Given the ongoing "arms race" in cybersecurity, the shortage of skilled professionals in this field is one of the strongest in computer science. The currently unmet staffing demand in cybersecurity is estimated at over 3 million jobs worldwide. Furthermore, the qualifications of the existing workforce are largely believed to be insufficient. We attempt to gain deeper insights into the nature of the current skill gap in cybersecurity. To this end, we correlate data from job ads and academic curricula using two kinds of skill characterizations: manual definitions from established skill frameworks as well as "skill topics" automatically derived by text mining tools. Our analysis shows a strong agreement between these two analysis techniques and reveals a substantial undersupply in several crucial skill categories, e.g., software and application security, security management, requirements engineering, compliance, and certification. Based on the results of our analysis, we provide recommendations for future curricula development in cybersecurity so as to decrease the identified skill gaps.
翻译:鉴于网络安全中目前存在的“武器竞赛”问题,这一领域的熟练专业人员短缺是计算机科学中最突出的问题之一,目前全世界网络安全方面未满足的人员配置需求估计超过300万个工作。此外,现有劳动力的素质在很大程度上被认为不足。我们试图更深入地了解网络安全中目前技能差距的性质。为此,我们利用两种技能特征将招聘广告和学术课程中的数据联系起来:既有技能框架的手工定义以及文字挖掘工具自动产生的“技能专题”。我们的分析表明,这两种分析技术之间有强烈的共识,并显示在软件和应用安全、安全管理、要求工程、合规和认证等几个关键技能类别中存在严重不足。我们根据我们的分析结果,为未来网络安全课程的开发提供了建议,以便缩小已查明的技能差距。