Mapping Professional Cyber Security Certifications to the CyBOK Knowledge Framework
Project Supervisor:
The Cyber Security Body of Knowledge (CyBOK) is the NCSC's national framework defining expertise across 21 specialist domains. Despite its growing role in academic and professional assessment, no systematic, evidenced mapping of professional certifications to CyBOK currently exists. This project addresses that gap.
A small group of students will investigate a curated list of cyber security certifications from leading bodies including ISC2, ISACA, CompTIA, CREST, GIAC, and Offensive Security. For each certification, students will locate and analyse the official examination syllabus or blueprint, record prerequisite experience requirements, examination format, and cost, and assess alignment with each of the 21 CyBOK Knowledge Areas using a structured rating methodology developed by the supervisory team.
The methodology follows four stages:
- familiarisation with the CyBOK framework and its Knowledge Area definitions;
- systematic data collection from official issuing body sources only;
- structured analysis of each syllabus against a standardised rating rubric (High / Medium / Low / None per Knowledge Area); and
- peer verification, where each student's ratings are reviewed by a colleague before submission.
This approach ensures consistency, traceability, and academic rigour throughout.
Students will develop transferable skills in systematic literature review, qualitative data analysis, and cyber security frameworks, and will contribute to an active area of academic inquiry with direct professional relevance.