J-34_-_Policy_-_National_Initiative_for_Cybersecurity_Education_(NICE)Cybersecurity_Workforce_Framework.pdf
PDF 2 MB Posted
- Attached to
- Enterprise IT Shared Services (EITSS) Federal contract opportunity
- Solicitation number
- 693JK419R500005
About this file
This document is a request for proposals for enterprise IT shared services. The Department of Transportation Office of the Chief Information Officer is seeking a contractor to provide infrastructure and standard operations support for the DOT Common Operating Environment. Proposals will be accepted on January 8, 2019 between 10:00 am and 3:00 pm Eastern Time in person at DOT headquarters. Offerors should submit 20 thumb drives with their technical proposal on 10 drives and business proposal on the other 10 drives in a sealed envelope with company and point of contact information. The requirement has a NAICS code of 541513 with a $27.5 million business size standard. The unrestricted solicitation is open to all business sizes, while large businesses must submit a small business subcontracting plan. The small business set-aside requires that the small business prime perform 51% of the work.
J-34 - Policy - National Initiative for Cybersecurity Education (NICE)Cybersecurity Workforce Framework
View the file
Other files for this federal contract opportunity
Show all 50
Enterprise IT Shared Services (EITSS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NIST Special Publication 800-181
National Initiative for Cybersecurity Education (NICE)
Cybersecurity Workforce Framework
William Newhouse Stephanie Keith
Benjamin Scribner Greg Witte
This publication is available free of charge from:
https://doi.org/10.6028/NIST.SP.800-181
NIST Special Publication 800-181
National Initiative for Cybersecurity Education (NICE)
Cybersecurity Workforce Framework
William Newhouse Applied Cybersecurity Division
Information Technology Laboratory
Stephanie Keith Cyber Workforce Strategy & Policy Division
Office of the Deputy DoD Chief Information Officer
Benjamin Scribner Cyber Education and Awareness Branch
DHS National Protection and Programs Directorate
Greg Witte G2, Inc.
Annapolis Junction, MD
August 2017
U.S. Department of Commerce Wilbur L. Ross, Jr., Secretary
National Institute of Standards and Technology
Kent Rochford, Acting NIST Director and Under Secretary of Commerce for Standards and Technology
Authority
This publication has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems. This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130.
Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of the OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States.
Attribution would, however, be appreciated by NIST.
National Institute of Standards and Technology Special Publication 800-181 Natl. Inst. Stand. Technol. Spec. Publ. 800-181, 144 pages (August 2017)
CODEN: NSPUE2
Certain commercial entities, equipment, or materials may be identified in this document to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.
There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.
Organizations are encouraged to review all draft publications during public comment periods and provide feedback to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at http://csrc.nist.gov/publications.
Comments on this publication may be submitted to:
National Institute of Standards and Technology Attn: NICE, Applied Cybersecurity Division, Information Technology Laboratory
100 Bureau Drive (Mail Stop 2000) Gaithersburg, MD 20899-2000 Email: ncwf@nist.gov
All comments are subject to release under the Freedom of Information Act (FOIA).
http://csrc.nist.gov/publications mailto:ncwf@nist.gov
NIST SP 800-181 NICE FRAMEWORK
ii
This publication is available free of charge from : https://doi.org/10.6028/N
IS
T.S
P .800-181
Reports on Computer Systems Technology
The Information Technology Laboratory (ITL) at NIST promotes the U.S. economy and public welfare by providing technical leadership for the Nation’s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL’s responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in federal information systems.
The Special Publication 800-series reports on ITL’s research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations.
Abstract
This publication describes the National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework (NICE Framework), a reference structure that describes the interdisciplinary nature of the cybersecurity work. It serves as a fundamental reference resource for describing and sharing information about cybersecurity work and the knowledge, skills, and abilities (KSAs) needed to complete tasks that can strengthen the cybersecurity posture of an organization. As a common, consistent lexicon that categorizes and describes cybersecurity work, the NICE Framework improves communication about how to identify, recruit, develop, and retain cybersecurity talent. The NICE Framework is a reference source from which organizations or sectors can develop additional publications or tools that meet their needs to define or provide guidance on different aspects of cybersecurity workforce development, planning, training, and education.
Keywords
Ability; cybersecurity; cyberspace; education; knowledge; role; skill; specialty area; task;
training; work role.
Revisions
Please visit the NICE Framework revisions website [1] to determine if there have been any updates to the NICE Framework.
Supplemental Content
A Reference Spreadsheet for the NICE Framework is available at https://www.nist.gov/file/372581.
https://www.nist.gov/file/372581 iii
: https://doi.org/10.6028/N
IS
T.S
Acknowledgements
The authors gratefully acknowledge and appreciate the significant contributions from individuals and organizations in the public and private sectors, whose thoughtful and constructive comments improved the overall quality, thoroughness, and usefulness of this publication. We appreciate the leadership and work of Rodney Petersen, Director of the National Initiative for Cybersecurity Education (NICE) at NIST. We wish to thank Tanya Brewer, Dean Bushmiller, Lynne Clarke, Jerri Damavandy, Lisa Dorr, Ryan Farr, Jim Foti, Jodi Guss, Keith Hall, Chris Kelsall, Elizabeth Lennon, Jeff Marron, Joshua Musicante, Stephen Olechnowicz, Lori Pfannenstein, Chuck Romine, Kevin Sanchez-Cherry, Danielle Santos, Stephanie Shively, Matthew Smith, Kevin Stine, Bluma Sussman, Caroline Tan, Baris Yakin, and Clarence Williams for their individual contributions to this publication.
The first NICE Framework was posted for public comment in September 2012 and published as final in April 2013 as the National Cybersecurity Workforce Framework version 1.0 [2]. The authors recognize Dr. Jane Homeyer, Anne Quigley, Rex Min, Noel Kyle, Maya Yankelevich, and Peggy Maxson for leading its development, along with Montana Williams and Roy Burgess for their leadership in the development of National Cybersecurity Workforce Framework version
2.0 which was posted in April 2014 [3].
Finally, the authors respectfully acknowledge the seminal work in computer security that dates to the 1960s. The vision, insights, and dedicated efforts of those early pioneers in computer security serve as the philosophical and technical foundation for the tasks, knowledge, skills, and abilities noted in this publication.
Trademark Information
All trademarks or registered trademarks belong to their respective organizations.
iv
: https://doi.org/10.6028/N
IS
T.S
Executive Summary
The National Initiative for Cybersecurity Education (NICE), led by the National Institute of Standards and Technology (NIST) of the U.S. Department of Commerce, is a partnership between government, academia, and the private sector working to energize and promote a robust network and an ecosystem of cybersecurity education, training, and workforce development. NICE fulfills this mission by coordinating with government, academic, and industry partners to build on existing successful programs, facilitate change and innovation, and bring leadership and vision to increase the number of skilled cybersecurity professionals helping to keep our nation secure.
NICE is committed to cultivating an integrated cybersecurity workforce that is globally competitive from hire to retire and prepared to protect our nation from existing and emerging cybersecurity challenges. NICE promotes nationwide initiatives that increase the number of people with the knowledge, skills, and abilities to perform the tasks required for cybersecurity work.
As threats that exploit vulnerabilities in our cyberinfrastructure grow and evolve, an integrated cybersecurity workforce must be capable of designing, developing, implementing, and maintaining defensive and offensive cyber strategies. An integrated cybersecurity workforce includes technical and nontechnical roles that are staffed with knowledgeable and experienced people. An integrated cybersecurity workforce can address the cybersecurity challenges inherent to preparing their organizations to successfully implement aspects of their missions and business processes connected to cyberspace.
This publication provides a fundamental reference in support of a workforce capable of meeting an organization’s cybersecurity needs by using a common, consistent lexicon to describe cybersecurity work by category, specialty area, and work role. It provides a superset of cybersecurity Knowledge, Skills, and Abilities (KSAs) and Tasks for each work role. The NICE Framework supports consistent organizational and sector communication for cybersecurity education, training, and workforce development.
A user of the NICE Framework will reference it for different aspects of workforce development, education, and/or training purposes, and when that material is used at organizational levels, the user should customize what is pulled from the NICE Framework to standards, regulations, needs, and mission of the user’s organization. The NICE Framework is a reference starting point for the content of guidance and guidelines on career paths, education, training, and credentialing programs.
The NICE Framework is a resource that will strengthen an organization’s ability to communicate consistently and clearly about cybersecurity work and its cybersecurity workforce. Organizations or sectors can develop additional publications or tools that meet their needs to define or provide guidance on different aspects of workforce development, planning, training, and education.
An online reference spreadsheet tool [4] is available on the NICE Framework website [5].
v
: https://doi.org/10.6028/N
IS
T.S
Table of Contents Executive Summary ..................................................................................................... iv
1 Introduction
1.1 NICE Framework Background
1.2 Purpose and Applicability
1.3 Audience/Users
1.3.1 Employers
1.3.2 Current and Future Cybersecurity Workers
1.3.3 Educators/Trainers
1.3.4 Technology Providers
1.4 Organization of this Special Publication
2 NICE Framework Components and Relationships
2.1 Components of the NICE Framework
2.1.1 Categories
2.1.2 Specialty Areas
2.1.3 Work Roles
2.1.4 Knowledge, Skills, and Abilities (KSAs)
2.1.5 Tasks
2.2 NICE Framework Component Relationships
3 Using the NICE Framework
3.1 Identification of Cybersecurity Workforce Needs
3.2 Recruitment and Hiring of Highly Skilled Cybersecurity Talent
3.3 Education and Training of Cybersecurity Workforce Members
3.4 Retention and Development of Highly Skilled Cybersecurity Talent
4 Extensions
4.1 Competencies
4.2 Job Titles
4.3 Cybersecurity Guidance and Guideline documents
List of Appendices
Appendix A – Listing of NICE Framework Elements
A.1 NICE Framework Workforce Categories
A.2 NICE Framework Specialty Areas vi
: https://doi.org/10.6028/N
IS
T.S
A.3 NICE Framework Work Roles
A.4 NICE Framework Tasks
A.5 NICE Framework Knowledge Descriptions
A.6 NICE Framework Skills Descriptions
A.7 NICE Framework Ability Descriptions
Appendix B – Work Role Detail Listing
B.1 Securely Provision (SP)
B.2 Operate and Maintain (OM)
B.3 Oversee and Govern (OV)
B.4 Protect and Defend (PR)
B.5 Analyze (AN)
B.6 Collect and Operate (CO)
B.7 Investigate (IN)
Appendix C – Workforce Development Tools
C.1 DHS Cybersecurity Workforce Development Toolkit
C.1.1 Proficiency Levels and Career Paths
C.2 Baldrige Cybersecurity Excellence Builder Tool
C.3 Position Description Drafting Tool
Appendix D – Cross Reference to Guidance and Guideline Documents
D.1 Cybersecurity Framework
D.1.2 Example Integration of Cybersecurity Framework with NICE Framework
D.2 Systems Security Engineering
D.3 U.S. Office of Personnel Management Federal Cybersecurity Codes
Appendix E – Acronyms
Appendix F – References
List of Tables
Table 1 - NICE Framework Workforce Categories
Table 2 - NICE Framework Specialty Areas
Table 3 - NICE Framework Work Roles
Table 4 - NICE Framework Tasks
Table 5 - NICE Framework Knowledge Descriptions vii
: https://doi.org/10.6028/N
IS
T.S
Table 6 - NICE Framework Skills Descriptions
Table 7 - NICE Framework Ability Descriptions
Table 8 - Crosswalk of NICE Framework Workforce Categories to Cybersecurity Framework Functions
Table 9 – Crosswalk of Work Role IDs to OPM Cybersecurity Codes
: https://doi.org/10.6028/N
IS
T.S
1 Introduction
The National Initiative for Cybersecurity Education (NICE), led by the National Institute of Standards and Technology (NIST) in the U.S. Department of Commerce, is a partnership between government, academia, and the private sector that seeks to energize and promote a robust network and an ecosystem of cybersecurity education, training, and workforce development. NICE fulfills this mission by coordinating with government, academic, and industry partners to build on existing successful programs, facilitate change and innovation, and bring leadership and vision to increase the number of skilled cybersecurity professionals helping to keep our nation secure and economically competitive.
NICE is committed to cultivating an integrated cybersecurity workforce that is globally competitive from hire to retire, prepared to protect our nation from existing and emerging cybersecurity challenges.
Throughout this document, the combined terms “cybersecurity workforce” is shorthand for a workforce with work roles that have an impact on an organization’s ability to protect its data, systems, and operations. Included are new work roles that have been known traditionally as information technology (IT) security roles. Those roles have been added to this workforce framework to highlight their importance to the overall cybersecurity posture of an organization.
Additionally, some of the work roles described herein include the shorter term cyber to be inclusive of sectors where cyber has become the conversational norm for this field.
A cybersecurity workforce includes not only technically focused staff, but also those who apply knowledge of cybersecurity when preparing their organization to successfully implement its mission. A knowledgeable and skilled cybersecurity workforce is needed to address cybersecurity risks within an organization’s overall risk management process.
1.1 NICE Framework Background
The concept for the NICE Framework began before the establishment of NICE in 2010 and grew out of the recognition that the cybersecurity workforce had not been defined and assessed. To address this challenge, the Federal Chief Information Officers (CIO) Council took on the task in 2008 to provide a standard framework to understand the cybersecurity roles within the federal government. Input from focus groups with subject matter experts from numerous federal agencies helped the Federal CIO Council produce a research report that referenced where other information technology professional development efforts were already under way, and thirteen specific roles were identified as needed by agencies to conduct cybersecurity work.
Building on this inherently multidisciplinary exploration of the “field” of cybersecurity, the Comprehensive National Cybersecurity Initiative’s included a focus on workforce that tasked several agencies to work together to develop a cybersecurity workforce framework. The first draft was posted for public comment in September 2011. Comments were incorporated into version 1.0 [2].
A subsequent U.S. government-wide review noted specific areas to be further examined and refined. The Department of Homeland Security (DHS) gathered input and validated final
: https://doi.org/10.6028/N
IS
T.S recommendations via focus groups with subject matter experts from around the country and across industry, academia, and government resulting in a second version of the NICE Framework, version 2.0 [3], shared publicly in 2014.
The Office of the Secretary of Defense (OSD) expanded on version 2.0 through internal engagements with service components and external engagements with the private sector. The DHS and NIST co-authors worked with OSD to refine their expansion to become this publication with a goal to emphasize private sector applicability and to reinforce the vision that the NICE Framework is a reference resource for both the public and private sectors.
1.2 Purpose and Applicability
This publication serves as a fundamental reference resource to support a workforce capable of meeting an organization’s cybersecurity needs. It provides organizations with a common, consistent lexicon that categorizes and describes cybersecurity work.
Using the NICE Framework as a fundamental reference will improve the communication needed to identify, recruit, and develop cybersecurity talent. The NICE Framework will allow employers to use focused, consistent language in professional development programs, in their use of industry certifications and academic credentials, and in their selection of relevant training opportunities for their workforce.
The NICE Framework facilitates the use of a more consistent, comparable, and repeatable approach to select and specify cybersecurity roles for positions within organizations. It also provides a common lexicon that academic institutions can use to develop cybersecurity curricula that better prepares students for current and anticipated cybersecurity workforce needs.
The application of the NICE Framework offers the ability to describe all cybersecurity work. An applicability goal of the NICE Framework is that any cybersecurity job or position can be described by identifying the relevant material from one or more components of the NICE Framework. For each job or position, the context of the mission or business processes and priorities will drive which material is selected from the NICE Framework.
Organizations or sectors can use the NICE Framework to develop additional publications or tools that meet their needs to define or provide guidance on different aspects of workforce development, planning, training, and education.
1.3 Audience/Users
The NICE Framework can be viewed as a non-prescriptive cybersecurity workforce dictionary.
Users of the NICE Framework who reference it should implement it locally for different workforce development, education, or training purposes.
1.3.1 Employers
Use of the NICE Framework’s common lexicon enables employers to inventory and develop their cybersecurity workforce. The NICE Framework can be used by employers and organizational leadership to:
: https://doi.org/10.6028/N
IS
T.S
• Inventory and track their cybersecurity workforce to gain a greater understanding of the strengths and gaps in Knowledge, Skills, and Abilities and Tasks performed;
• Identify training and qualification requirements to develop critical Knowledge, Skills, and Abilities to perform cybersecurity Tasks;
• Improve position descriptions and job vacancy announcements selecting relevant KSAs and Tasks, once work roles and tasks are identified;
• Identify the most relevant work roles and develop career paths to guide staff in gaining the requisite skills for those roles; and
• Establish a shared terminology between hiring managers and human resources (HR) staff for the recruiting, retention, and training of a highly-specialized workforce.
1.3.2 Current and Future Cybersecurity Workers
The NICE Framework supports those in the cybersecurity field and those who might wish to enter the cybersecurity field, to explore Tasks within cybersecurity Categories and work roles. It also assists those who support these workers, such as human resource staffing specialists and guidance counselors, to help job seekers and students understand which cybersecurity work roles and which associated Knowledge, Skills, and Abilities are being valued by employers for in-demand cybersecurity jobs and positions.
These workers are further supported when vacancy announcements and open position descriptions use the NICE Framework’s common lexicon to provide clear and consistent descriptions of the cybersecurity tasks and training that are needed for those positions.
When training providers and industry certification providers use the common lexicon of the NICE Framework, those in the cybersecurity field, or those who might wish to enter the cybersecurity field, can find training and/or certification providers that can teach the tasks necessary to secure a cybersecurity job or to progress into new positions. Use of the common lexicon helps students and professionals to obtain KSAs that are typically demonstrated by a person whose cybersecurity position includes a given work role. This understanding helps them to find academic programs that include learning outcomes and knowledge units that map to the KSAs and Tasks that are valued by employers.
1.3.3 Educators/Trainers
The NICE Framework provides a reference for educators to develop curriculum, certificate or degree programs, training programs, courses, seminars, and exercises or challenges that cover the KSAs and Tasks described in the NICE Framework.
Human resource staffing specialists and guidance counselors can use the NICE Framework as a resource for career exploration.
: https://doi.org/10.6028/N
IS
T.S
1.3.4 Technology Providers
The NICE Framework allows a technology provider to identify the cybersecurity work roles and the KSAs and Tasks associated with hardware and software products and services they provide.
A technology provider can then create appropriate support materials to assist members of the cybersecurity workforce in the proper configuration and management of their products.
1.4 Organization of this Special Publication
The remainder of this special publication is organized as follows:
• Chapter 2 defines the components of the NICE Framework: (i) Categories; (ii) Specialty Areas; (iii) Work Roles; (iv) associated supersets of Knowledge, Skills, and Abilities; and
(v) Tasks for each work role.
• Chapter 3 describes using the NICE Framework
• Chapter 4 notes areas where other publications, guidelines, guidance, and tools can expand the impact of the NICE Framework.
• Appendix A describes the NICE Framework list of Categories, Specialty Areas, Work Roles, KSAs, and Tasks.
• Appendix B provides a detailed listing of each work role, including the associated KSAs and Tasks.
• Appendix C provides some examples of workforce development tools
• Appendix D provides some examples of guidance or guideline documents that cross reference some of the content of those documents to components in the NICE Framework
• Appendix E gives selected acronyms and abbreviations used in this document.
• Appendix F gives references cited in this document.
: https://doi.org/10.6028/N
IS
T.S
2 NICE Framework Components and Relationships
2.1 Components of the NICE Framework
The NICE Framework organizes cybersecurity and related work. This section introduces and defines the core components of the NICE Framework in support of those areas.
2.1.1 Categories
Categories provide the overarching organizational structure of the NICE Framework. There are seven Categories and all are composed of Specialty Areas and work roles. This organizational structure is based on extensive job analyses, which group together work and workers that share common major functions, regardless of job titles or other occupational terms.
2.1.2 Specialty Areas
Categories contain groupings of cybersecurity work, which are called Specialty Areas. There were 31 specialty areas called out in National Cybersecurity Workforce Framework version 1.0 [2] and 32 in National Cybersecurity Workforce Framework version 2.0 [3]. Each specialty area represents an area of concentrated work, or function, within cybersecurity and related work. In previous versions of the NICE Framework, tasks and KSAs were associated with each specialty area. KSAs and Tasks are now associated with the work roles.
2.1.3 Work Roles
Work roles are the most detailed groupings of cybersecurity and related work which include a list of attributes required to perform that role in the form of knowledge, skills, and abilities (KSAs) and tasks performed in that role.
Work being performed in a job or position is described by selecting one or more work roles from the NICE Framework relevant to that job or position, in support of mission or business processes.
To aid in the organization and communication about cybersecurity responsibilities, work roles are grouped into specific classes of categories and specialty areas as shown in Appendix A.
2.1.4 Knowledge, Skills, and Abilities (KSAs)
Knowledge, Skills, and Abilities (KSAs) are the attributes required to perform work roles and are generally demonstrated through relevant experience, education, or training.
Knowledge is a body of information applied directly to the performance of a function.
Skill is often defined as an observable competence to perform a learned psychomotor act.
Skills in the psychomotor domain describe the ability to physically manipulate a tool or instrument like a hand or a hammer. Skills needed for cybersecurity rely less on physical manipulation of tools and instruments and more on applying tools, frameworks, processes, : https://doi.org/10.6028/N
IS
T.S and controls that have an impact on the cybersecurity posture of an organization or individual.
Ability is competence to perform an observable behavior or a behavior that results in an observable product.
2.1.5 Tasks
A Task is a specific defined piece of work that, combined with other identified Tasks, composes the work in a specific specialty area or work role.
2.2 NICE Framework Component Relationships
The NICE Framework components describe cybersecurity work. As illustrated in Figure 1, each Category is composed of Specialty Areas, each of which is composed of one or more work roles.
Each work role, in turn, includes KSAs and Tasks.
Grouping components in this manner simplifies communication about cybersecurity workforce topics, and helps with alignment to other frameworks. Specific associations of work roles to KSAs and Tasks are shown in Appendix B and in a reference spreadsheet [4] posted to the NICE Framework website [5].
Figure 1 - Relationships among NICE Framework Components
: https://doi.org/10.6028/N
IS
T.S
3 Using the NICE Framework
Using the NICE Framework to understand organizational needs and assess the extent to which those needs are met can help an organization to plan, implement, and monitor a successful cybersecurity program.
3.1 Identification of Cybersecurity Workforce Needs
Cybersecurity is a rapidly changing and expanding field. This expansion requires a cadre of skilled workers to help organizations perform cybersecurity functions. As organizations identify what is needed to adequately manage current and future cybersecurity risk, leaders need to consider the cybersecurity workforce capabilities and capacity needed.
Figure 2 illustrates how the NICE Framework is a central reference to help employers build a capable and ready cybersecurity workforce.
Figure 2 - Building Blocks for a Capable and Ready Cybersecurity Workforce
The circular arrows on the left side of Figure 2 are activities that are likely to have an impact on an organization’s ability to develop a capable and ready workforce:
• Using the common lexicon of the NICE Framework clarifies communication between cybersecurity educators, trainers/certifiers, employers, and employees.
• Performing criticality analysis will identify those KSAs and tasks that are critical for successful performance with a given work role and those that are key to multiple work roles.
• Running a proficiency analysis will inform an organization’s expectation of the level (e.g.
entry-level, expert) for positions, comprised often of more than one work role. The proficiency analysis should enable refinement of selection of the relevant tasks, and KSAs needed for the work roles that make up that position.
: https://doi.org/10.6028/N
IS
T.S
Appendix C identifies some existing workforce development tools that support identification of cybersecurity workforce needs.
3.2 Recruitment and Hiring of Highly Skilled Cybersecurity Talent
Referencing the NICE Framework will help organizations to accomplish strategic workforce planning and hiring. NICE Framework material, when used during the creation or revision of position descriptions in vacancy announcements and job postings, will help candidates to seek out specific positions for which they are interested, capable, or qualified. Tasks used to describe a position’s duties and responsibilities, and KSAs used to describe the position’s needed skills and qualifications, should allow candidates and hiring managers to communicate more effectively. Position descriptions and vacancy announcements using the NICE Framework terminology support more consistent evaluation criteria for vetting and approving candidates.
For organizations who are concerned with workforce gaps, a review of the NICE Framework’s list of tasks can determine specific tasks which are not being performed by the organization.
Those tasks allow the organization to identify the work role(s) and specialty area(s) that are gaps.
The organization is better able to engage with the community of education, training, and credential, and certification providers who map their offerings to the NICE Framework. The organization can identify training that will allow existing staff member to address the gaps. The organization’s hiring managers using data pulled from the NICE Framework in this manner can recognize applicants who have the KSAs to perform the cybersecurity tasks.
3.3 Education and Training of Cybersecurity Workforce Members
The NICE Framework’ identification of tasks in work roles allows educators to prepare learners with the specific KSAs from which they can demonstrate the ability to perform cybersecurity tasks.
Academic institutions are a critical part of preparing and educating the cybersecurity workforce.
Collaboration among public and private entities, such as through the NICE program, enables such institutions to determine common knowledge and abilities that are needed. In turn, developing and delivering curricula that are harmonized with the NICE Framework lexicon allows institutions to prepare students with the skills needed by employers. As the pipeline of students finding desired jobs in cybersecurity increases, more students will be attracted to academic cybersecurity programs as a pathway to a career.
3.4 Retention and Development of Highly Skilled Cybersecurity Talent
A critical aspect of a skilled cybersecurity workforce involves the development and retention of the skilled talent already onboard. A current employee has existing relationships, institutional knowledge, and organizational experience that is hard to replace. Refilling a position after an employee leaves may bring new advertising and hiring costs, expenses for training, diminished productivity, and reduced morale. The following list illustrates some of the ways that the NICE Framework supports retention and development of cybersecurity talent:
: https://doi.org/10.6028/N
IS
T.S
• Organizations can develop career pathways that describe the qualifications necessary for progressively challenging and evolving sets of work roles, such as those enumerated by the NICE Framework.
• A detailed understanding of the KSAs and Tasks helps existing staff to understand the specific steps needed to develop their capabilities, promoting readiness for a desired position.
• An organization might offer staff rotations to provide opportunities to develop and use new skills.
• Organizations can identify personnel that are diligent in improving KSAs in relevant areas, recognizing those who perform well.
• Organizations can create development/improvement plans for staff to help them map out how they can obtain KSAs required for new work roles.
• Group training opportunities can be identified to prepare staff members to enhance common knowledge, skills, and abilities in the work roles of an organization.
• Organizations can use training and examinations that are based for specific cybersecurity skills and abilities to assess proficiency in a realistic environment.
• Organizations can use existing personnel to fill critical cybersecurity staffing needs, leveraging the ability to review resumes of existing staff to identify those with desirable KSAs.
• The NICE Framework is helpful for existing employees who desire to move into a cybersecurity work role from another position. An organization can describe the KSAs needed to allow a reliable employee in a non-cybersecurity work role to become part of the cybersecurity workforce taking on cybersecurity tasks.
: https://doi.org/10.6028/N
IS
T.S
4 Extensions
Organizations or sectors can use the NICE Framework to develop additional publications or tools that meet their needs and define or provide guidance on different aspects of workforce development, planning, training, and education.
New reference materials that cross-reference elements of the NICE Framework will be shared via the NICE website [5].
The following areas are a few examples from which additional publications or tools could be developed.
4.1 Competencies
The Department of Labor’s Employment and Training Administration [6] defines a competency as the capability of applying or using knowledge, skills, abilities, behaviors, and personal characteristics to successfully perform critical work tasks, specific functions, or operate in a given role or position. In addition to the enumeration of technical KSAs, competency models also consider behavioral indicators and describe nontechnical considerations such as Personal Effectiveness, Academic, and Workplace Competencies. Additional information about these considerations is available from the Department of Labor’s CareerOneStop Site [7].
4.2 Job Titles
Job titles are a description of an employee’s job or position in an organization. A mapping of sample job titles to specialty areas or work roles would help organizations to use the NICE Framework.
4.3 Cybersecurity Guidance and Guideline documents
NICE Strategic Goal #3, Guide Career Development and Workforce Planning, aims to support employers to address market demands and enhance recruitment, hiring, development, and retention of cybersecurity talent. One objective within this strategic goal is to publish and raise awareness of the NICE Framework and encourage adoption. Adoption in this case means that the NICE Framework is used as a reference resource for actions related to cybersecurity workforce, training, and education.
One way to encourage adoption of the NICE Framework is to encourage authors of cybersecurity guidance or guideline documents to cross reference their content with components of the NICE Framework. Three example publications are explored in Appendix D.
: https://doi.org/10.6028/N
IS
T.S
Appendix A – Listing of NICE Framework Elements
A.1 NICE Framework Workforce Categories
Table 1 provides a description of each Category described by the NICE Framework. Each includes a two-character abbreviation (e.g., SP) for quick reference of the Category and to support the creation of NICE Framework work role identifiers (see Table 3 - NICE Framework work roles). This listing will be updated periodically [1]. The definitive source for the most current version of this material can be found in the Reference Spreadsheet for NIST Special Publication 800-181 [4].
Table 1 - NICE Framework Workforce Categories
Categories Descriptions Securely Provision (SP) Conceptualizes, designs, procures, and/or builds secure information technology (IT) systems, with responsibility for aspects of system and/or network development.
Operate and Maintain (OM) Provides the support, administration, and maintenance necessary to ensure effective and efficient information technology (IT) system performance and security.
Oversee and Govern (OV) Provides leadership, management, direction, or development and advocacy so the organization may effectively conduct cybersecurity work.
Protect and Defend (PR) Identifies, analyzes, and mitigates threats to internal information technology (IT) systems and/or networks.
Analyze (AN) Performs highly-specialized review and evaluation of incoming cybersecurity information to determine its usefulness for intelligence.
Collect and Operate (CO) Provides specialized denial and deception operations and collection of cybersecurity information that may be used to develop intelligence.
Investigate (IN) Investigates cybersecurity events or crimes related to information technology (IT) systems, networks, and digital evidence.
: https://doi.org/10.6028/N
IS
T.S
A.2 NICE Framework Specialty Areas
Table 2 provides a description of each of the NICE Framework Specialty Areas. Each Specialty Area includes a three-character abbreviation (e.g., RSK) for quick reference of the specialty area and to support the creation of NICE Framework work role identifiers (see Table 3 - NICE Framework work roles). This listing will be updated periodically [1]. The definitive source for the most current version of this material can be found in the Reference Spreadsheet for NIST Special Publication 800-181 [4].
Table 2 - NICE Framework Specialty Areas
Categories Specialty Areas Specialty Area Descriptions Securely Provision
(SP)
Risk Management (RSK) Oversees, evaluates, and supports the documentation, validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives.
Software Development (DEV) Develops and writes/codes new (or modifies existing) computer applications, software, or specialized utility programs following software assurance best practices.
Systems Architecture (ARC) Develops system concepts and works on the capabilities phases of the systems development life cycle; translates technology and environmental conditions (e.g., law and regulation) into system and security designs and processes.
Technology R&D (TRD) Conducts technology assessment and integration processes; provides and supports a prototype capability and/or evaluates its utility.
Systems Requirements Planning
(SRP)
Consults with customers to gather and evaluate functional requirements and translates these requirements into technical solutions. Provides guidance to customers about applicability of information systems to meet business needs.
Test and Evaluation (TST) Develops and conducts tests of systems to evaluate compliance with specifications and requirements by applying principles and methods for cost-effective planning, evaluating, verifying, and validating of technical, functional, and performance characteristics (including interoperability) of systems or elements of systems incorporating IT.
Systems Development (SYS) Works on the development phases of the systems development life cycle.
Operate and Maintain
(OM)
Data Administration (DTA) Develops and administers databases and/or data management systems that allow for the storage, query, protection, and utilization of data.
Knowledge Management (KMG) Manages and administers processes and tools that enable the organization to identify, document, and access intellectual capital and information content.
: https://doi.org/10.6028/N
IS
T.S
Customer Service and Technical Support (STS)
Addresses problems; installs, configures, troubleshoots, and provides maintenance and training in response to customer requirements or inquiries (e.g., tiered-level customer support). Typically provides initial incident information to the Incident Response (IR) Specialty.
Network Services (NET) Installs, configures, tests, operates, maintains, and manages networks and their firewalls, including hardware (e.g., hubs, bridges, switches, multiplexers, routers, cables, proxy servers, and protective distributor systems) and software that permit the sharing and transmission of all spectrum transmissions of information to support the security of information and information systems.
Systems Administration (ADM) Installs, configures, troubleshoots, and maintains server configurations (hardware and software) to ensure their confidentiality, integrity, and availability. Manages accounts, firewalls, and patches. Responsible for access control, passwords, and account creation and administration.
Systems Analysis (ANA) Studies an organization's current computer systems and procedures, and designs information systems solutions to help the organization operate more securely, efficiently, and effectively. Brings business and information technology (IT) together by understanding the needs and limitations of both.
Oversee and Govern
(OV)
Legal Advice and Advocacy
(LGA)
Provides legally sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain. Advocates legal and policy changes, and makes a case on behalf of client via a wide range of written and oral work products, including legal briefs and proceedings.
Training, Education, and Awareness (TEA)
Conducts training of personnel within pertinent subject domain. Develops, plans, coordinates, delivers and/or evaluates training courses, methods, and techniques as appropriate.
Cybersecurity Management
(MGT)
Oversees the cybersecurity program of an information system or network, including managing information security implications within the organization, specific program, or other area of responsibility, to include strategic, personnel, infrastructure, requirements, policy enforcement, emergency planning, security awareness, and other resources.
Strategic Planning and Policy
(SPP)
Develops policies and plans and/or advocates for changes in policy that support organizational cyberspace initiatives or required changes/enhancements.
Executive Cyber Leadership
(EXL)
Supervises, manages, and/or leads work and workers performing cyber and cyber-related and/or cyber operations work.
Program/Project Management (PMA) and Acquisition
Applies knowledge of data, information, processes, organizational interactions, skills, and analytical expertise, as well as systems, networks, and information
This publication is available free of charge from : https://doi.org/10.6028/N
IS
T.S
P .800-181
Categories Specialty Areas Specialty Area Descriptions exchange capabilities to manage acquisition programs. Executes duties governing hardware, software, and information system acquisition programs and other program management policies. Provides direct support for acquisitions that use information technology (IT) (including National Security Systems), applying IT-related laws and policies, and provides IT-related guidance throughout the total acquisition life cycle.
Protect and Defend
(PR)
Cyber Defense Analysis (CDA) Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network to protect information, information systems, and networks from threats.
Cyber Defense Infrastructure Support (INF)
Tests, implements, deploys, maintains, reviews, and administers the infrastructure hardware and software that are required to effectively manage the computer network defense service provider network and resources. Monitors network to actively remediate unauthorized activities.
Incident Response (CIR) Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security. Investigates and analyzes all relevant response activities.
Vulnerability Assessment and Management (VAM)
Conducts assessments of threats and vulnerabilities; determines deviations from acceptable configurations, enterprise or local policy; assesses the level of risk;
and develops and/or recommends appropriate mitigation countermeasures in operational and nonoperational situations.
Analyze
(AN)
Threat Analysis (TWA) Identifies and assesses the capabilities and activities of cybersecurity criminals or foreign intelligence entities; produces findings to help initialize or support law enforcement and counterintelligence investigations or activities.
Exploitation Analysis (EXP) Analyzes collected information to identify vulnerabilities and potential for exploitation.
All-Source Analysis (ASA) Analyzes threat information from multiple sources, disciplines, and agencies across the Intelligence Community. Synthesizes and places intelligence information in context; draws insights about the possible implications.
Targets (TGT) Applies current knowledge of one or more regions, countries, non-state entities, and/or technologies.
Language Analysis (LNG) Applies language, cultural, and technical expertise to support information collection, analysis, and other cybersecurity activities.
: https://doi.org/10.6028/N
IS
T.S
Collect and Operate
(CO)
Collection Operations (CLO) Executes collection using appropriate strategies and within the priorities established through the collection management process.
Cyber Operational Planning
(OPL)
Performs in-depth joint targeting and cybersecurity planning process. Gathers information and develops detailed Operational Plans and Orders supporting requirements. Conducts strategic and operational-level planning across the full range of operations for integrated information and cyberspace operations.
Cyber Operations (OPS) Performs activities to gather evidence on criminal or foreign intelligence entities to mitigate possible or real-time threats, protect against espionage or insider threats, foreign sabotage, international terrorist activities, or to support other intelligence activities.
Investigate
(IN)
Cyber Investigation (INV) Applies tactics, techniques, and procedures for a full range of investigative tools and processes to include, but not limited to, interview and interrogation techniques, surveillance, counter surveillance, and surveillance detection, and appropriately balances the benefits of prosecution versus intelligence gathering.
Digital Forensics (FOR) Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations.
A.3 NICE Framework Work Roles
Table 3 provides a description of each of the work roles described by the NICE Framework. Each work role is identified by the Category and Specialty Area, followed by a sequential number (e.g., SP-RSK-001 is the first work role in the SP Category and RSK Specialty Area). Some of the work role Descriptions originate with external documents (e.g., Committee on National Security Systems Instruction [CNSSI] 4009) and include that information in the description column. This listing will be updated periodically [1]. The definitive source for the most current version of this material can be found in the Reference Spreadsheet for NIST Special Publication 800-181 [4].
: https://doi.org/10.6028/N
IS
T.S
Table 3 - NICE Framework Work Roles
Category Specialty Area Work Role Work Role ID Work Role Description Securely Provision
(SP)
Risk Management
(RSK)
Authorizing Official/Designating Representative
SP-RSK-001 Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation
(CNSSI 4009).
Security Control Assessor SP-RSK-002 Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).
Software Development
(DEV)
Software Developer SP-DEV-001 Develops, creates, maintains, and writes/codes new (or modifies existing) computer applications, software, or specialized utility programs.
Secure Software Assessor SP-DEV-002 Analyzes the security of new or existing computer applications, software, or specialized utility programs and provides actionable results.
Systems Architecture
(ARC)
Enterprise Architect SP-ARC-001 Develops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.
Security Architect SP-ARC-002 Ensures that…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .