Bukauskas Linas, Brilingaitė Agnė, Juozapavičius Aušrius, Lepaitė Daiva, Ikamas Kęstutis, Andrijauskaitė Rimantė
Institute of Computer Science, Vilnius University, Didlaukio Str. 47, LT-08303 Vilnius, Lithuania.
General Jonas Žemaitis Military Academy of Lithuania, Šilo Str. 5A, LT-10322 Vilnius, Lithuania.
Heliyon. 2023 Jan 10;9(1):e12808. doi: 10.1016/j.heliyon.2023.e12808. eCollection 2023 Jan.
The impact of cybersecurity (CS) on public well-being is increasing due to the continued digitisation process of all industry sectors. The protection of information systems rests upon a sufficient number of CS specialists and their competences. A cyber-competence map describing the capacity and trends of the CS workforce is an essential element of the workforce development strategy. Large enterprises tend to have narrowly specialised employees with clearly identifiable roles. Still, most enterprises in small countries are SMEs. Therefore, the tasks and responsibilities of many CS-related specialists overlap the functions of several roles. This paper aims to develop a small-state cybersecurity competence map consistent with the standards of professional organisations. The work applies a combined qualitative and quantitative methodological approach to collect data using questionnaires and expert interviews in the CS field organisations. The study includes a representative public survey, a large-scale survey of company executives, an exploratory CS expert survey, and a comprehensive job posting analysis. Finally, a national CS competence map is presented and verified using two qualitative semi-structured interviews with field professionals. Even though the map reflects a status of a small nation state, it is activity-based and might be applicable in any country. As a future research direction, we will investigate the impact of early and late exposure to cybersecurity competences in education and framework applicability.
由于所有行业部门持续的数字化进程,网络安全(CS)对公众福祉的影响正在增加。信息系统的保护依赖于足够数量的网络安全专家及其能力。描述网络安全劳动力的能力和趋势的网络能力地图是劳动力发展战略的重要组成部分。大型企业往往拥有角色明确、专业化程度高的员工。然而,小国的大多数企业是中小企业。因此,许多与网络安全相关的专家的任务和职责与多个角色的职能重叠。本文旨在绘制一份符合专业组织标准的小国网络安全能力地图。这项工作采用定性和定量相结合的方法,通过对网络安全领域组织进行问卷调查和专家访谈来收集数据。该研究包括一项具有代表性的公众调查、一项对公司高管的大规模调查、一项探索性的网络安全专家调查以及一项全面的招聘信息分析。最后,通过对该领域专业人士进行两次定性半结构化访谈,展示并验证了一份国家网络安全能力地图。尽管该地图反映的是一个小国的状况,但它是以活动为基础的,可能适用于任何国家。作为未来的研究方向,我们将研究在教育中早期和晚期接触网络安全能力的影响以及框架的适用性。