首页> 外文OA文献 >The Education of Information Security Professionals: An Analysis of Industry Needs vs Academic Curriculum in the 21st Century
【2h】

The Education of Information Security Professionals: An Analysis of Industry Needs vs Academic Curriculum in the 21st Century

机译:信息安全专业人员的教育:21世纪行业需求与学术课程的分析

摘要

This research compared the employment of the skills and attributes needed by information systems security professionals in an information systems security work environment with those taught in NSA Centers of Academic Excellence in Information Assurance Education. Using two surveys the goal of this research was to determine if the skills and attributes identified in the CISSP were employed in an information systems work environment and if these skills were taught in colleges and universities designated as NSA Centers of Academic Excellence in Information Assurance Education.The skills and attributes within the10 domains of the CISSP were identified by 23 questions contained in two surveys, one to information systems security professionals working in the field and one to information systems security faculty in NSA designated Centers of Academic Excellence in Information Assurance Education. The CISSP domains cover the following areas of information security responsibilities: 1) Access Control Systems and Methodology, 2) Telecommunications and Network Security, 3) Security Management Practices, 4) Applications and Systems Development Security, 5) Cryptography, 6) Security Architecture and Models, 7) Operations Security, 8) Business Continuity Planning and Disaster Recovery Planning, 9) Laws, Investigations, and Ethics, and 10) Physical Security. The CISSP domains were chosen as the defining criteria for the development of the operational definitions after an extensive review of literature in the field of information security.The surveys were developed over three phases: the pilot phase, the validity phase, and the reliability phase. The breakdown of the domain descriptions into questions was accomplished during the pilot survey phase. Requests for participation in the survey were e-mailed to 800 information systems security professionals and 321 information systems security faculty. There was a 67% information systems security faculty response rate and a 20% information systems security professional response rate.This research indicated that information systems security professionals working in an information systems security work environment employed or addressed the skills and attributes identified in the 10 domains of the CISSP. This research also indicated that the skills and attributes taught in the curriculum of NSA Centers of Academic Excellence in Information Assurance Education had no association with the skills and attributes employed, or addressed, by information systems security professionals in an information systems security work environment. There was one exception, Domain 4, Applications and Systems Development Security, which indicated there was an association between how the skills and attributes were employed in an information systems security work environment and were taught in NSA Centers of Academic Excellence in Information Assurance Education.The findings of this research can be used as a baseline to develop information systems security curriculum. Further research is needed to determine the differences, if any, in the skills and attributes identified in the various information security certifications, the correlation between the skills and attributes identified in each of the information security certifications, and any differences in the employment of these skills and attributes between certified and non-certified information systems security professionals.
机译:这项研究将信息系统安全工作环境中信息系统安全专业人员所需的技能和属性与国家安全局信息保证教育卓越学术中心教授的技能和属性进行了比较。通过两次调查,本研究的目的是确定CISSP中确定的技能和属性是否在信息系统工作环境中使用,以及这些技能是否在指定为NSA信息保证教育学术卓越中心的大学和学院教授。两项调查中包含23个问题,确定了CISSP的10个领域内的技能和属性,一项针对在该领域工作的信息系统安全专业人员,另一项针对NSA指定的信息保障教育卓越学术中心的信息系统安全学院。 CISSP域涵盖以下信息安全职责领域:1)访问控制系统和方法,2)电信和网络安全,3)安全管理实践,4)应用程序和系统开发安全,5)密码术,6)安全体系结构和模型,7)运营安全,8)业务连续性计划和灾难恢复计划,9)法律,调查和道德,以及10)物理安全。在广泛研究信息安全领域的文献之后,选择CISSP域作为制定操作定义的定义标准。调查分为三个阶段进行:试点阶段,有效性阶段和可靠性阶段。在试点调查阶段完成了将域描述分解为问题的过程。参加调查的请求已通过电子邮件发送给800位信息系统安全专业人员和321位信息系统安全教师。信息系统安全人员的回应率为67%,信息系统安全专业人员的回应率为20%。这项研究表明,在信息系统安全工作环境中工作的信息系统安全专业人员采用或解决了10个领域中确定的技能和属性CISSP。该研究还表明,NSA信息保证教育卓越学术中心的课程中讲授的技能和属性与信息系统安全工作环境中的信息系统安全专业人员所采用或解决的技能和属性没有关联。域4,应用程序和系统开发安全是一个例外,它表示在信息系统安全工作环境中如何使用技能和属性以及在NSA信息保证教育卓越学术中心教授的技能和属性之间存在关联。这项研究的发现可以用作开发信息系统安全课程的基准。需要进一步研究以确定各种信息安全认证中确定的技能和属性是否存在差异,每种信息安全认证中标识的技能和属性之间的相关性以及这些技能的使用上的差异认证和非认证信息系统安全专业人员之间的属性。

著录项

  • 作者

    Fundaburk Albert L.;

  • 作者单位
  • 年度 2004
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号