Javascript must be enabled to continue!
Bridging Cybersecurity Practice and Law: A Hands-On, Scenario-Based Curriculum Using the NICE Framework to Foster Skill Development
View through CrossRef
In an increasingly interconnected world, cybersecurity professionals play a pivotal role in safeguarding organizations from cyber threats. To secure their cyberspace, organizations are forced to adopt a cybersecurity framework such as the NIST National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity (NICE Framework). Although these frameworks are a good starting point for businesses and offer critical information to identify, prevent, and respond to cyber incidents, they can be difficult to navigate and implement, particularly for small-medium businesses (SMBs). To help overcome this issue, this paper identifies the most frequent attack vectors to SMBs (Objective 1) and proposes a practical model of both technical and non-technical tasks, knowledge, skills, abilities (TKSA) from the NICE Framework for those attacks (Objective 2). This research develops a scenario-based curriculum. By immersing learners in realistic cyber threat scenarios, their practical understanding and preparedness in responding to cybersecurity incidents is enhanced (Objective 3). Finally, this work integrates practical experience and real-life skill development into the curriculum (Objective 4). SMBs can use the model as a guide to evaluate, equip their existing workforce, or assist in hiring new employees. In addition, educational institutions can use the model to develop scenario-based learning modules to adequately equip the emerging cybersecurity workforce for SMBs. Trainees will have the opportunity to practice both technical and legal issues in a simulated environment, thereby strengthening their ability to identify, mitigate, and respond to cyber threats effectively. We piloted these learning modules as a semester-long course titled “Hack Lab” for both Computer Science (CS) and Law students at CSU during Spring 2024 and Spring 2025. According to the self-assessment survey by the end of the semester, students demonstrated substantial gains in confidence across four key competencies (identifying vulnerabilities and using tools, applying cybersecurity laws, recognizing steps in incident response, and explaining organizational response preparation) with an average improvement of +2.8 on a 1–5 scale. Separately, overall course evaluations averaged 4.4 for CS students and 4.0 for Law students, respectively, on a 1–5 scale (college average is 4.21 and 4.19, respectively). Law students reported that hands-on labs were difficult, although they were the most impactful experience. They demonstrated a notable improvement in identifying vulnerabilities and understanding response processes.
Title: Bridging Cybersecurity Practice and Law: A Hands-On, Scenario-Based Curriculum Using the NICE Framework to Foster Skill Development
Description:
In an increasingly interconnected world, cybersecurity professionals play a pivotal role in safeguarding organizations from cyber threats.
To secure their cyberspace, organizations are forced to adopt a cybersecurity framework such as the NIST National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity (NICE Framework).
Although these frameworks are a good starting point for businesses and offer critical information to identify, prevent, and respond to cyber incidents, they can be difficult to navigate and implement, particularly for small-medium businesses (SMBs).
To help overcome this issue, this paper identifies the most frequent attack vectors to SMBs (Objective 1) and proposes a practical model of both technical and non-technical tasks, knowledge, skills, abilities (TKSA) from the NICE Framework for those attacks (Objective 2).
This research develops a scenario-based curriculum.
By immersing learners in realistic cyber threat scenarios, their practical understanding and preparedness in responding to cybersecurity incidents is enhanced (Objective 3).
Finally, this work integrates practical experience and real-life skill development into the curriculum (Objective 4).
SMBs can use the model as a guide to evaluate, equip their existing workforce, or assist in hiring new employees.
In addition, educational institutions can use the model to develop scenario-based learning modules to adequately equip the emerging cybersecurity workforce for SMBs.
Trainees will have the opportunity to practice both technical and legal issues in a simulated environment, thereby strengthening their ability to identify, mitigate, and respond to cyber threats effectively.
We piloted these learning modules as a semester-long course titled “Hack Lab” for both Computer Science (CS) and Law students at CSU during Spring 2024 and Spring 2025.
According to the self-assessment survey by the end of the semester, students demonstrated substantial gains in confidence across four key competencies (identifying vulnerabilities and using tools, applying cybersecurity laws, recognizing steps in incident response, and explaining organizational response preparation) with an average improvement of +2.
8 on a 1–5 scale.
Separately, overall course evaluations averaged 4.
4 for CS students and 4.
0 for Law students, respectively, on a 1–5 scale (college average is 4.
21 and 4.
19, respectively).
Law students reported that hands-on labs were difficult, although they were the most impactful experience.
They demonstrated a notable improvement in identifying vulnerabilities and understanding response processes.
Related Results
Cybersecurity and Organisational Performance – the Interplay
Cybersecurity and Organisational Performance – the Interplay
The interplay between cybersecurity and organisational performance is multifaceted in nature, as it is related to how cybersecurity impacts and is impacted by various organisationa...
From Constitutional Comparison to Life in the Biosphere
From Constitutional Comparison to Life in the Biosphere
From Constitutional Comparison to Life in the Biosphere is a monograph that argues for a fundamental reorientation of constitutional law around the realities of biospheric interdep...
Autonomy on Trial
Autonomy on Trial
Photo by CHUTTERSNAP on Unsplash
Abstract
This paper critically examines how US bioethics and health law conceptualize patient autonomy, contrasting the rights-based, individualist...
Cultivating self-efficacy to empower professionals’ re-up skilling in cybersecurity
Cultivating self-efficacy to empower professionals’ re-up skilling in cybersecurity
Purpose
The accelerated digital transformation and the growing emphasis on privacy, safety and security present ongoing challenges for cybersecurity experts. Alongside these challe...
The Understanding of Curriculum Change
The Understanding of Curriculum Change
The curriculum is the key and indispensable part of the academic and training system that contains immense aims of scientific, thought, social, political, cultural, and moral facet...
Cybersecurity Knowledge Deterioration and the role of Gamification Intervention
Cybersecurity Knowledge Deterioration and the role of Gamification Intervention
Cybersecurity is becoming an overly critical issue in contemporary times. Cyberspace safety is declining, and this covers all categories of persons, businesses, institutions, and e...
Cybersecurity Startup Founders in Greater Washington, DC: Prior Experience Required
Cybersecurity Startup Founders in Greater Washington, DC: Prior Experience Required
The Greater Washington region is one of three leading cybersecurity industry clusters in the world. The proximity of this region to federal agencies, particularly in national secu...
Mezinárodní právo na prahu 21. století (dosažený stav, neúspěchy a perspektivy)
Mezinárodní právo na prahu 21. století (dosažený stav, neúspěchy a perspektivy)
The study deal with selected problems of international law at the time of change of the 20th and 21st centuries. Such a milestone gives an opportunity to review the achieved state ...

