A Framework for Mapping Organisational Workforce Knowledge Profile in Cyber Security
Lata Nautiyal, Awais Rashid

TL;DR
This paper introduces a framework based on CyBOK for systematically mapping and assessing the cyber security knowledge profile of an organisation's workforce, addressing a gap in standardised evaluation methods.
Contribution
It presents a novel framework leveraging CyBOK to evaluate organisational and third-party cyber security knowledge capabilities systematically.
Findings
Framework enables identification of knowledge gaps.
Case studies demonstrate practical application.
Workshops refine the profiling methodology.
Abstract
A cyber security organisation needs to ensure that its workforce possesses the necessary knowledge to fulfil its cyber security business functions. Similarly, where an organisation chooses to delegate their cyber security tasks to a third party provider, they must ensure that the chosen entity possesses robust knowledge capabilities to effectively carry out the assigned tasks. Building a comprehensive cyber security knowledge profile is a distinct challenge; the field is ever evolving with a range of professional certifications, academic qualifications and on-the-job training. So far, there has been a lack of a well-defined methodology for systematically evaluating an organisation's cyber security knowledge, specifically derived from its workforce, against a standardised reference point. Prior research on knowledge profiling across various disciplines has predominantly utilised…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security
