The National Institute of Standards and Technology (NIST) has received considerable recognition over the past few years for their development of the Cybersecurity Framework (CSF), which is now widely used as the basis for establishing effective security management systems. The Information Technology Laboratory of NIST has been active in other areas of cybersecurity as well. This includes partnering with the U.S. Department of Commerce to lead the National Initiative for Cybersecurity Education (NICE). NICE is described as “…a partnership between government, academia, and the private sector focused on cybersecurity education, training, and workforce development.” Its mission is to energize and promote a robust network and an ecosystem of cybersecurity education, training, and workforce development.
This Framework was originally developed for use in the federal government, and its scope was expanded in 2010. The first version was published in 2012, followed by updates in 2014 and 2016. The latest update is available as a NIST special publication (NIST SP-800-181).
At 144 pages, this publication may seem daunting at first glance, but the general description in the main body of the document fills only 10 pages. Most of the content is in the form of a series of appendices that describe the following elements:
- Seven categories of common cybersecurity functions
- Thirty-three specialty areas cybersecurity work
- Fifty-two work roles, comprised of specific knowledge, skills, and abilities required to perform tasks in a work role
- Knowledge, Skills, and Abilities (KSAs) required to perform tasks, generally demonstrated through relevant experience or performance-based education and training
- Tasks or specific work activities that could be assigned to a professional working in one of the work roles.
Specific competencies that were included in earlier versions of the Framework have been removed, and will re-appear in a forthcoming update of NIST special publication SP 800-16 (Role-Based Model for Federal Information Technology and Cybersecurity Training).
SANS Institute and the NICE Framework
The SANS Institute has positioned their cybersecurity course in the context of this Framework. They have described the Framework as follows:
“The NICE Framework provides a blueprint to categorize, organize, and describe cyber security work into Specialty Areas, tasks, and knowledge, skills and abilities (KSAs). The Workforce Framework provides a common language to speak about cyber roles and jobs and helps define professional requirements in cyber security.”[1]

There have been other related efforts to address this situation, involving cooperation between the public and private sectors. One notable example is the Cybersecurity Competency Model, which was developed with input from experts from education, business, and industry. That model incorporates competencies included in earlier versions of the Framework, so it is reasonable to assume that it will remain consist with the forthcoming updates to NIST SP 800-16.
All this information provides a potentially valuable resource for employers who are planning or evaluating their workforce, educators, certifying bodies or even those who are considering a career in cybersecurity. This is important, considering the generally accepted observation that there is a distinct shortage of qualified cybersecurity experts.
The effectiveness of these and related resources will ultimately depend on having this information available and presented in a simple and unambiguous manner. Stakeholders are encouraged to learn more about the Framework and Competency Model, and to determine how these tools can be applied in improving the cybersecurity workforce.