TY - GEN
T1 - Cybersecurity as a Crosscutting Concept Across an Undergrad Computer Science Curriculum
T2 - 55th ACM Technical Symposium on Computer Science Education, SIGCSE 2024
AU - Nadeem, Azqa
PY - 2024
Y1 - 2024
N2 - Although many Computer Science (CS) programs offer cybersecurity courses, they are typically optional and placed at the periphery of the program. We advocate to integrate cybersecurity as a crosscutting concept in CS curricula, which is also consistent with latest cybersecurity curricular guidelines, e.g., CSEC2017. We describe our experience of implementing this crosscutting intervention across three undergraduate core CS courses at a leading technical university in Europe between 2018 and 2023, collectively educating over 2200 students. The security education was incorporated within CS courses using a partnership between the responsible course instructor and a security expert, i.e., the security expert (after consultation with course instructors) developed and taught lectures covering multiple CSEC2017 knowledge areas. This created a complex dynamic between three stakeholders: the course instructor, the security expert, and the students. We reflect on our intervention from the perspective of the three stakeholders - we conducted a post-course survey to collect student perceptions, and semi-supervised interviews with responsible course instructors and the security expert to gauge their experience. We found that while the students were extremely enthusiastic about the security content and retained its impact several years later, the misaligned incentives for the instructors and the security expert made it difficult to sustain this intervention without organizational support. By identifying limitations in our intervention, we suggest ideas for sustaining it.
AB - Although many Computer Science (CS) programs offer cybersecurity courses, they are typically optional and placed at the periphery of the program. We advocate to integrate cybersecurity as a crosscutting concept in CS curricula, which is also consistent with latest cybersecurity curricular guidelines, e.g., CSEC2017. We describe our experience of implementing this crosscutting intervention across three undergraduate core CS courses at a leading technical university in Europe between 2018 and 2023, collectively educating over 2200 students. The security education was incorporated within CS courses using a partnership between the responsible course instructor and a security expert, i.e., the security expert (after consultation with course instructors) developed and taught lectures covering multiple CSEC2017 knowledge areas. This created a complex dynamic between three stakeholders: the course instructor, the security expert, and the students. We reflect on our intervention from the perspective of the three stakeholders - we conducted a post-course survey to collect student perceptions, and semi-supervised interviews with responsible course instructors and the security expert to gauge their experience. We found that while the students were extremely enthusiastic about the security content and retained its impact several years later, the misaligned incentives for the instructors and the security expert made it difficult to sustain this intervention without organizational support. By identifying limitations in our intervention, we suggest ideas for sustaining it.
KW - crosscutting concept
KW - cybersecurity education
KW - experience report
UR - http://www.scopus.com/inward/record.url?scp=85189324188&partnerID=8YFLogxK
U2 - 10.1145/3626252.3630821
DO - 10.1145/3626252.3630821
M3 - Conference contribution
AN - SCOPUS:85189324188
T3 - SIGCSE 2024 - Proceedings of the 55th ACM Technical Symposium on Computer Science Education
SP - 916
EP - 922
BT - SIGCSE 2024 - Proceedings of the 55th ACM Technical Symposium on Computer Science Education
PB - Association for Computing Machinery (ACM)
Y2 - 20 March 2024 through 23 March 2024
ER -