WHAT THE PROFESSION OF CYBERSECURITY NEEDS TO KNOW AND DO
Dan Shoemaker, Anne Kohnke, Ken E. Sigler · EDPACS · 2019
Presently, 71% of annual losses are due to failures in the physical and human attack domains, while electronic breaches account for roughly 29%. While the lowest percentage of losses (29%) falls into the area of the classic technology-based attacks, unfortunately these are often the only kind of attacks factored into an organization’s cybersecurity planning. Surprisingly, in most organizations, human or physical types of threats are simply not part of traditional cyberdefense thinking. Most active cyberdefense solutions do not consider embodying integrated and well-defined behavioral controls into the cybersecurity process. And as a result, well executed attacks against the non-electronic attack surface are almost certain to succeed. We argue that the profession must find ways to ensure that the real-world practice of cybersecurity involves the creation and adoption of a complete, correct, and highly effective set of well-defined and commonly accepted controls; ones that are capable of closing off every feasible type of adversarial action. To be completely effective, the solution must amalgamate all of the essential concepts of cyberdefense into a single unifying practice model, one that has real-world currency. Professional societies help to serve as the developers and sanctioners of the fundamental ideas in their respective fields and the creation of the CSEC2017 document provides an authoritative statement of the elements of the field of cybersecurity for a broad array of practitioners. This paper discusses the CSEC2017 thought model and outlines the eight knowledge areas specified for the discipline to represent the complete body of knowledge within the field.