在网络安全演习中衡量学习情况

Mika Karjalainen, S. Puuska, T. Kokkonen
{"title":"在网络安全演习中衡量学习情况","authors":"Mika Karjalainen, S. Puuska, T. Kokkonen","doi":"10.1145/3436756.3437046","DOIUrl":null,"url":null,"abstract":"In recent years, cyber security exercises have established themselves as an integral part of cyber security education. Cyber security professionals usually work as a part of a team that monitors and responds to incidents in the environment. A sufficiently realistic complex learning environment is necessary for collaborative learning at the expert level. Evaluating the learning outcomes of complex exercises is an important task for both assessing how individuals met the learning objectives, and how to improve the exercise to better serve those goals. This requires the assessment of multiple skill and knowledge categories independently. We leveraged the NIST NICE Cybersecurity Workforce Framework as a base for building knowledge categories for questionnaire use. However, the NICE framework is comprehensive and detailed requiring that the areas of competence assessment needed to be simplified for questionnaire use. We summarized the NICE framework into 44 questions addressed to the individuals who participated in the exercise. A web-based questionnaire was used to query 21 participants’ skill level before and after the exercise, as well as their familiarity and experience with the topic before and during the exercise. The results indicate that cyber security exercises will increase the knowledge of the participant in the knowledge areas that were present in the exercise. This increase was more prominent in cases where the participant was more likely to recognize, and experience events related to that category during the exercise. Furthermore, we concluded that the NICE framework can be used to assess individual know-how and as a basis for knowledge-related questionnaires.","PeriodicalId":250546,"journal":{"name":"Proceedings of the 12th International Conference on Education Technology and Computers","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Measuring Learning in a Cyber Security Exercise\",\"authors\":\"Mika Karjalainen, S. Puuska, T. Kokkonen\",\"doi\":\"10.1145/3436756.3437046\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In recent years, cyber security exercises have established themselves as an integral part of cyber security education. Cyber security professionals usually work as a part of a team that monitors and responds to incidents in the environment. A sufficiently realistic complex learning environment is necessary for collaborative learning at the expert level. Evaluating the learning outcomes of complex exercises is an important task for both assessing how individuals met the learning objectives, and how to improve the exercise to better serve those goals. This requires the assessment of multiple skill and knowledge categories independently. We leveraged the NIST NICE Cybersecurity Workforce Framework as a base for building knowledge categories for questionnaire use. However, the NICE framework is comprehensive and detailed requiring that the areas of competence assessment needed to be simplified for questionnaire use. We summarized the NICE framework into 44 questions addressed to the individuals who participated in the exercise. A web-based questionnaire was used to query 21 participants’ skill level before and after the exercise, as well as their familiarity and experience with the topic before and during the exercise. The results indicate that cyber security exercises will increase the knowledge of the participant in the knowledge areas that were present in the exercise. This increase was more prominent in cases where the participant was more likely to recognize, and experience events related to that category during the exercise. Furthermore, we concluded that the NICE framework can be used to assess individual know-how and as a basis for knowledge-related questionnaires.\",\"PeriodicalId\":250546,\"journal\":{\"name\":\"Proceedings of the 12th International Conference on Education Technology and Computers\",\"volume\":\"10 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-10-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 12th International Conference on Education Technology and Computers\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3436756.3437046\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 12th International Conference on Education Technology and Computers","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3436756.3437046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

近年来,网络安全演习已成为网络安全教育的重要组成部分。网络安全专业人员通常作为监控和响应环境事件的团队的一部分工作。一个足够现实的复杂学习环境是专家级协作学习的必要条件。评估复杂练习的学习效果是一项重要的任务,既可以评估个人如何达到学习目标,也可以评估如何改进练习以更好地服务于这些目标。这需要独立评估多个技能和知识类别。我们利用NIST NICE网络安全劳动力框架作为构建问卷使用的知识类别的基础。然而,NICE框架是全面和详细的,要求能力评估领域需要简化以供问卷使用。我们将NICE框架总结为44个问题,这些问题针对参与练习的个人。采用基于网络的问卷调查方式,对21名参与者在练习前后的技能水平,以及练习前后对该主题的熟悉程度和经验进行了调查。结果表明,网络安全演习将增加参与者在演习中存在的知识领域的知识。当参与者在练习中更有可能识别并经历与该类别相关的事件时,这种增加更为突出。此外,我们得出结论,NICE框架可用于评估个人知识,并作为知识相关问卷的基础。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Measuring Learning in a Cyber Security Exercise
In recent years, cyber security exercises have established themselves as an integral part of cyber security education. Cyber security professionals usually work as a part of a team that monitors and responds to incidents in the environment. A sufficiently realistic complex learning environment is necessary for collaborative learning at the expert level. Evaluating the learning outcomes of complex exercises is an important task for both assessing how individuals met the learning objectives, and how to improve the exercise to better serve those goals. This requires the assessment of multiple skill and knowledge categories independently. We leveraged the NIST NICE Cybersecurity Workforce Framework as a base for building knowledge categories for questionnaire use. However, the NICE framework is comprehensive and detailed requiring that the areas of competence assessment needed to be simplified for questionnaire use. We summarized the NICE framework into 44 questions addressed to the individuals who participated in the exercise. A web-based questionnaire was used to query 21 participants’ skill level before and after the exercise, as well as their familiarity and experience with the topic before and during the exercise. The results indicate that cyber security exercises will increase the knowledge of the participant in the knowledge areas that were present in the exercise. This increase was more prominent in cases where the participant was more likely to recognize, and experience events related to that category during the exercise. Furthermore, we concluded that the NICE framework can be used to assess individual know-how and as a basis for knowledge-related questionnaires.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信