+ All Categories
Home > Internet > NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

Date post: 07-Jan-2017
Category:
Upload: north-texas-chapter-of-the-issa
View: 412 times
Download: 0 times
Share this document with a friend
48
@NTXISSA #NTXISSACSC4 What Should a College Information/Cyber Security Program Contain? Rick Brunner, Col USAF (Retired), EJD, MS, SCF, CISSP, ITIL Enterprise Information/Application Security Architect & Consultant, Adjunct Faculty Robert Half & Collin College 7 October 2016
Transcript
Page 1: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

WhatShouldaCollegeInformation/CyberSecurityProgram

Contain?RickBrunner,ColUSAF(Retired),EJD,MS,SCF,CISSP,ITIL

EnterpriseInformation/ApplicationSecurityArchitect&Consultant,AdjunctFacultyRobertHalf&CollinCollege

7October2016

Page 2: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Disclaimer

Theviews,thoughts,claims,oropinionsinthispresentationaresolelythoseofthepresenter.

Nothinginthispresentationrepresentstheviews,thoughts,claims,oropinionsofCollinCollege,RobertHalf,UnitedStatesAirForce,theAirForceReserves,theDepartmentofDefense,theIntelligenceCommunity,oranyprioremployer.

Page 3: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Objectives• Discusswhyyoumaywantacyber,information,orinformationtechnologysecuritycareer

• Discussstepstoknowwhoyouareandapplythattopotentialsecurityfocusareas

• Discusssubjects,topics,itemsorcharacteristicsthatshouldbeofferedorincludedaspartofacyberorinformationsecuritydegreeprogram

• Compare/contrastdifferentprogramswithintheDFWarea

• Suggestrecommendationsoroptionsthatoneshouldlookatwhileinaprogramorwhenlookingatenteringaprogram

Page 4: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

DefinitionsTerm Meaning Source

ComputerSecurity Measuresandcontrolsthatensureconfidentiality,integrity,andavailabilityoftheinformationprocessedandstoredbyacomputer

CNSS4009

CyberSecurity Theprotectionofinformationassetsbyaddressingthreatstoinformationprocessed,stored,andtransportedbyinternetworkedinformationsystems

ISACAGlossary

InformationAssurance

Measuresthatprotectanddefendinformationandinformationsystemsbyensuringtheiravailability,integrity,authentication,confidentiality,andnon-repudiation.Thesemeasuresincludeprovidingforrestorationofinformationsystemsbyincorporatingprotection,detection,andreactioncapabilities

CNSS4009

InformationSecurity Ensuresthatwithintheenterprise,informationisprotectedagainstdisclosuretounauthorizedusers(confidentiality),impropermodification(integrity),andnon-accesswhenrequired(availability)

ISACAGlossary

InformationTechnologySecurity

Istheprocessofimplementingmeasuresandsystemsdesignedtosecurelyprotectandsafeguardinformation(businessandpersonaldata,voiceconversations,stillimages,motionpictures,multimediapresentations,includingthosenotyetconceived)utilizingvariousformsoftechnologydevelopedtocreate,store,useandexchangesuchinformationagainstanyunauthorizedaccess,misuse,malfunction,modification,destruction,orimproperdisclosure,therebypreservingthevalue,confidentiality,integrity,availability,intendeduseanditsabilitytoperformtheirpermittedcriticalfunctions.

SANS

Page 5: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

100BestJobsTitle U.S News

RankingMedianIncome($)

UnemploymentRate(%)

NumberofJobs (2014-2024)

ComputerSystemsAnalyst 3 82,710 2.6 118,600

SoftwareDeveloper 13 95,510 2.5 135,300

Statistician 17 79,990 4.0 10,100

OperationsResearchAnalyst

18 76,660 3.8 27,600

WebDeveloper 20 63,490 3.4 39,500

ITManager 29 127,640 1.8 53,700

InformationSecurityAnalyst 34 88,890 1.4 14,800

Mathematician 35 103,720 4 700

DatabaseAdministrator 48 80,280 2.0 13,400

ComputerSupportSpecialist

60 61,830 3.3 13,600

ComputerSystemsAdministrator

67 75,790 2.0 30,200

ComplianceOfficer 94 64,950 1.0 8,700Source:http://money.usnews.com/careers/best-jobs/rankings/the-100-best-jobs

Page 6: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

IsaCyberSecurityDegreeWorthIt?

Page 7: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

TheCybersecurityWorkforceDeficit

• Globalcybersecurityworkforceshortfallrangefromonetotwomillionpositionsunfilledby2019

• In2015,about209,000cybersecurityjobswentunfilledintheUnitedStatesalone

Source:HackingtheSkillsShortage--Astudyoftheinternationalshortageincybersecurityskills,CenterforStrategicandInternationalStudiesReport,Sponsored:McAfee,PartofIntelSecurity,2016

Page 8: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

“Knowthyself.”―Socrates

Page 9: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Worthit? Whatis"it"?Increasedknowledge? Almostcertainly

Increasedsatisfactionwithone'sprofession? Quitelikely

Betterjobopportunities? Formanycareerpaths,yes

Additionalknowledgeinotherdomains? Almostcertainly

Betteropportunitiesfornetworkingandsocialconnectivity?

Possibly

Providingabasisforadvanceddegrees? Almostcertainly

Reducinginitialoutlayoffunds? Probablynot

Providingabetterbasistopursueyourownstartup? Notusually

https://www.quora.com/Is-a-computer-security-degree-worth-it Author:GeneSpafford

Page 10: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Worthit? Whatis"it"?(Continued)

Onceyoudefine"it"thenananswercanbemorereadilydetermined

• Highlydependentonyourowntalents,skills,anddedication

https://www.quora.com/Is-a-computer-security-degree-worth-it Author:GeneSpafford

Page 11: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

WhoAreYou• Whatareyourstrengths

• StrengthsFinder- http://freestrengthstest.workuno.com/• Whatdid/areyouenjoy(ing)themost• Whatareyourhobbies• WhatareyourGoals:

• Short(1to2years)• Mid(3to5years)• Long(Anythingpast5years)

• Whatareyoupassionateabout,alternatively,whatdrivesyou• Whatisyourpersonalitytype

• DISC• MyersBriggs

• Whatisyouremotionalintelligencelevel• Whatgotyouherewon’tgetyouthere– Goldsmith

Page 12: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

MatchYourStrengths• Findthatnicheorspecialtyarea

• MatchstrengthsandexperiencewithapotentialSecuritydomain

Strengths Previous Careers Security Focus Areas

Inquisitive, Analytical Law enforcement, Military, IT Incident Response, Forensics

Attention to detail, Focus Technical writing, Legal Policy and Governance, Privacy

Outgoing, Communicator Education, Sales Security Training

Professional, Collect input Sales, Marketing Business Security, BCP, Strategy

Detail oriented, Problem solver Insurance, risk, tax Risk Assessment, Architect

Data driven, Organized Engineering Metrics and Reporting

Technical, Structured Clerical, High tech Technology administration

Source:Mr.ScottPreston,VicePresident,CorporateInformationSecurity,GMFinancial

Page 13: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Source:http://www.cyberdegrees.org/jobs/

Page 14: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

TakeAction

• ResearchtheSecurityfocusareaindetail

• Books,podcasts,tradeorganizations

• Incidentsinthenews,complianceregulations

• Usewebresourcessuchashttp://www.cyberdegrees.org/jobs/

• Showcompetency

• Gainanindustrycertification

• Completeacollegecourse

• Completeacollegedegree

• CreateaPlanofActionandMilestones

Page 15: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4 15

Wherearewenow?

Wheredowewanttogo?

Howdowedothat?

Whatdoweneedtodotogetthere?

WhatDoYouNeedtoDo

CurrentState

GapAnalysis

DesiredState

Page 16: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

DoYouReallyNeedCollegeDegree

• Employersinsistenceonabachelor’sdegreeasabaselinecredentialforcybersecuritywork

• Only23%ofrespondentssayeducationprogramsarepreparingstudentstoentertheindustry

• Abachelor’sdegreeinatechnicalfieldisrankedthirdamongmosteffectivewaystoacquirecybersecurityskills,behindhands-onexperienceandprofessionalcertifications

• Adegreeisasignalofgeneralcompetenceratherthanindicatorofrelevantcybersecurityskills

Source:HackingtheSkillsShortage--Astudyoftheinternationalshortageincybersecurityskills,CenterforStrategicandInternationalStudiesReport,Sponsored:McAfee,PartofIntelSecurity,2016

Page 17: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

AnotherView

Source:UnderstaffedandatRisk--Today’sITSecurityDepartment,IndependentlyconductedbyPonemonInstituteLLC,SponsoredbyHPEnterpriseSecurityPublicationDate:February2014

Page 18: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

DoYouReallyNeedCollegeDegree(Continued)

• Averagecostofa4-yeardegree(tuition,fees,roomandboard)• StateSchool—$78,000

• TexasResident—$23,140/year• TexasNonresident—$32,738/year

(http://www.collegeforalltexans.com/apps/collegecosts.cfm?Type=1&Level=1)

• PrivateSchool—2XStateSchool

• Averagestudentloandebt• $37,000/graduate• Notreportedforthosethatdidnotgraduate

• ConsumerReportsnationalsurveyon1500studentloanborrowers:• 44%leftcollege;cuttingbackondailylivingexpensesinordertopayloan• 28%delayingmajorgoalslikebuyingahouse• 37%putoffsavingforretirement• 45%knowingwhattheyknownow,theircollegeexperiencewasn’tworththecost

Source:HavingtheCollegeMoneyTalk,ConsumerReports,August2016

Page 19: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Alternatives

• ProfessionalCertifications&Programs• Non-traditional• 2-Yeardegrees

Page 20: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

ProfessionalCertifications&Programs• Adegreewillonlytakeyousofarupthejobladder(3rd criteriabehind

experienceandcertification)• ProfessionalSecuritycertificationisnecessary(2nd criteriabehind

experience)• Theycomeinallshapesandsubjects– fromforensicstointrusionto

ethicalhacking• Regardlessofthetopicorlevel:

• Canbeusedacrossjobsandorganizations• Consistsoftrainingandafinalexam• Mustberenewedperiodically(every3to4years)• Needcontinuingeducationcreditsforreaccreditation

• Theycanbeexpensiveandtime-consuming• Anentry-levelcredentialcantakethreetoninemonthstocompleteandsetyou

back$300-$600fortheexam• Theycanleadtopromotion,betterjobprospectsand/oraraise

• SANSsurveyreportedsalaryincreasesofupto5%afteraccreditationSource:http://www.cyberdegrees.org/resources/certifications/

Page 21: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

15Top-PayingCertificationsfor2016Rank Certification Granting

OrganizationAverageSalary($)

1 AWSCertifiedSolutionsArchitect- Associate AWS 125,871

2 CertifiedinRiskandInformationSystemsControl(CRISC) ISACA 122,954

3 CertifiedInformationSecurityManager(CISM) ISACA 122,291

4 CertifiedInformationSystemsSecurityProfessional(CISSP) ISC2 121,923

5 ProjectManagementProfessional(PMP®) PMI 116,094

6 CertifiedInformationSystemsAuditor(CISA) ISACA 113,320

7 CiscoCertifiedInternetworkExpert(CCIE)RoutingandSwitching Cisco 112,858

8 CiscoCertifiedNetworkAssociate(CCNA)DataCenterr Cisco 107,045

9 CiscoCertifiedDesignProfessional(CCDP) Cisco 105,008

10 CertifiedEthicalHacker(CEH) EC-Council 103,297

11 SixSigmaGreenBelt CouncilofSixSigmaCertification

102,594

12 CitrixCertifiedProfessional- Virtualization(CCP-V) Citrix 102,138

13 CiscoCertifiedNetworkingProfessional(CCNP)Security Cisco 101,414

14 ITIL®v3Foundation APMGroupLimited

99,868

15 VMwareCertifiedProfessional5- DataCenterVirtualization(VCP5-DCV) VMware 99,334

Source:https://www.globalknowledge.com/us-en/content/articles/top-paying-certifications/

Page 22: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

HowDoYouGetYourFootintheDoor(Non-Traditional)?

• Thereisnoonetruepathtoworkingincybersecurity• TrainingeneralIT

• Manyexpertssuggestthatyoubeginwithajob,internshiporapprenticeshipinIT

• Focusyourinterests• Employerssuggestyoufocusonanarea(e.g.networkingsecurity)anddoit

well• Thinkahead5-10yearstoyour“ultimatesecuritycareer”• LookforstartITjobsthatwillsupplyyouwiththerightskills

• Gainpracticalexperience• Gainprofessionalsecuritycertification• Usehttp://www.cyberdegrees.org/resources/transitioning-from-

general-it/#starter websiteasaresourceinyourjourneySource:http://www.cyberdegrees.org/resources/transitioning-from-general-it/#starter

Page 23: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

“Educationisthekindlingofaflame,notthefillingofavessel.”―Socrates

Page 24: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

WhatisaCyberSecurityDegree• Thecybersecuritycareerfieldisconstantlygrowingandchanging• Thereareanincreasingnumberofcybersecuritydegreeprograms,andtherearealsomany

degreeprogramsthatcanleadtocareersinthecybersecurityfield• Manyofthesedegreeprogramsfallwithinthefivetraditionalsub-disciplinesofcomputing:

• ComputerScience• ComputerEngineering• InformationSystems• InformationTechnology• SoftwareEngineering

• Otherdegreeprogramsthatcanalsoleadyouthereinclude• Business• Science• Law• Engineering• CriminalJustice• Otherdegrees

Source:https://niccs.us-cert.gov/education/degree-programs

Page 25: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

HowDoYouChooseaProgram

• Lookforinterdisciplinarydegreethatincludescomputerprogramming,probabilityandstatistics,systemarchitecture,softwareengineering,securesystemsdesign,ethics,business,communication,technicalwriting,teamwork,andsoforth

• Wheretobegin• 2-YearPrograms• 4-YearPrograms

Source:http://www.cyberdegrees.org/listings/

Page 26: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

2-YearProgram• Atechnical2-Yearprogramshouldincludethefollowingcoreknowledgeunits

(KU):• BasicDataAnalysis• BasicScriptingorIntroductoryProgramming• CyberDefense• CyberThreats• FundamentalSecurityDesignPrinciples• InformationAssuranceFundamentals• IntrotoCryptography• ITSystemsComponents• NetworkingConcepts• Policy,Legal,Ethics,andCompliance• SystemAdministration

• Lookforcoursesthatgiveyoualotofhands-onexperiencewithrealworldproblems

Source:NationalNSA/DHSCentersofAcademicExcellenceinInformationAssurance/CyberDefenseKnowledgeUnits,https://www.iad.gov/NIETP/documents/Requirements/CAE_IA-CD_KU.pdf

Page 27: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

IncorporatingCybersecurityintoExistingCurricula(Science,Technology,EngineeringandMathematics[STEM])

• TechnicalDualCreditatCollinCollege• AllenIndependentSchoolDistrict(ISD)• ProsperISD• FriscoISD• WylieISD

• StudentcompletesprogramatCollin• AssociateofAppliedScience(AAS)• Certification

• 4-YearPrograms• UniversityofTexas—Dallas(UTD)• UniversityofNorthTexas(UNT)

Page 28: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

4-YearProgram

• Shouldincludeallofthe2-YearprogramKUsandtheseadditionalKUs:• Databases• NetworkDefense• NetworkingTechnologyandProtocols• OperatingSystemsConcepts• ProbabilityandStatistics• SoftwareEngineering

• Haveadvancedclassessuchascloudcomputing,forensicaccounting,wirelesssensornetworks

• Lookforcoursesthatgiveyoualotofhands-onexperiencewithrealworldproblems

Source:NationalNSA/DHSCentersofAcademicExcellenceinInformationAssurance/CyberDefenseKnowledgeUnits,https://www.iad.gov/NIETP/documents/Requirements/CAE_IA-CD_KU.pdf

Page 29: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

WhatElse

• Havespecificcriteriaforchoosingadegreeprogram(cost/geography/commuteetc.)

• Lookforaprogramthatprovidesbestvalue• Evaluatingprograms

• NSA/DHSCurrentNationalCentersofAcademicExcellenceDesignatedInstitutions

• PonemonInstituteReport—2014BestSchoolsForCybersecurity

• Usethesewhenyou’redecidingbetweenschools

Source:http://www.cyberdegrees.org/listings/

Page 30: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

NSA/DHSCurrentNationalCentersofAcademicExcellenceDesignatedInstitutions

Inadditiontocoreknowledgeunits,theNSA/DHSalsoinsiststhataprogram:

• Demonstratesoutreachandcollaboration• HasacenterforInformationAssurance(IA)/CyberDefense(CD)education

• FostersarobustandactiveIA/CDacademicprogram• EnsuresIA/CDisamultidisciplinarysciencewithintheinstitution

• SupportsthepracticeofIA/CDthroughouttheinstitution• EncouragesstudentandfacultyIA/CDresearch

Source:http://www.cyberdegrees.org/listings/

Page 31: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

2014BestSchoolsForCybersecurity(PonemonInstituteReport)

Characteristicsthatsetthebestschoolsapart:• Interdisciplinaryprogramthatcutsacrossdifferent,butrelatedfields– especially

computerscience,engineeringandmanagement• DesignatedbytheNSAandDHSasacenterofacademicexcellenceininformation

assuranceeducation• Curriculumaddressesbothtechnicalandtheoreticalissuesincybersecurity• Bothundergraduateandgraduatedegreeprogramsareoffered• Adiversestudentbody,offeringeducationalopportunitiestowomenandmembers

ofthemilitary• Facultycomposedofleadingpractitionersandresearchersinthefieldof

cybersecurityandinformationassurance• Hands-onlearningenvironmentwherestudentsandfacultyworktogetheron

projectsthataddressreallifecybersecuritythreats• Emphasisoncareerandprofessionaladvancement• Coursesonmanagement,informationsecuritypolicyandotherrelatedtopics

essentialtotheeffectivegovernanceofsecureinformationsystems• Graduatesofprogramsareplacedinprivateandpublicsectorpositions

Source:http://www.cyberdegrees.org/listings/ andhttp://www.ponemon.org/local/upload/file/2014%20Best%20Schools%20Report%20FINAL%202.pdf

Page 32: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

2014BestSchoolsForCybersecurity(PonemonInstituteReport)

Insistenceoninterdisciplinarystudies• Courseworktoincludemanagement,law,business,ethics,

probabilityandstatistics,communications,technicalwriting,andteamwork*

• Astrongdegreeisgoingtoprepareyouforissuesyou’llbediscussingwithnon-technicalcolleagues

Source:http://www.cyberdegrees.org/listings/ andhttp://www.ponemon.org/local/upload/file/2014%20Best%20Schools%20Report%20FINAL%202.pdf

*Note:probabilityandstatistics,communications,technicalwriting,andteamworkwereaddedbypresenter

Page 33: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

NationalHackingorCapturetheFlagCompetitions

• Provideaneffectivechanneltoidentifytalentanddevelopcybersecurityskills

• Overthreeinfivesurveyrespondentssaynationalhackingcompetitionsplayakeyroleindevelopingcybersecuritytalent

• Overalltwoinfiverespondentscitehackingcompetitionsasamongthemosteffectivewaytoacquireskills

Source:HackingtheSkillsShortage--Astudyoftheinternationalshortageincybersecurityskills,CenterforStrategicandInternationalStudiesReport,Sponsored:McAfee,PartofIntelSecurity,2016

Page 34: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

NationalCollegiateCyberDefenseCompetition(CCDC)

• CCDCEventsaredesignedto:• Buildameaningfulmechanismbywhichinstitutionsofhighereducationmayevaluate

theirprograms• Provideaneducationalvenueinwhichstudentsareabletoapplythetheoryandpractical

skillstheyhavelearnedintheircoursework• Fosteraspiritofteamwork,ethicalbehavior,andeffectivecommunicationbothwithin

andacrossteams• Createinterestandawarenessamongparticipatinginstitutionsandstudents

• Competition:• Eachteambeginsthecompetitionwithanidenticalsetofhardwareandsoftware• Teamscoredontheirabilitytodetectandrespondtooutsidethreats,maintainavailability

ofexistingservicessuchasmailserversandwebservers,respondtobusinessrequestssuchastheadditionorremovalofadditionalservices,andbalancesecurityneedsagainstbusinessneeds

• Anautomatedscoringengineisusedtoverifythefunctionalityandavailabilityofeachteam’sservicesonaperiodicbasisandtrafficgeneratorscontinuouslyfeedsimulatedusertrafficintothecompetitionnetwork

• Avolunteerredteamprovidesthe“externalthreat”allInternet-basedservicesfaceandallowstheteamstomatchtheirdefensiveskillsagainstliveopponents

http://www.nationalccdc.org/index.php/competition/about-ccdc/mission

Page 35: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

NationalCollegiateCyberDefenseCompetition(Continued)

• Demonstrates:• “TEAM”Work• Technicalabilitytocounter/mitigate/minimize“real”worldattacks

• Teamsunderstandinginmaintaining“BusinessServices”whileunderattack

• Results• Manyparticipantsreceiveonthespotjoboffersfrombusinessentitieswhileatthecompetition

• Someareinthe6figurerange• Manyareinthehigh5figurerange

Page 36: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

AdditionalPresenter’sView

Source:http://www.texascisocouncil.org/resources

Page 37: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

AdditionalPresenter’sView(Continued)

• Demonstratedtechnicalwritingandcommunicationscapabilities

• EmployedassummerhireoraspartofanInternshipProgram

• PerformvolunteerworkforaCharity• JoinInfraGardandlocalChapternearyourschool• Join(ifpossible):

• InformationSystemsSecurityAssociationandalocalChapternearyourschool

• ISACAandalocalChapternearyourschool

Page 38: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

“Ifyoupursueadegreeandtakealltheeasycoursesandblowoffsomeoftheassignments,thedegreemaybeworthalotlessthanifyoupursueamorechallengingpath.Ifyouliveoncampusandgetinvolvedwithsomeoftheclubsandorganizationsforstudentsyourexperiencewillbeverydifferentfromsomeonewhotakeseverythingonline.”

GeneSpafford

Page 39: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

WhataboutaMaster’sDegreeorHigher?

• Itdepends• Doyourhomework:

• WilltheMSgiveyourealtechnicalskills• HaveyouconsideredaMaster’sinComputerScienceorTechnology

ManagementwithaconcentrationinInformationSecurity• ITiscontinuallychanging– isyourMSinCyberSecuritygoingtobeahelpful

qualificationin10years• DoesgainingaMaster’sincreaseyourjobopportunities• Canyoujustifythecostofadegree(e.g.$30k)intermsofROI?Inother

words,willitsignificantlyincreaseyourearningpowerinthefuture

• Iftheanswertothesequestionsis“no,”youmaywanttoholdoffontheinvestment.

Source:http://www.cyberdegrees.org/listings/#Do_I_Need_a_Degree

Page 40: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

LocalSchools

UniversityofDallas

Page 41: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

CompareandContrast

School 2-Year 4-YearTechnicalDualCredit

CertificateProgram

AssociatesofAppliedScience Bachelors Masters

MasterofBusiness

Administration PhD

DHS/NSADesignatedCenterofExcellence

CollinCollege X X X X

RichlandCollege X X X X

UniversityofTexasatArlington X

UniversityofTexasatDallas X X X X X X XUniversityofNorthTexas X X X X X X XUniversityofDallas X X X X XSouthernMethodistUniversity X X X X XWesternGovernorsUniversityTexas X X X X

Page 42: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Conclusions

• Information/CyberSecurityopportunitiesabound• Information/CyberSecurityisarelativelyyoungfieldof

study• Collegedegreeprogramsvary• WorkExperienceandProfessionalCertificationsremain

moreimportantthanadegreeinthehiringdecision• Arecognizedcollegeorgraduate-leveldegreeprogramis

essentialorveryimportantinthehiringdecision• Courseworktoincludemanagement,law,business,ethics,

probabilityandstatistics,communications,technicalwriting,andteamwork

ACollegeDegreeinInformation/CyberSecurityisworthit,butdoyourhomework

Page 43: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Recommendations

• Define“it”• Knowyourstrengthsandweaknesses• Knowyourselfandwhereyoulike/wanttogo• Doyourhomework• Lookatyourselfobjectively• Identifyactionsyouneedtotakeinordertomoveforeword

• AreyousureyouwantaCybersecuritycareer

Page 44: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Recommendations(Continued)

• ProfessionalCertification• CurrentEmployer• Veterans

• GIBill• FederalVirtualTrainingEnvironment(FedVTE)

• Shortcoursesatlittletonocost• CollegeandDualCreditstudents

• Planontakingcertificationcourse/examwhileinschool• UseISC2AssociatesProgram toyouradvantage• Checkothercertificationorganizationrequirements

Page 45: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Recommendations(Continued)• College

• Read“HavingtheCollegeMoneyTalk”article,ConsumerReports,August2016

• Usetheinformationprovidedinpresentationandfurthercomplete“CompareandContrast”slideindecidingwhichprogramis“right”for“you”

• Getinvolved• Clubs,organizationssuchasISSA-NTX• “CapturetheFlag”exercises• CollegiateCyberDefenseCompetition

• Canleadtostrongemploymentopportunitieswithpotentiallucrativesalaries• Ensureinterdisciplinaryprogramcutsacrossdifferent,butrelatedfields–

especiallycomputerscience,engineering,management,business,ethics,probabilityandstatistics,technicalwriting,communications

• Takethe“hard”courses• Use/takepartinanyinternshipswithlocalindustryandexcel

• Summerhireprograms• Semesterprograms

Page 46: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

Recommendations(Continued)

• MS,MBAorPhD• Basedonyou,yourneedsandwants

• PossibleFinancialOptions• TheHazlewoodAct- StateofTexas• Veterans

• GIBill

• Currentemployer• https://www.cappex.com/ FindingSchoolsandScholarships• CyberCorps®:ScholarshipforService(SFS)https://niccs.us-

cert.gov/education/cybercorps-scholarship-service-sfs• Has2,300graduatessince2000witha93%placementrate

• SpecificSchoolPrograms• Talktopeopleinthefield

Page 47: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4

“ThemoreIlearn,themoreIrealizehowmuchIdon'tknow.”

―AlbertEinstein

Page 48: NTXISSACSC4 - What Should a College Information or Cyber Security Program Contain?

@NTXISSA#NTXISSACSC4@NTXISSA#NTXISSACSC4

The Collin College Engineering DepartmentCollin College StudentChapteroftheNorthTexasISSA

NorthTexasISSA(InformationSystemsSecurityAssociation)

NTXISSACyberSecurityConference– October7-8,2016 48

Thankyou


Recommended