Summit on Education in Secure Software Final Report
Diana L. Burley, Matt Bishop · eScholarship (California Digital Library) · 2011
Cybersecurity risks pose some of the most serious economic and national security challenges of the 21st century.In order to meet these challenges, the software that controls critical systems and infrastructure must be reliable, robust, and able to satisfy the requirements that are placed upon it.To this end, all people involved in the development and deployment of these systems and infrastructure, from the policymakers who determine what requirements the systems must meet to the businesspeople who provide the support needed to create the systems to the architects, implementers, and operators of these systems, must understand the criticality of reliable, robust, and secure software to control these systems.The notion of "trustworthy computing" embodies many more facets of computing than software implementation, but poorly implemented software undermines all other aspects of trustworthy computing.Thus, a curriculum designed to meet the cybersecurity challenges of the future must integrate principles and practices of secure programming.Because of the breadth of people who will influence the creation and deployment of this software, students studying a variety of technical and non-technical disciplines must recognize the difference between software that is sufficiently robust and software that is not.To determine how best to address this need, the National Science Foundation Directorates of Computer and Information Science and Engineering (CISE) and Education and Human Resources (EHR) jointly sponsored the Summit on Education in Secure Software (SESS).The summit focused on how best to educate students and current professionals on secure programming concepts and practices, and to provide roadmaps indicating both the resources required and the problems that had to be overcome.Organized by The George Washington University and the University of California at Davis, the summit began with a teleconference on September 7, 2010 and continued with a two-day workshop in Washington, DC on October 18 and 19, 2010.SESS participants included members of academia, government, industry, professional organizations, and policy makers from both the public and private sectors.This multi-disciplinary group provided depth to identify technical challenges and breadth to identify operational constraints and opportunities.This enabled the summit participants to examine ways to advance and improve the state of education in secure software.The goal of SESS was to develop a comprehensive agenda focused on the challenges of secure software education.To meet this goal, SESS had three specific objectives. Summary of the FindingsThe findings are presented in the form of "road maps" for constituent groups that describe ways to improve the state of education in secure programming.The road maps explain what the members of the constituent group should know, various methods by which they might be educated, and what resources will be necessary to achieve that level of education.The road maps also identify expected and possible challenges to meeting these goals-the "potholes".Each roadmap concludes with specific recommendations for meeting the articulated educational goals.Although presented as separate road maps, one for each constituent audience (computer science students; non-computer science students; community college students; K-12 students; computer science professionals; and non-computer science professionals), the roadmaps should be considered as different views of a unified educational program that spans kindergarten through professional development, and audiences ranging from software developers to those who focus on management, policy and use to ordinary computer users.Thus, the educational goals in the road maps should be considered the "core fundamental end points" to be reached through instruction guided by a secure programming curriculum.Overall, SESS participants asserted that secure programming must be considered within the context of the system design and deployment process.They highlighted 6 critical points that students of secure programming should know: