Last week, the National Academy of Sciences (NAS) released a study on “Professionalizing the Nation’s Cyber Workforce? Criteria for Decision-Making.” The study examined three questions:
- Is cybersecurity ready to be professionalized across the nation?
- Which jobs within the cybersecurity field should be professionalized and to what degree?
- Should the federal government lead this effort single handedly?
The study was commissioned by the Department of Homeland Security. NAS, under the auspices of the Computer Science and Telecommunications Board of the National Research Council, carried out the study by forming a committee and holding several workshops with relevant stakeholders. CompTIA participated in this process and applauds NAS for its inclusiveness and outreach to relevant stakeholders. The primary recommendation from the report was:
Activities by the federal government and other entities to professionalize a cybersecurity occupation should be undertaken only when that occupation has well-defined and stable characteristics, when there are observed deficiencies in the occupational workforce that professionalization could help remedy, and when the benefits outweigh the costs.
Beyond the recommendation, however, the report listed seven conclusions:
- More attention to both the capacity and capability of the U.S. cybersecurity workforce is needed.
- Although the need for cybersecurity workers is likely to continue to be high, it is difficult to forecast with certainty the number of workers required or the needed mix of cybersecurity knowledge and skills.
- The cybersecurity workforce encompasses a variety of contexts, roles and occupations and is too broad and diverse to be treated as a single occupation or profession. Whether and how to professionalize will vary according to role and context.
- Because cybersecurity is not solely a technical endeavor, a wide range of backgrounds and skills will be needed in an effective national cybersecurity workforce.
- Professionalization has multiple goals and can occur through multiple mechanisms.
- The path toward professionalization of a field can be slow and difficult, and not all portions of a field can or should be professionalized at the same time.
- Professionalization has associated costs and benefits that should be weighed when making decisions to undertake professionalization activities.