Wait, security courses aren't a requirement to graduate with a computer science degree?
- Reference: 1706304487
- News link: https://www.theregister.co.uk/2024/01/26/security_courses_requirements/
- Source link:
Jack Cable, a CISA senior technical advisor, writes that in 2019 when he was a computer science student at Stanford University in California, he didn't need to take any cybersecurity courses to graduate. This, he says, was true for students at 23 of the top 24 computer science schools in America.
Nearly five years later, "that list of the top 24 universities in computer science hasn't changed: 23 still don't require cybersecurity," Cable [1]wrote in his memo.
[2]
Cue the coffee spitting.
[3]
[4]
The University of California, San Diego, for the record, is the [5]only school in the top 24 with a computer science and engineering program that does list security as an undergraduate degree requirement, although it's unclear if that's really the case from the college's [6]curriculum .
"Cybersecurity is viewed as a subdiscipline, much like graphics or human-computer interaction – not essential knowledge that every future software developer should be equipped with as they enter the workforce," Cable laments. "This is unacceptable. All too often, attacks exploit simple weaknesses that any developer with basic security knowledge could have stopped."
[7]
We wholeheartedly agree. Sure, computer science is not engineering, and you may argue that engineering is a more natural home for practical secure coding. Turning an abstract algorithm into a safe software routine, or writing a service that doesn't blindly trust user input, for example, is an implementation-level issue for engineers. We get it.
But screw it, this situation is unsustainable. Put security in your compsci curriculum for the sake of new developers and the people using their code.
[8]EquiLend drags systems offline after admitting attacker broke in
[9]HPE joins the 'our executive email was hacked by Russia' club
[10]Using GoAnywhere MFT for file transfers? Patch now – an exploit's out for a critical bug
[11]What Microsoft's latest email breach says about this IT security heavyweight
By now the infosec [12]skills shortage is old news, and voices in both the [13]private and [14]public sectors have called on developers to get a grip on vulnerabilities in their software supply chains. Even the White House's National Cybersecurity Strategy calls for holding application makers [15]liable for security flaws in their products, which will for one thing need better training for programmers.
But if colleges and universities aren't requiring computer science students to take any infosec classes before they are hired by these companies, look, we've got a real problem. It's one that will contribute to the [16]disconnect between security executives and developers — not to mention the ever-growing threat from [17]ransomware and other destructive [18]cyberattacks .
One of the reasons for these lack of courses, according to CISA, is that the private sector isn't demanding these skills in its developer hires. In September, the agency hosted a workshop that centered around the challenges in incorporating security into computer science curricula, and one of the hurdles identified was a lack of demand.
[19]
"To date, companies have not expressed that security is one of the key factors they evaluate when hiring software developers," Cable wrote. "Until that changes, universities have little incentive to change their practices."
But: Here's a chance to do something about this. Last month, CISA put out a [20]Request for Information on the role of security in computer science education. Responses are due February 20 and we'll keep a close eye on what emerges. ®
Get our [21]Tech Resources
[1] https://www.cisa.gov/news-events/news/we-must-consider-software-developers-key-part-cybersecurity-workforce
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbQ5l80SVtuT7XcQwnXdHAAAARQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbQ5l80SVtuT7XcQwnXdHAAAARQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbQ5l80SVtuT7XcQwnXdHAAAARQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://gist.github.com/cablej/f272747f2d545342aec7f34a1bfae4ef
[6] https://catalog.ucsd.edu/curric/CSE-ug.html
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbQ5l80SVtuT7XcQwnXdHAAAARQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2024/01/25/cybersecurity_incident_forces_equilend_to/
[9] https://www.theregister.com/2024/01/25/hpe_russia_email_attack/
[10] https://www.theregister.com/2024/01/24/public_exploit_published_within_hours/
[11] https://www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/
[12] https://www.theregister.com/2022/10/15/infosec_boys_club/
[13] https://www.inforisktoday.com/snyk-ceo-peter-mckay-on-making-defense-easier-for-developers-a-21055
[14] https://www.cisa.gov/resources-tools/resources/securing-software-supply-chain-recommended-practices-developers
[15] https://www.theregister.com/2023/03/03/us_national_cybersecurity_strategy/
[16] https://get.chainguard.dev/ciso-developer-trends
[17] https://www.theregister.com/2024/01/03/ban_ransomware_payments/
[18] https://www.theregister.com/2024/01/25/hpe_russia_email_attack/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbQ5l80SVtuT7XcQwnXdHAAAARQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://www.federalregister.gov/documents/2023/12/20/2023-27948/request-for-information-on-shifting-the-balance-of-cybersecurity-risk-principles-and-approaches-for
[21] https://whitepapers.theregister.com/
There is more to computers than the network. (Contrary to Sun's slogan ;)
An offline solution is pretty darn secure.
Totally concur that security should be part of any computer oriented curriculum
The ivory-tower assumption that "Computer Science" is not really part of IT is the basis for the whole problem.
I know Knuth's brilliant "Art of Computer Programming" series didn't worry about buffer overflows or re-using unreferenced memory or being able to read data outside of your assigned space. But because our current implementations use languages and models that don't worry about these things, we are spending a huge amount of time and effort to clean up sloppy-but-effective code.
The same arguments will be made against automated testing environments, rigorous documentation, pen testing, etc. It's sort of like asking an economics major to take charge of a real banking system. Real life is hard.
Drive awareness
I support this sentiment, and suggest that driving awareness of issues should begin with an understanding of the consequences and risks associated with actions. CompSci doesn’t sit alone, disconnected in murky pond. Decisions have consequences and those consequences can lead to frustration, error or worse.
Isn’t that worth teaching?
Computer science is not the same as computing or IT. Expecting a computer science graduate to have taken cybersecurity courses is like expecting a maths graduate to have taken book-keeping courses.