Cybersecurity is becoming an important element in curricula at all education levels. However, the foundational knowledge on which the field of cybersecurity is being developed is frag- mented, and as a result, it can be difficult for both students and educators to map coherent paths of progression through the subject. By comparison, mature scientific disciplines like mathematics, physics, chemistry, and biology have established foundational knowledge and clear learning pathways. Within software engineering, the IEEE Software Engineering Body of Knowledge [1] codifies key foundational knowledge on which a range of educational pro- grammes may be built. There are a number of previous and current efforts on establishing skills frameworks, key topic areas, and curricular guidelines for cybersecurity. However, a consensus has not been reached on what the diverse community of researchers, educators, and professionals sees as established foundational knowledge in cybersecurity.
The Cybersecurity Body of Knowledge (CyBOK) aims to codify the foundational and generally recognised knowledge on cybersecurity. In the same fashion as SWEBOK, CyBOK is meant to be a guide to the body of knowledge; the knowledge that it codifies already exists in literature such as textbooks, academic research articles, technical reports, white papers, and standards. Our focus is, therefore, on mapping established knowledge and not fully replicating everything that has ever been written on the subject. Educational programmes ranging from secondary and undergraduate education to postgraduate and continuing professional development programmes can then be developed on the basis of CyBOK.
This introduction sets out to place the 21 Knowledge Areas (KAs) of the CyBOK into a coherent overall framework. Each KA assumes a baseline agreement on the overall vocabulary, goals, and approaches to cybersecurity, and here we provide that common material which underpins the whole body of knowledege. We begin with an overview of cybersecurity as a topic, and some basic definitions, before introducing the knowledge areas. The KAs and their groupings into categories are, of course, not orthogonal and there are a number of dependencies across the KAs which are cross-referenced and also separately captured visually on the CyBOK web site (https://www.cybok.org). We then discuss how the knowledge in the KAs can be deployed to understand the means and objectives of cybersecurity, mitigate against failures and incidents, and manage risks.
Although we have necessarily divided the CyBOK into a number of discrete Knowledge Areas (KAs), it is clear that there are many inter-relationships among them. Those with professional responsibility for one area must typically have at least a moderate grasp of the adjacent topics; someone responsible for architecting a secure system must understand many. There are a number of unifying principles and crosscutting themes that underpin the development of systems that satisfy particular security properties. We conclude the introduction by discussing some of these.
Course Content
