当前位置: X-MOL 学术Comput. Sci. Rev. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Cyber security training for critical infrastructure protection: A literature review
Computer Science Review ( IF 12.9 ) Pub Date : 2021-02-24 , DOI: 10.1016/j.cosrev.2021.100361
Nabin Chowdhury , Vasileios Gkioulos

Introduction:

Today, cyber-security curricula are available across educational types and levels, including a vast array of programs and modules tailored to specific sectors of industry and audiences, to allow more targeted delivery of knowledge. Nonetheless, general agreement on best measures and methods for cybersecurity training has yet to be reached.

Objective:

In this study, we seek to establish the current state-of-the-art in cyber-security training offerings for critical infrastructure protection and the key performance indicators (KPIs) that allow evaluating their effectiveness. Particular focus is given in this study on the aviation, energy and nuclear sectors.

Methodology:

Accordingly, the article presents the findings of a systematic literature review that collected relevant literature produced after 2000. The identified sources have been examined according to a formal data extraction form, allowing the analysis of relevant training solutions, methodologies, target groups and focus areas.

Results:

The results show that solutions that provide hands-on experience, team skills development, high level of real-life fidelity are often preferred to other options, with simulation-based solutions showing the highest amount of research and development. Nonetheless, researchers have not reached agreements on optimal training delivery methods and design of cybersecurity exercises.

Conclusion:

Consequently, research on improving current cybersecurity training offerings should be conducted, to demonstrate whether integrating advantageous attributes from different delivery methods could produce more comprehensive and effective solutions.



中文翻译:

针对关键基础设施保护的网络安全培训:文献综述

介绍:

如今,网络安全课程可用于各种教育类型和级别,包括针对行业和受众的特定部门量身定制的大量计划和模块,以使知识的交付更具针对性。但是,尚未就网络安全培训的最佳措施和方法达成普遍协议。

客观的:

在这项研究中,我们寻求建立用于关键基础设施保护的当前网络安全培训产品和可评估其有效性的关键绩效指标(KPI)。本研究特别关注航空,能源和核能领域。

方法:

因此,本文介绍了系统的文献综述的结果,该文献综述收集了2000年后产生的相关文献。已根据正式的数据提取表对确定的来源进行了检查,从而可以分析相关的培训解决方案,方法,目标群体和重点领域。

结果:

结果表明,提供动手经验,团队技能发展,高水平的真实逼真度的解决方案通常比其他选择更受青睐,基于仿真的解决方案显示出最高的研发水平。但是,研究人员尚未就最佳培训提供方法和网络安全演习设计达成协议。

结论:

因此,应进行有关改进当前网络安全培训产品的研究,以证明整合不同交付方式的有利属性是否可以产生更全面,有效的解决方案。

更新日期:2021-02-24
down
wechat
bug