CybersecurityU.S. intensifies campaign to train, hire, retain cybersecurity professionals

Published 31 August 2010

The cyber threats to both government and public network intensify, and the U.S. federal agencies must find ways to attract qualified workers and develop new skills internally; NIST’s Dr. Ernest McDuffie: “We’ve got a problem of where the next generation of engineers are going to come from— Awareness, education, workforce, and training all have to come together”

Across the U.S. federal government, agencies are grappling with a shortage of cybersecurity professionals who have the skills to protect their computers and networks from relentless, and increasingly dangerous, forms of attack (“Shortage of cyber workers in the U.S.,” 22 July 2010 HSNW; and “U.S. government encounters shortage of skilled cyber-security workers,” 7 April 2010 HSNW).

DHS and the U.S. Air Force received authority to expedite the hiring of almost 1,700 cybersecurity pros over the next two years, but InformationWeek’s J. Nicholas Hoover writes that fast-track hiring is a stopgap solution. The long-term answer requires new training programs and better ways of attracting and retaining employees with the sought-after skills.

At a recent cybersecurity workforce conference at the National Institute for Standards and Technology’s offices in Gaithersburg, Maryland, chief information security officers and other government IT managers identified a range of related issues: a confusing morass of certifications; HR processes that identify candidates based on buzzwords, not bona fide experience; drawn-out hiring and security-clearance processes; federal mandates that push unqualified people to the front of the hiring line; and competition with the private sector for job candidates.

Given the scope and urgency of the challenge, cybersecurity workforce development has become a key IT initiative of the Obama administration and, government officials say, one of the top priorities of White House cybersecurity coordinator Howard Schmidt (“Schmidt: private sector key to warding off cyber attacks,” 8 April 2010 HSNW).

Cybersecurity education and workforce development were addressed in the Bush administration’s Comprehensive National Cybersecurity Initiative, and in April that work was folded into a broader effort called the National Initiative for Cybersecurity Education (NICE), led by NIST’s Dr. Ernest McDuffie.

Two elements of NICE deal explicitly with the federal cybersecurity ranks, one with workforce structure and the other with training and professional development. “We’ve got a problem of where the next generation of engineers are going to come from,” McDuffie says. “Awareness, education, workforce, and training all have to come together.” NICE is still in the early going. McDuffie and team are identifying program goals, timelines, and performance metrics.

Hoover writes that, in fact, the problem is even more fundamental. “The feds have long had difficulty describing the job of cybersecurity specialists, so the Office of Personnel Management (OPM), the government’s HR department, is working to provide new guidance around cybersecurity job classifications, hiring, and performance management.”

Much of OPM’s work so far has been gathering