The Cyber Security Body of Knowledge (CyBOK)
The independent, community-built foundation of cyber security knowledge that underpins the Eristotle Certified Cyber Security Professional pathway.
A Foundation We Reference, Not One We Own
The Cyber Security Body of Knowledge (CyBOK) is an independent project developed by the University of Bristol and funded by the UK National Cyber Security Centre. It codifies the foundational knowledge that underpins the cyber security profession, drawn together through international expert consultation and peer review.
Eristotle neither owns nor maintains CyBOK. We reference it, and we map our Cyber Security certification and competency framework to it, because a profession is better served by one shared foundation than by every organisation writing its own.
Where our own bodies of knowledge – ISOBOK™, AIBOK™ and CWBOK™ – address the security office, artificial intelligence and cyber warfare, CyBOK covers the technical and organisational fundamentals of cyber security itself. Together they give a practitioner a complete map of the territory.
CyBOK is published and maintained at cybok.org, where the full knowledge area documents are available directly from the source.
Licence and attribution
CyBOK is made available by the University of Bristol under the Open Government Licence v3.0. The authoritative and current licence terms are published at cybok.org and take precedence over this summary.
Where our course and reference material draws on a CyBOK Knowledge Area, we cite it in full — author, Knowledge Area, version number and a link to the source — so that any reader can go to the original rather than relying on our reading of it. Our own material is written by us; CyBOK is cited, not reproduced.
CyBOK® and the CyBOK logo are registered trademarks of the University of Bristol. Eristotle is not affiliated with, endorsed by, or accredited by the University of Bristol or the National Cyber Security Centre.
Knowledge Areas
CyBOK organises the discipline into twenty-one Knowledge Areas across five categories.
1. Human, Organisational & Regulatory Aspects
- Risk Management & Governance
- Law & Regulation
- Human Factors
- Privacy & Online Rights
2. Attacks & Defences
- Malware & Attack Technologies
- Adversarial Behaviours
- Security Operations & Incident Management
- Forensics
3. Systems Security
- Cryptography
- Operating Systems & Virtualisation Security
- Distributed Systems Security
- Formal Methods for Security
- Authentication, Authorisation & Accountability
4. Software and Platform Security
- Software Security
- Web & Mobile Security
- Secure Software Lifecycle
5. Infrastructure Security
- Applied Cryptography
- Network Security
- Hardware Security
- Cyber-Physical Systems Security
- Physical Layer and Telecommunications Security
Each Knowledge Area is published by CyBOK as a full reference document with its own authors, reviewers and bibliography. Read them at cybok.org.
Mapping CyBOK to the Eristotle Cyber Security Competency Framework
The Eristotle Cyber Security Competency Model turns CyBOK’s knowledge areas into a development path, from foundational understanding through applied practice to adaptive judgement. This is how a body of knowledge becomes a career.
Foundational Learning
Core concepts, principles, and context-setting knowledge
Where a practitioner new to the field builds the vocabulary and mental models the rest of the discipline depends on.
Human, Organisational & Regulatory Aspects
- Risk management, governance, and the legal and regulatory context
- Human factors and privacy as design constraints, not afterthoughts
Systems Security
- Cryptography, operating systems, and distributed systems fundamentals
- Authentication, authorisation and accountability as first principles
Applied Learning
Practical knowledge, operational technique, and day-to-day execution
Where knowledge becomes capability: detecting, responding, building and defending under real conditions.
Attacks & Defences
- Malware, attack technologies, and adversarial behaviour
- Security operations, incident management, and forensics
Software and Platform Security
- Software security and the secure software lifecycle
- Web and mobile security in practice
Adaptive Learning
Evolving practice, systems thinking, and judgement under uncertainty
Where a practitioner stops applying known answers and starts reasoning about problems nobody has documented yet.
Infrastructure Security
- Network, hardware, and applied cryptographic engineering
- Cyber-physical systems and the physical and telecommunications layer
Formal Methods and Assurance
- Reasoning rigorously about whether a system actually holds its guarantees
- Carrying assurance thinking into emerging technology and AI-enabled systems
View ALL Cyber Security Related Certifications
Why We Build on CyBOK
A professional body earns trust by being accountable to a shared standard, not by inventing a private one. For the fundamentals of cyber security, that standard already exists and it is better than anything we would write alone. So we build on it:
- Independence. CyBOK is maintained outside the certification market, so the knowledge is not shaped by anyone’s commercial interest, including ours.
- Peer review. Each Knowledge Area is authored and reviewed by named subject experts, with its sources published openly.
- Portability. A practitioner who learns against CyBOK holds knowledge that travels, rather than knowledge tied to one provider’s syllabus.
- Honest scope. Mapping to CyBOK forces us to be explicit about what our certifications do and do not cover.
CyBOK is a project of the University of Bristol, funded by the UK National Cyber Security Centre. It is not affiliated with Eristotle and does not endorse Eristotle certifications. All CyBOK material remains the property of its authors and publishers, and is available directly at cybok.org.
