Workforce

Professionalizing cyber means new workforce standards

Cybersecurity professionals have the skills and companies have the job openings, but without a common language to populate resumes and job listings, key roles will go unfilled.

The National Initiative for Cybersecurity Education (NICE) is trying to shape the profession’s lexicon with its National Cybersecurity Workforce Framework. It will release a draft for public comment soon.

"This is an exciting time," Ben Scribner, program director for national cybersecurity professionalization and workforce development at the Department of Homeland Security, told the audience at ISACA's CSX North America cybersecurity conference Oct. 19. "We are at the very beginning of establishing cybersecurity as a profession."

But with new territory come new challenges.

"We have a very hard time getting the right people into the right jobs," Scribner said. "It's very hard to match people with the skills that are required for a job."

Government's role as a market-shaper should be decisive, he added. "We don't have the time to let market forces create that profession and make it more formalized," Scribner said. "[Hackers] are in our networks now."

To get educators and employers "singing off the same sheet of music," the National Cybersecurity Workforce Framework lists seven categories of cybersecurity activity:

  • Securely provision
  • Operate and maintain
  • Analyze
  • Oversight and development
  • Collect and operate
  • Protect and defend
  • Investigate

Those categories are divided into 32 specialties aimed at creating an industrywide common language so qualified applicants can advertise their skills and employers can advertise openings in a way that gets jobs filled, said Bill Newhouse, NICE program leader at the National Institute of Standards and Technology.

And there's no question jobs need filling.

Newhouse added that it's important for the industry to define career paths for future cybersecurity professionals to follow. And NICE plans to enlist the help of educators in determining standards and certifications for cybersecurity training.

On the employer side, some companies -- including John Deere and PricewaterhouseCoopers -- have already offered input on the framework, Scribner and Newhouse said, adding that they plan to solicit comments on an official draft of the framework before next spring.

About the Author

Zach Noble is a former FCW staff writer.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.