<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">Map ping Foundational Knowledge in Cybersecurity</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author role="corresp">
							<persName><forename type="first">Kalinka</forename><surname>Kaloyanova</surname></persName>
							<email>kkaloyanova@fmi.uni-sofia.bg</email>
							<affiliation key="aff0">
								<orgName type="department">Faculty of Mathematics and Informatics</orgName>
								<orgName type="institution">University of Sofi a St</orgName>
								<address>
									<addrLine>Kliment Ohridski, 5 James Bourchier Blvd</addrLine>
									<postCode>1164</postCode>
									<settlement>Sofi a</settlement>
									<country key="BG">Bulgaria</country>
								</address>
							</affiliation>
							<affiliation key="aff1">
								<orgName type="department">Institute of Mathematics and Informatics</orgName>
								<orgName type="institution" key="instit1">Bulgarian Academy of Sciences</orgName>
								<orgName type="institution" key="instit2">Acad. G</orgName>
								<address>
									<addrLine>Bonchev Str., Block 8</addrLine>
									<postCode>1113</postCode>
									<settlement>Sofi a</settlement>
									<country key="BG">Bulgaria</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">Map ping Foundational Knowledge in Cybersecurity</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">D337EFE4AED50EAD125B1C0C22B4668D</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-24T06:58+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>information security</term>
					<term>cybersecurity</term>
					<term>curricula</term>
					<term>CSEC2017</term>
					<term>Cyber Security Body of Knowledge (CyBOK)</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>Various cybersecurity curricular guidelines were announced during the last several years. These are the results from common efforts of many organizations, universities, professional bodies, practitioners, etc. This paper considers fundamental cybersecurity knowledge and its presentation in order to help educators to prepare new educational programs.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1">Introduction</head><p>In recent years, many universities have been included cybersecurity as an important element at different levels of their education programs. Various courses and completed programs were developed. They are based on the basic recommendations provided by a number of cybersecurity frameworks and educational guidelines, produced from different professional organizations, academic and practitioners. As different frameworks emphasize different topics, a complex view on the fundaments in cybersecurity is needed. Cyber Security Body of Knowledge (CyBOK), version 1.0, announced at the end of 2019, presents such a comprehensive understanding of foundational cybersecurity knowledge and provide it into several main categories and a number of knowledge areas <ref type="bibr" target="#b0">[1]</ref>.</p><p>In this paper, we discuss the main categories and knowledge areas recognized by CyBOK, and their correspondence to the educational requirements at university level. The last ones are best represented through the CSEC2017 curriculum <ref type="bibr" target="#b2">[3]</ref>.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2">Cyber Security Frameworks and Guidelines</head><p>The most widely accepted standard for information security -ISO/IEC 27000 provides organizations with the basic requirements of how to develop and implement their information security management systems <ref type="bibr" target="#b9">[10]</ref>. A lot of major concepts, measures and implementation issues in cybersecurity are discussed in the ISO/IEC 27000 series and could be successfully used in delivering education in the fi eld <ref type="bibr" target="#b12">[13]</ref>. In a number of countries, the development of national cybersecurity programs has begun <ref type="bibr" target="#b13">[14]</ref>, <ref type="bibr" target="#b15">[16]</ref>.</p><p>Many project and common efforts of different groups of educators, practitioners, national and professional organizations led to the publication of a number of frameworks and guidelines in cybersecurity. Widespread among them are the NICE Cybersecurity Workforce Framework, published by the U.S. National Initiative on Cybersecurity Education (NICE) <ref type="bibr" target="#b11">[12]</ref>, the National Centers of Academic Excellence in Cyber Defense (CAE-CD) Designation Program Guidance <ref type="bibr" target="#b10">[11]</ref>, IISP Knowledge Framework <ref type="bibr" target="#b8">[9]</ref>.</p><p>Several cybersecurity curricula were also announced. The Cybersecurity Curricular Guideline CSEC2017 presents the result of the work of several organizations -ACM, IEEE Computer Society, AIS SIGSEC, and IFIP WG 11 <ref type="bibr" target="#b3">[4]</ref>. The curriculum recommendations provided here could be used to supplement the established computer science and computer engineering disciplines <ref type="bibr" target="#b2">[3]</ref>.</p><p>The Cybersecurity: A Generic Reference Curriculum is "the result of the work of multinational team of volunteer academics and researchers drawn from 17 nations associated with Partnership for Peace Consortium (PfPC) Emerging Security Challenges Working Group" <ref type="bibr" target="#b4">[5]</ref>. The generic guidelines provided by all these documents can be used when particular programs and courses are created for scholars, students and workers.</p><p>Among the various cybersecurity frameworks and guidelines, CSEC2017 <ref type="bibr" target="#b2">[3]</ref> could be most easily adopted for a university cybersecurity program <ref type="bibr" target="#b10">[11]</ref>. First, it is more acceptable for universities due to the close connections with other computing curricula that are periodically defi ned by ACM (Association for Computing Machinery), IEEE (Institute of Electrical and Electronics Engineers), and AIS (Association for Information Systems) <ref type="bibr" target="#b4">[5]</ref>. Second, it provides recommendations using traditional categories like knowledge areas, knowledge units, topics, etc.</p><p>Due to the rapid development of cybersecurity, the basic knowledge in this fi eld is not well structured, yet. Plenty of books, scientifi c and white papers, blogs, etc. presents different aspects of the fi eld <ref type="bibr" target="#b7">[8]</ref>. It is not easy for teachers, students and even professionals to choose the most appropriate resources that should be used for each specifi c case, even when they follow curricula recommendations <ref type="bibr" target="#b14">[15]</ref>, <ref type="bibr" target="#b16">[17]</ref>.</p><p>Cyber Security Body of Knowledge (CyBOK) is trying to fi ll this gap exploring and systemizing the knowledge obtained from the existing resources (papers, technical documents, standards, reports, etc.) that can assist cybersecurity education. As CyBOK v.1.0 identifi es defi nitions, explanation, examples in cybersecurity area, it complements other curricula recommendations and assists educators in creating new cybersecurity educational units.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3">CyBOK -Cyber Security Body of Knowledge</head><p>While most of the above presented documents and frameworks, especially curricula guidelines, aim to develop cybersecurity educational programs, the main goal of the Cyber Security Body of Knowledge (CyBOK) <ref type="bibr" target="#b0">[1]</ref> project is to systemize the existing knowledge in the fi eld and to serve as common information resource for these educational programs. To achieve its main goal, the current version -CyBOK v1.0 determines a number of knowledge areas (KA) grouped under the following fi ve categories <ref type="bibr" target="#b6">[7]</ref>:</p><p>• Human, Organizational and Regulatory aspects;</p><p>• Attacks and Defenses;</p><p>• Software and Platform Security;</p><p>• System Security;</p><p>• Infrastructure Security.</p><p>All categories consist of four knowledge areas, except Software and Platform Security category, which consists of three.</p><p>Security management systems and organizational security controls are the focus of the fi rst category -Human, Organizational and Regulatory aspects. Formulating four substantial knowledge areas -Risk Management and Governance, Law and Regulation, Human Factors and Privacy and Online Rights, this category addresses the security issues at the organizational level. Also is addressed the application of instruments like procedures, standards, organizational policies to mitigate risks.</p><p>The second category Attack and Defense refers to more technical issues and analyses. The technical aspects of computer attacks and malicious software and hardware are discussed in Malware and Attack Technologies knowledge area. The next knowledge area Adversarial Behaviors presents specifi c aspects of cybercrime such as behavior of the attackers, their motives and methods used and cybercrime relation with economics and society. The technical aspects of operational security (system management, security monitoring) and how to respond to the incident management are covered by Security Operations &amp; Incident Management. The last knowledge area in this category -Forensics, concerns the work with digital evidence of security events and crimes.</p><p>Software engineering and security aspects are in the focus of Software and Platform Security category. The role of the security in the system development life cycle is marked in Secure Software Lifecycle knowledge area. Specifi c programming practices leading to security faults and techniques improving software security are the subject of knowledge area Software Security. In addition, particular issues concerning security of web application are Web and Mobile Security.</p><p>The Systems security category introduce fundamental concepts of cryptography, algorithms, and proof techniques through the Cryptography knowledge area. The other KA -Operating Systems and Virtualization Security presents the protection mechanism to ensure the security at operation systems level. The case security issues of different large-scale distributed systems were discussed in more details the Distributed Systems Security area. The Authentication, Authorization &amp; Accountability knowledge area focuses on the identifi cation management discussing technics and technologies for user identifi cation and user authorization.</p><p>Network Security, Hardware Security, Cyber-Physical Systems Security and Physical Layer Security knowledge areas belong to the Infrastructure security category. Each of these four knowledge areas cover security issues at different sides of the physical infrastructure -hardware security, different computational devices, networking and telecommunications protocols, etc.</p><p>The chosen topics demonstrate not only the breath of scope CyBOK, but also the signifi cant efforts to fi nding a balance between the more rigorous academic forms and the practical orientation, demanded by the industry.</p><p>Despite the presenting variety of topics, this is not the last version of the CyBOK and the process for change requests have already started <ref type="bibr" target="#b1">[2]</ref>.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="4">A Comparison of the frameworks</head><p>As the nineteen CyBOK knowledge areas are organized into fi ve categories these categories could be easily used for the correspondence with the eight knowledge areas of CSEC2017 curricula. This comparison is presented in Table <ref type="table" target="#tab_0">1</ref>. Even at such high-level, the parallel, presented in Table <ref type="table" target="#tab_0">1</ref>, demonstrates that CyBOK categories and knowledge areas could be successfully used as a basis for comparison with CSEC 2017 knowledge areas <ref type="bibr" target="#b2">[3]</ref>.</p><p>As the CSEC2017 knowledge areas are further broken down into knowledge units, these units could be used for the next step of the compliance. The topics in CSEC2017, present more detailed pieces of knowledge (Attacks, Malware, Forensics, Cryptography, etc.) and they could be used for fi nding correspondence within the content of CyBOK knowledge areas. In some cases, the CSES2017 essentials, listed at the beginning of each KA could be used to fi nd parallels, as they present the essential concepts presented in units and modules.</p><p>We applied this approach in the case of CSEC2017 knowledge area Component Security -it does not match directly to any of the CyBOK categories. Instead, we could fi nd the correspondence with the Security Operations &amp; Incident Management, which is a part of Attacks and Defenses Category, as well with particular elements from other areas. For example, supply chain management (one of the essentials of Component security) is discussed in CyBOK within the Adversarial Behaviors area.</p><p>It can be seen that CSEC 2017 content is fully addressed by the CyBOK knowledge areas. The topics are covered in a balanced manner. In the case, where specifi c knowledge is needed, the CyBOK presents the latest research in the fi eld. For example, in Cryptography contemporary theoretical results in quantum algorithms and calculations are examined.</p><p>Not only technical, but also human, organizational and law aspects are explored in both documents. The CyBOK provides an international perspective on regulatory requirements and online rights, but it lists noted technologies for protecting data and user privacy. In this way, it draws attention to wider sociotechnical view and covers the issues, discussed in the last tree CSEC2017 areas.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="5">Conclusions</head><p>In this paper, we explore the CyBOK approach for knowledge areas in cybersecurity and show its applicability to educational process. As a comprehensive store of established knowledge sets, including papers, documents and many other references, it is the best starting point for universities and other academic institutions when creating their educational programs. The presented accordance with CSEC2017 will assists educators in preparing courses and other teaching materials. For all organizations, it could be a good foundation to enhance their own IT security management.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" type="table" xml:id="tab_0"><head>Table 1 . CSEC 2017 &amp; CyBOK comparison CSEC2017 Knowledge areas CyBOK 2019 Categories CyBOK 2019 Knowledge areas</head><label>1</label><figDesc></figDesc><table><row><cell>Data security</cell><cell>Attacks and Defences</cell><cell>Malware &amp; Attack Technologies</cell></row><row><cell></cell><cell></cell><cell>Adversarial Behaviours</cell></row><row><cell></cell><cell></cell><cell>Security Operations &amp; Incident</cell></row><row><cell></cell><cell></cell><cell>Management</cell></row><row><cell></cell><cell></cell><cell>Forensics</cell></row><row><cell>System security</cell><cell>Systems security</cell><cell>Cryptography</cell></row><row><cell></cell><cell></cell><cell>Operating Systems &amp; Virtualisation</cell></row><row><cell></cell><cell></cell><cell>Security</cell></row><row><cell></cell><cell></cell><cell>Distributed Systems Security</cell></row><row><cell></cell><cell></cell><cell>Authentication, Authorisation &amp;</cell></row><row><cell></cell><cell></cell><cell>Accountability</cell></row></table></figure>
		</body>
		<back>

			<div type="acknowledgement">
<div xmlns="http://www.tei-c.org/ns/1.0"><head>Acknowledgements</head><p>This paper is partially supported by the National Scientifi c Program "Information and Communication Technologies for a Single Digital Market in Science, Education and Security (ICTinSES)", fi nanced by the Ministry of Education and Science.</p></div>
			</div>

			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<monogr>
		<author>
			<persName><forename type="first">About</forename><surname>Cybok</surname></persName>
		</author>
		<ptr target="https://www.cybok.org/about/" />
		<title level="m">Aims of the CyBOK project</title>
				<imprint>
			<date type="published" when="2020-05-11">2020/05/11</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<monogr>
		<ptr target="https://www.cybok.org/news/change-requests-now-welcome" />
		<title level="m">Change-requests-now-welcome</title>
				<imprint>
			<date type="published" when="2020-03-25">2020/03/25</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<monogr>
		<ptr target="https://www.acm.org/binaries/content/assets/education/curricula-recommendations/csec2017.pdf" />
		<title level="m">Cybersecurity Curricula 2017 Curriculum Guidelines for Post-Secondary Degree Programs in Cybersecurity</title>
				<imprint>
			<date type="published" when="2017">CSEC2017. 2020/04/21</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<monogr>
		<title/>
		<author>
			<persName><surname>Csec_Overview</surname></persName>
		</author>
		<ptr target="http://www.ncsl.org/documents/taskforces/CSEC_Overview.pdf" />
		<imprint>
			<date type="published" when="2020-04-22">2020/04/22</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<monogr>
		<ptr target="https://www.acm.org/education/curricula-recommendations" />
		<title level="m">Curricula Recommendations</title>
				<imprint/>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<monogr>
		<ptr target="https://pfp-consortium.org/index.php/pfpc-products/education-curricula/item/262-cybersecurity-reference-curriculum" />
		<title level="m">A Generic Reference Curriculum</title>
				<imprint>
			<date type="published" when="2020-04-08">2020/04/08</date>
		</imprint>
		<respStmt>
			<orgName>Cybersecurity</orgName>
		</respStmt>
	</monogr>
</biblStruct>

<biblStruct xml:id="b6">
	<monogr>
		<title/>
		<author>
			<persName><forename type="first">V</forename><surname>Cybok</surname></persName>
		</author>
		<ptr target=".CyBOK_version_1.0_YMKBy7a.pdf" />
		<imprint>
			<date type="published" when="2020-02-18">2020/02/20. 2020/02/18</date>
			<biblScope unit="volume">1</biblScope>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b7">
	<analytic>
		<title level="a" type="main">Semantics of Vulnerabilities and Intelligent Search</title>
		<author>
			<persName><forename type="first">V</forename><surname>Dimitrov</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Computer and Communications Engineering</title>
		<imprint>
			<biblScope unit="volume">13</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="20" to="25" />
			<date type="published" when="2019">2019</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b8">
	<monogr>
		<ptr target="https://www.iisp.org/imis15/iisp/About_Us/Our_Knowledge_Framework/iisp/About_Us/Our_Knowledge_Framework.aspx?hkey=6e8644f9-fc2f-4f53-9784-b0fb2dba5e8b" />
		<title level="m">IISP Knowledge Framework</title>
				<imprint>
			<date type="published" when="2017">2017. 2020/04/21</date>
		</imprint>
		<respStmt>
			<orgName>IISP</orgName>
		</respStmt>
	</monogr>
	<note type="report_type">Report</note>
</biblStruct>

<biblStruct xml:id="b9">
	<monogr>
		<idno>ISO/IEC 27000:2018</idno>
		<title level="m">E): Information technology -Security techniques -Information security management systems -Overview and vocabulary. Standard. ISO/IEC</title>
				<meeting><address><addrLine>Switzerland</addrLine></address></meeting>
		<imprint/>
	</monogr>
</biblStruct>

<biblStruct xml:id="b10">
	<monogr>
		<ptr target="http://www.iad.gov/NIETP/CAERequirements.cfm" />
		<title level="m">NIETP programs</title>
				<imprint>
			<date type="published" when="2020-04-19">2020/04/19</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b11">
	<monogr>
		<author>
			<persName><forename type="first">William</forename><surname>Newhouse</surname></persName>
		</author>
		<idno type="DOI">10.6028/NIST.SP.800-181</idno>
		<ptr target="https://doi.org/10.6028/NIST.SP.800-181" />
		<title level="m">National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework</title>
				<imprint>
			<date type="published" when="2017">2017</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b12">
	<analytic>
		<title level="a" type="main">Introducing Information Security Concepts and Standards in Higher Education</title>
		<author>
			<persName><forename type="first">D</forename><surname>Orozova</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><surname>Kaloyanova</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Todorova</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">TEM Journal</title>
		<imprint>
			<biblScope unit="volume">8</biblScope>
			<biblScope unit="issue">3</biblScope>
			<biblScope unit="page" from="1017" to="1024" />
			<date type="published" when="2019-08">August 2019</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b13">
	<analytic>
		<title level="a" type="main">Computer crime forms and mechanism for security and protection</title>
		<author>
			<persName><forename type="first">S</forename><surname>Savoska</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Tozievska</surname></persName>
		</author>
		<ptr target="CEUR-WS.org,onlineCEUR-WS.org/Vol-2464/paper7.pdf" />
	</analytic>
	<monogr>
		<title level="m">Proc. of ISGT2018</title>
				<meeting>of ISGT2018<address><addrLine>Sofi a, Bulgaria</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2018">November 16-17, 2018. 2020/02/18</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b14">
	<analytic>
		<title level="a" type="main">Academic Support to Cyber Resilience: National and Regional Approach</title>
		<author>
			<persName><forename type="first">V</forename><surname>Shalamanov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Penchev</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Computer and Communications Engineering</title>
		<imprint>
			<biblScope unit="volume">13</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="73" to="80" />
			<date type="published" when="2019">2019</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b15">
	<analytic>
		<title level="a" type="main">Cyber Threat Map for National and Sectoral Analysis</title>
		<author>
			<persName><forename type="first">G</forename><surname>Sharkov</surname></persName>
		</author>
		<author>
			<persName><surname>Papazov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><surname>Todorova</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Koykov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Georgiev</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Zahariev</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Computer and Communications Engineering</title>
		<imprint>
			<biblScope unit="volume">13</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="29" to="32" />
			<date type="published" when="2019">2019</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b16">
	<analytic>
		<title level="a" type="main">Framework for the Development of Cybersecurity Training Programs for Students of Engineering Specialties, Related to Computer Systems and Information Technologies</title>
		<author>
			<persName><forename type="first">R</forename><surname>Trifonov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">O</forename><surname>Nakov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Manolov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Popov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Tsochev</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Pavlova</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Computer and Communications Engineering</title>
		<imprint>
			<biblScope unit="volume">13</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="65" to="68" />
			<date type="published" when="2019">2019</date>
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
