing courses suitable for the
considering cyber ranges for practical training played a sig- program;
2 [Link] 2) Labeling of existing study courses by SPARTA Topics;
3 [Link] 3) Creation of the backbone of the study program, i.e.
4 [Link] selection of existing courses for use;
94740 VOLUME 9, 2021
J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 8. Connection between ‘‘Information Security’’ bachelor study program and NICE competencies.

4) Analysis of Topics, competencies and KSAs provided Our proposal of a good-practice curricula and its analysis
by the backbone program using SPARTA CSF; are presented in several figures and tables:
5) Selection of work roles that are targeted by the study • Tables 12, 13 and 14 in Appendix B depict the cur-
program; riculum, filled with 1st , 2nd and 3rd year courses. This
6) Identification of missing Topics; curriculum has been created taking into account all the
7) Addition of new courses containing necessary Topics; factors described in Section II and including the analyses
8) Finalization and analysis of the program, identification from Section IV.
of supported work roles; • Figure 8 shows the percentage of SPARTA Topics cov-
B. GOOD-PRACTICE CURRICULA ered by the study program and their linking to NICE
In this section, the process of designing cybersecurity bache- competencies. Note that NICE competencies can be
lor’s and master’s study programs is described. This process connected to NICE work roles and vice versa. There-
leads to a dynamic application which allows any university to fore, students and universities may, for instance, know
generate a cybersecurity curriculum from scratch or from an the Topics necessary to become a ‘‘Security Archi-
existing one. tect’’. The connection between NICE competencies
The application permits to analyze and link subjects to and NICE work roles is fully described in SPARTA
cybersecurity SPARTA Topics which are identified as basic D9.1 [27].
cybersecurity knowledge, see Section IV-A for more details. As shown in Table 12, the second column of the template
Moreover, SPARTA Topics are linked to NICE competencies is filled with the desired curriculum subjects, which are five
and therefore, to NICE work roles, see Section III for more and all compulsory for the ‘‘1st year, Winter’’. Optional
details. This last feature allows curricula developers to target subjects (if any) can be listed after the mandatory ones. For
their curricula to the desired work role. instance, the ‘‘Language’’ subject is optional in the ‘‘1st year,
Our application can also be used to analyze an existing Summer’’. One or more SPARTA Topics can be assigned
study program and understand the missing cybersecurity top- to each subject. The assignment will reflect the knowledge
ics. It can thus be used as a tool to transform general study (abilities, skills) covered. The points assigned to each subject
programs into cybersecurity ones. is exactly 1 and this value can be split into several SPARTA
As shown in Section IV, there is a lack of bachelor study Topics assigning them 0.25, 0.5, 0.75 or 1. These values
programs focused on cybersecurity (only 19 bachelors over represent the subject ratio dedicated to the related SPARTA
89 analyzed cybersecurity curricula). Therefore, bachelor’s Topic. For instance, the ‘‘Mathematics 1’’ subject equally
programs are of our particular interest. covers ‘‘Algebra and Discrete Mathematics’’ and ‘‘Topology
The analyses of bachelors’ topics shows that computer and Analysis’’ Topics.
science is a fundamental component, followed by humanities, The third column in the table allows to assign the ECTS
social science, and mathematics. These areas are particularly credits to each subject. Following the European standard,
important in bachelor’s curricula since they cover the basic a bachelor study program should have 180 credits, and there-
skills necessary for the understanding of any future cyber- fore around 30 credits per semester.
security study. Accordingly, an appropriate balance between Tables 13 and 14 depict 2nd and 3rd years of our
these topics should be considered when designing a study good-practice bachelor program. In particular, Table 14 has
program. the summary of the assigned ECTS credits to each SPARTA

VOLUME 9, 2021 94741


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

FIGURE 12. Curricula designer.

FIGURE 13. SPARTA topics and NICE competencies necessary to become a Database Administrator marked in blue and red. Red
competencies and topics are the ones to be added to ‘‘Information Security’’ bachelor curriculum in order to become a Database
Administrator.

Topic and according to the SPARTA Area. In particular, Note that the ECTS credits are assigned in 20% to Human-
the row ‘‘Total’’ collects the ECTS credits of each SPARTA istic and Social Science, 16% to Computer Science, and 17%
Topic and the related percentage. to Mathematics according to the suggested balance among

94742 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 9. List of analyzed cybersecurity study programs.

TABLE 10. Higher-education entities that run a study program in cybersecurity in Europe. ‘‘y.’’ stands for year.

these main areas as shown in Section IV-B. Furthermore, C. CURRICULA DESIGNER


the Security area strictly follows with 16%. To make the design of cybersecurity curricula easier,
The total proportion between compulsory and optional a dynamic web application for the individual study curric-
subjects is also of relevance. In this case, a total of 78% of ula was developed within the SPARTA project. The web
ECTS credits are compulsory and 22% are left as elective application allows users to add their own study courses and
among the subjects taught. As in many study programs, once then, using the drag and drop method, compose the curricula
the basic knowledge is acquired, students have the possibility of a Bachelor’s degree program. Besides the study program
to partially direct their study towards a specific cybersecu- composition, the application provides statistical data about
rity area, and therefore towards the desired work role. In the coverage of SPARTA Topics and, more importantly, about
fact, the application also allows to see which Topics need the work roles supported by the study program. Using the
to be covered in order to acquire certain NICE competen- tool and its internal evaluation methods based on the SPARTA
cies, and therefore the desired NICE work role. An exam- CSF, it is possible to analyze and modify the program to have
ple analysis for the Database Administrator Work Role is it reflecting the actual needs of specific work roles.
shown in Figure 13 based on the requirements from the NICE The web application is developed using JavaScript
Framework shown in Figure 14 in Appendix A. (ECMAScript 6) with the React framework, Syntactically

VOLUME 9, 2021 94743


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 11. List of analyzed cybersecurity study programs.

FIGURE 14. NICE Framework showing NICE competencies and NICE work roles for Database Administrator.

Awesome Style Sheets Cascading Style Sheets (SASS CSS) Finally, in the Statistics section on the right side, the
pre-processor and NPM package manager. following information is visualized:
The left section of the tool (see Figure 12) contains the list • a pie chart with the distribution of SPARTA Areas
of courses. New courses can be added and edited here. The supported by the program,
courses are visualized as floating cards, which can be moved • a table with the percentage distribution of ECTS credits
using the mouse (‘‘drag and drop’’) to a concrete position covering particular SPARTA Topics in the program,
in the curricula in the middle section. The systems marks • a list of the work roles currently supported by the study
the areas to which the courses may be dropped. Using the program according to NICE.
information about the course, the system prevents the user
from dropping the course to a wrong semester. VI. CONCLUSION
The curricula component allows one to export user-defined In this article, we have proposed an approach to reduce the
curricula to a file that may be used in future sessions, to get gap between the supply of cybersecurity experts and the need
back to previously saved work. of industries and society. In particular, using SPARTA CSF

94744 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

TABLE 12. Example of 1st year of bachelor study program.

TABLE 13. Example of 2nd year of bachelor study program.

TABLE 14. Example of 3rd year of bachelor study program.

we have linked cybersecurity education to work roles. The Moreover, a tool for visualizing the collected data in an
mapping enables us to identify the topics that are fundamental interactive map has been developed. Our dynamic web appli-
for a cybersecurity carrier. Moreover, it permits comparing cation can help students when looking for a cybersecurity
existing study programs, improving them, and producing study program. Finally, related program analysis, SPARTA
guidelines for the creation of new cybersecurity curricula. CSF, and curricula recommendations are used to design
Indeed, a sample of 89 cybersecurity study programs was good-practice higher-education study programs in cybersecu-
analyzed in order to produce an overview of cybersecurity rity and propose a cybersecurity curricula designer tool. The
disciplines and topics. The analyses show that 23% of the tool automatically analyses curricula and discovers missing
curricula are taught jointly and involve multiple faculties. topics and/or unsupported work roles and thus helps program
This collaboration is due to the interdisciplinary nature of administrators to design study programs reflecting the cyber-
cybersecurity. Furthermore, we have argued that there is a security job market requirements.
lack of Bachelor’s study programs focused on cybersecurity In the future, we would like to continue to update the
(just 19 of the 89 courses we have considered). In order to SPARTA CSF to reflect new trends and directions in cyber-
train more cybersecurity experts, a more significant number security. A batch of new competencies will be added to
of students need to have the possibility to study cybersecurity reflect also interdisciplinary aspects. Furthermore, we plan
subjects from the first year of their careers. to extend the tools, and specifically the Curricula Designer,

VOLUME 9, 2021 94745


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

to support more Cybersecurity Skills Frameworks (hopefully [18] J. Hallett, R. Larson, and A. Rashid, ‘‘Mirror, mirror, on the wall:
the EU CSF when it is ready) and to add functionality for What are we teaching them all? Characterising the focus of cyberse-
curity curricular frameworks,’’ in Proc. USENIX Workshop Adv. Secur.
professional training design. Educ., W.-C. Feng and A. L. Podhradsky, Eds., Baltimore, MD, USA:
USENIX Association, Aug. 2018, pp. 1–9. [Online]. Available: https://
[Link]/conference/ase18/presentation/hallett
APPENDIX A [19] NCSC. (2019). NCSC Degree Certification—Call for New Appli-
CURRICULA ANALYSIS cants. [Online]. Available: [Link]
See Tables 9–11 and Figure 14. degree-certification-call-new-applicants-0
[20] R. Petersen, D. Santos, M. C. Smith, K. A. Wetzel, and G. Witte.
(Nov. 2020). NIST Special Publication 800-181 Revision 1: Work-
APPENDIX B force Framework for Cybersecurity (NICE Framework). [Online]. Avail-
GOOD-PRACTICE CURRICULA able: [Link]
[Link]
See Tables 12–14. [21] NIST. (Jul. 2020). NICE Framework Supplemental Material. [Online].
Available: [Link]
framework-resource-center/nice-framework-supplemental-material
REFERENCES [22] NSA. (2019). National Centers of Academic Excellence in Cyber Defense
[1] (2017). ACM, IEEE, AIS SIGSEC & IFIP. ACM/IEEE/AIS Education Program (CAE-CDE) Criteria for Measurement Bachelor, Mas-
SIGSEC/IFIP Cybersecurity Curricular Guideline CSEC 2017. [Online]. ter, and Doctoral Level. [Online]. Available: [Link]
Available: [Link] documents/Requirements/CAE_CDE_criteria.pdf
newcover_csec2017.pdf [23] NSA. (2019). Academic Requirements for Designation as a CAE
[2] Australian Computer Society. (2015). The ACS Core Body of Knowledge in Cyber Operations Fundamental. [Online]. Available: https://
for ICT Professionals CBOK. [Online]. Available: [Link] [Link]/Resources/Students-Educators/centers-academic-
au/content/dam/acs/acs-skills/The-ACS-Core-Body-of-Knowledge-for- excellence/cae-co-fundamental/requirements/
[Link] [24] NSA. (2019). National Centers of Academic Excellence. [Online].
[3] Australian Computer Society. (Oct. 2019). ACS—The Professional Asso- Available: [Link] students-educators/centers-
ciation for Australia’s ICT Sector. [Online]. Available: [Link] academic-excellence/
[Link]/ [25] A. Rashid, H. Chivers, G. Danezis, E. L. Imperial, and A. Martin.
[4] (2017). Australian Government—Department of Education. Academic (Oct. 2019). The Cyber Security Body Of Knowledge. [Online]. Available:
Centres of Cyber Security Excellence Program Guidelines. [Online]. Avail- [Link]
able: [Link] accse_program [26] SFIA Foundation. (2018). The SFIA Framework. [Online]. Available:
_guidelines_february_2017_final.pdf [Link]
[5] ENISA. (2021). Exploring Research Directions in Cybersecurity. [Online]. [27] SPARTA. D9.1—Cybersecurity Skills Framework. Accessed: Jun. 1, 2021.
Available: [Link] [Online]. Available: [Link]
research-directions-in-cybersecurity. [Link]
[6] European Commision. (2021). Horizon Europe. [Online]. Available: [28] SPARTA. D9.2—Curricula Descriptions. Accessed: Jun. 1, 2021.
[Link] [Online]. Available: [Link]
[Link]
[7] European Commision. (2021). Digital Europe. [Online]. Available: https:
[29] (2020). The Times Higher Education World University Rankings. [Online].
//[Link]/en/activities/digital-programme
Available: [Link]
[8] (Oct. 2019). Australian Government—Department of Education. Academic
rankings/2020/world-ranking#!/page/0/length/25/sort_by/rank/sort_
Centres of Cyber Security Excellence (ACCSE). [Online]. Available: https:
order/asc/cols/stats
//[Link]/academic-centres-cyber-security-excellence-
[30] UK Government. (2019). The National Cyber Security Centre. [Online].
accse.
Available: [Link]
[9] (2020). ECSO, Report: Results of Simulation-Based Competence [31] (2021). SPARTA H2020 Project: Special Projects for Advanced Research
Development Survey. [Online]. Available: [Link] and Technology in Europe. [Online]. Available: [Link]
documents/publications/[Link]
[10] (2020). University of Bristol, MSc Mathematics of Cybersecurity. [Online].
Available: [Link]
mathematics-of-cybersecurity/
[11] CEP. (Oct. 2019). The Cyber Education Project. [Online]. Available:
[Link]
[12] (2018). ECSO: Gaps in European Cyber Education and Profes-
sional Training. [Online]. Available: [Link]
publications/[Link]
[13] (2017). ENISA: Stocktaking of Information Security Training
Needs in Critical Sectors. [Online]. Available: [Link]
[Link]/news/enisa-news/stocktaking-of-information-security-training-
needs-in-critical-sectors
[14] (Mar. 26, 2020). ENISA. Cybersecurity Skills Development in the EU.
JAN HAJNY is currently an Associate Professor
[Online]. Available: [Link]
with the Faculty of Electrical Engineering and
of-cyber-security-education-in-the-european-union
Communication, Brno University of Technology,
[15] ENISA. Cybersecurity Higher Education Database. Accessed:
Jun. 1, 2021. [Online]. Available: [Link]
Czech Republic. He is the Co-Founder and the
cybersecurity-education/education-map Leader of the Cryptology Research Group, where
[16] (2019). (ISC)2 : Cyber Security Workforce Study 2019: Strategies for Build- he is responsible for managing the Information
ing and Growing Strong Cyber Security Teams. [Online]. Available: https:// Security Study Program. He is the author of more
[Link]/Research/-/media/6573BE9062B64FC7B4B91F20ECC5 than 80 scientific publications. He deals with
[Link] privacy-enhancing cryptographic systems. His
[17] Rupert Grayston. (Aug. 2019). Specialist Accreditation in Cyber Security. research is focused on the design of new authen-
[Online]. Available: [Link] tication protocols, credential schemes, and privacy-protection systems. He is
accreditation/ACS%20Information%20Sheet%20- also responsible for IT infrastructure benchmarking, stress testing, security
%20Cyber%20Security%20Specialist%20Accreditation%[Link] audits, penetration testing, and vulnerability scanning.

94746 VOLUME 9, 2021


J. Hajny et al.: Framework, Tools and Good Practices for Cybersecurity Curricula

SARA RICCI received the [Link]. degree in LETTERIO GALLETTA is currently an Assistant
mathematics from the University of Pisa, Italy, Professor with the IMT School for Advanced Stud-
and the Ph.D. degree in computer engineering ies and a member of the CINI National Laboratory
and mathematics security from Universitat Rovira for Cybersecurity. Previously, he held a postdoc-
i Virgili, Spain. She is currently a Postdoctoral toral position with the Department of Computer
Researcher with the Brno University of Tech- Science, University of Pisa. His research activity
nology, Czech Republic. Her research interests mainly focuses on language-based security, and
include theoretical cryptography, in particular using techniques from programming languages,
lattice-based and elliptic curve cryptography, and compilers, and formal verification to address secu-
data privacy and security. She is also focused on rity problems. He applied these techniques to
the design of new privacy-preserving cryptographic protocols and their different fields, like adaptive software, the Internet of Things, secure
security analyses. compilation, firewalls, and smart contracts.

EDMUNDAS PIESARSKAS is currently an


Expert in different management aspects of cyber
security, including innovation governance and
ROCCO DE NICOLA is currently a Full Professor
skills management, working with the Lithuanian
with the IMT School for Advanced Studies Lucca.
Cybercrime Center of Excellence for Training,
He has been working with the Università di
Research and Education (L3CE), a non-profit
Firenze, Sapienza, Università di Roma, and IEI-
NGO which invests in technology, conducts
CNR, Pisa. He has been a Visiting Professor with
research, and manages projects, focusing on illegal
Ecole Normale Supérieure, Paris, and the Ludwig
interference incidents—related to data, systems,
Maximilian University of Munich. He is a member
and operation of computers—affecting a wide
of the Academia Europaea and has been appointed
range of foreign countries.
as the Commander of the Order of Merit of the
Italian Republic by the President of the Italian
OLIVIER LEVILLAIN is currently an Associate Professor in cybersecurity Republic. He is also the Vice Director of the CINI National Laboratory for
with Télécom SudParis. Before that, he has been in charge of the Cybersecu- Cybersecurity. His research is concerned with the foundations of distributed
rity Training Center, ANSSI (the French cybersecurity agency). He also used computing, the formal specification and checking of qualitative and quan-
to work in ANSSI laboratories on various subjects, ranging from attacks on titative properties of systems, and the protection of distributed systems and
low-level hardware mechanisms to public key infrastructures. More recently, computer networks and has led to more than 250 publications in journals or
he has been working on secure network protocols and on programming books.
languages.

VOLUME 9, 2021 94747

You might also like