The Saudi Framework for Higher Education in Cybersecurity (Cyber-Education)

Traffic Light Protocol (TLP):

  • The Traffic Light Protocol system was established to share the maximum amount of sensitive information and is widely used worldwide. There are four colors (traffic lights):
  • Red – Personal and confidential to the recipient only
  • The recipient is not entitled to share the classified information marked with the red signal with any individual, whether inside or outside the facility, beyond the specified scope of receipt.
  • Orange – Limited sharing
  • The recipient of the orange signal can share the information within the same facility only with concerned persons and those required to take action related to the information.
  • Green – Sharing within the same community
  • You can share it with others from your facility or another facility related to you or within the same sector, and it is not allowed to exchange or publish it through public channels.
  • White – Unlimited

1 Introduction

Based on the Statute of the National Cybersecurity Authority issued pursuant to the Royal Order No. 6801 dated 11/02/1439 AH, which included the Authority’s jurisdictions and tasks, including: "building specialized national capabilities in the fields of cybersecurity, participating in the preparation of its educational and training programs, preparing professional standards and frameworks, and building and implementing related professional standard measures and tests," and stemming from the Authority’s keenness to build and develop high-quality national academic programs in the field of cybersecurity, the Authority has prepared the "Saudi Framework for Higher Education in Cybersecurity" to serve as a guiding manual that can be utilized in the development, evaluation, and accreditation of higher education programs in cybersecurity. This framework was developed by the Authority in coordination and cooperation with the Ministry of Education and the Education and Training Evaluation Commission.

This framework aims to contribute to setting the minimum requirements for curricula of higher education programs in cybersecurity, to ensure the academic quality of these programs, and to guarantee their ability to graduate highly qualified cadres in the field of cybersecurity who join the national workforce working in cybersecurity, enrich it with their knowledge and expertise, and contribute to national efforts aimed at achieving a "safe and trusted Saudi cyber space that enables growth and prosperity."

The Saudi Framework for Higher Education in Cybersecurity has been prepared to be compatible with the Unified Saudi Classification for Educational Levels and Specializations, the National Qualifications Framework, and the guidelines of the National Center for Academic Accreditation and Evaluation.

1-1 Scope of the Saudi Framework for Higher Education in Cybersecurity

  • This framework covers post-secondary degree programs in the following cybersecurity specializations:

      1. Intermediate Diploma
      1. Bachelor's Degree
      1. Higher Diploma
      1. Master's Degree
      1. Doctorate Degree
  • This framework can be utilized and applied to educational programs and academic degrees in cybersecurity specializations taught in public and private educational institutions for post-secondary education in the Kingdom of Saudi Arabia.

  • In the first edition of this framework, the focus was on general cybersecurity educational programs without addressing specialized programs in subfields of cybersecurity. Future editions of this framework will cover many specialized subfield programs in cybersecurity. The curriculum requirements contained in this framework will be reviewed and updated periodically to keep pace with the rapid developments witnessed in the field of cybersecurity.

1-2 Methodology

  • Although the field of cybersecurity is relatively modern compared to other related fields that have existed for a long time, such as computer science and engineering, many countries and international academic organizations have recently initiated the establishment of specific frameworks for higher education in cybersecurity to ensure the quality of educational program outcomes in this field.

  • Examples of such frameworks include: the National Centers of Academic Excellence in Cyber Defense (CAE-CD) program framework in the United States of America; the Accreditation Board for Engineering and Technology (ABET) standards for computing programs; the Cybersecurity Curricula guidelines from the Institute of Electrical and Electronics Engineers (IEEE) and the Association for Computing Machinery (ACM) in 2017; in addition to the higher education program framework accredited by the National Cyber Security Centre (NCSC) in the United Kingdom. These frameworks share a number of common features. These international frameworks were utilized in defining the methodology for preparing the Saudi Framework for Higher Education in Cybersecurity by setting the minimum requirements for cybersecurity curricula for each degree program through defining Program Descriptors (PD), which determine the learning outcomes, and Knowledge Units (KUs) studied by students in the program. As previously mentioned, this framework was designed in alignment with the Saudi Unified Classification for Educational Levels and Specializations, the National Qualifications Framework, and the guidelines of the National Center for Academic Accreditation and Evaluation.

  • The program descriptors in this framework correspond with the descriptors of the levels of the National Qualifications Framework, which assist educational institutions in designing the Program Learning Outcomes (PLOs), a set of knowledge, skills, and values expected to be acquired by graduates upon completion of the program. This framework aims to contribute to establishing the minimum program descriptors to be considered when formulating the learning outcomes for each cybersecurity degree program. Each educational institution may add additional learning outcomes to its cybersecurity educational programs as deemed appropriate.

  • This framework describes the knowledge units in cybersecurity, where a knowledge unit is a set of related topics that constitute the curriculum content taught, along with a set of learning outcomes that students acquire after completing the study of this unit. The learning outcomes for each knowledge unit define the minimum expectations of what the student should learn and be able to do after successfully completing that knowledge unit. It is important for educational institutions to consider depth, breadth, and progression in these outcomes according to the program level, and to incorporate communication skills and values learning outcomes within the courses. The framework specifies the minimum core knowledge units that the program must cover, in addition to a list of elective knowledge units. Educational institutions may offer elective knowledge units relevant to their programs from which students can choose to fulfill their graduation requirements. It is important to note that a knowledge unit is not necessarily a single course; a knowledge unit may be covered by one or more courses, and a course may cover one or more knowledge units either fully or partially.

  • For bachelor’s degree programs, this framework distinguishes between a specialized cybersecurity program and a program specialized in one of the information technology disciplines with a cybersecurity track within that program.

  • The knowledge units in this framework were derived from the following sources:

      1. The guideline program and knowledge units of the National Centers of Academic Excellence in Cyber Defense (CAE-CD), 2019.
      1. Cybersecurity curricula from the Institute of Electrical and Electronics Engineers and the Association for Computing Machinery (IEEE/ACM), 2017.
      1. Computer science curricula from the Institute of Electrical and Electronics Engineers and the Association for Computing Machinery (IEEE/ACM), 2013.
  • Additions and necessary modifications were made to meet national needs in this field and to align with relevant frameworks in the Kingdom.

  • There are three types of requirements in this framework for each graduate program:

      1. Admission Requirements: A list of requirements that a student must fulfill before being admitted to the program.
      1. Core Knowledge Units (Core KUs): Mandatory knowledge units that the student must fully complete as a basic requirement for graduation.
      1. Elective Knowledge Units (Elective KUs): A list of elective knowledge units from which the educational institution and/or the student may choose to complete the required number of knowledge units for graduation.

1-3 Prerequisites and Mathematics Requirements

Some knowledge units are prerequisites for other knowledge units, and it is important to consider this in the students' study plans and arrange them in an appropriate chronological order.

In addition, there is a fundamental connection between mathematics and many fields of cybersecurity, and most cybersecurity programs require some basic knowledge units in mathematics. However, the mathematics knowledge units required for a specific program largely depend on the nature and focus of that program; therefore, it is important for educational institutions offering bachelor's or intermediate diploma programs in cybersecurity to properly include the relevant mathematics knowledge units in their programs that meet the core requirements of the knowledge units in cybersecurity within their programs.

1-4 Document Structure

The remaining part of this document is organized as follows:

Section Two reviews the covered cybersecurity programs, in addition to the descriptions of the targeted programs and the knowledge unit requirements for each. Section Three provides a detailed description of all the knowledge units.

2 Programs

2-1 Intermediate Diploma

| 2-1-1 Program Descriptions | | | |
| Knowledge | Skills | Values, Responsibility, and Autonomy | |
| ⏺ General and interconnected knowledge and understanding of the foundations, theories, principles, and technical concepts in the field of cybersecurity.
⏺ Knowledge and understanding of analytical methodologies used in cybersecurity topics and interpretation of related information. | ⏺ Employing a set of theoretical and technical knowledge in related sciences and adapting it to reflect theoretical understanding in specific and unfamiliar contexts in the field of cybersecurity.
⏺ Utilizing critical and creative thinking, and providing innovative practical solutions in moderately complex and unfamiliar contexts related to cybersecurity.
⏺ Using study and investigation methodologies to benefit from their results to solve moderately complex problems in cybersecurity.
⏺ Selecting and using a variety of technical practices and tools and adapting them to perform moderately complex practical activities in the field of cybersecurity.
⏺ Communicating appropriately; demonstrating understanding and knowledge and conveying it to beneficiaries in the field of cybersecurity.
⏺ Analyzing and interpreting numerical data, and using graphical representations in moderately complex contexts related to cybersecurity. | ⏺ Commitment to the professional ethics of cybersecurity, and demonstrating responsible citizenship.
⏺ Managing self-learning and work, setting goals and working to achieve them, and making learning-related decisions with a moderate degree of autonomy.
⏺ Managing cybersecurity-related tasks and activities and working under indirect supervision.
⏺ Working collaboratively, leading work teams to perform a set of tasks with a degree of responsibility, and working effectively to achieve common goals.
⏺ Promoting health, psychological, and social aspects related to the field of cybersecurity. | |
| 2-1-2 Admission Requirements | | | |
| ⏺ General Secondary Certificate or its equivalent. | | | |
| 2-1-3 Core Knowledge Units | | | |
| ⏺ Cybersecurity Foundations (CSF)
⏺ Cybersecurity Design Principles (CDP)
⏺ IT Systems Components (ISC)
⏺ Basic Networking (BNW)
⏺ Basic Scripting and Programming (BSP)
⏺ Network Defense (NDF)
⏺ Operating Systems Concepts (OSC)
⏺ Cyber Threats (CTH)
⏺ Policy, Legal, Ethics and Compliance (PLE)
⏺ Security Risk Analysis (SRA) | | | |
| 2-1-4 Elective Knowledge Units | | | |
| ⏺ All remaining knowledge units, and students must complete at least (3) elective knowledge units before graduation. | | | |

2-2 Bachelor’s Degree (Track in Cybersecurity)

| 2-2-1 Program Descriptions | | | |
| Knowledge | Skills | Values, Responsibility, and Autonomy | |
| ⏺ Knowledge of a broad and deep range of foundations, theories, principles, and basic concepts in the field of cybersecurity.
⏺ Deep knowledge and understanding of the operations, tools, techniques, policies, and practices used in cybersecurity.
⏺ A set of specialized knowledge related to current and emerging developments in the field of cybersecurity. | ⏺ Analyzing and evaluating complex and diverse information in the field of cybersecurity.
⏺ Critical assessment, selection, and use of cybersecurity methods, methodologies, and tools to solve problems, reduce risks, and perform cybersecurity tasks.
⏺ Using study, investigation, and research methodologies in cybersecurity projects and activities.
⏺ Performing a range of tasks and procedures using cybersecurity tools in complex and diverse operations.
⏺ Communicating appropriately and transferring specialized knowledge and skills, and building professional and social relationships.
⏺ Using mathematical operations and quantitative methods to process data and information in complex and diverse contexts in cybersecurity. | ⏺ Commitment to the ethics and professional standards of cybersecurity, and demonstrating responsible citizenship.
⏺ Making constructive decisions in situations requiring self-reliance for work, learning, and innovation independently.
⏺ Managing cybersecurity-related tasks independently.
⏺ Working cooperatively and constructively, with the ability to lead, undertake entrepreneurship, and perform a range of tasks responsibly.
⏺ Active participation in the development of the cybersecurity specialization and community service. | |
| 2-2-2 Admission Requirements | | | |
| General Secondary Certificate or its equivalent. | | | |
| 2-2-3 Core Knowledge Units | | | |
| ⏺ Cybersecurity Foundations (CSF)
⏺ Cybersecurity Design Principles (CDP)
⏺ IT Systems Components (ISC)
⏺ Basic Networking (BNW)
⏺ Basic Scripting and Programming (BSP)
⏺ Network Defense (NDF)
⏺ Operating Systems Concepts (OSC)
⏺ Cyber Threats (CTH)
⏺ Policy, Legal, Ethics and Compliance (PLE)
⏺ Security Risk Analysis (SRA)
⏺ Data Structures (DST)
⏺ Databases (DAT) | | | |
| 2-2-4 Elective Knowledge Units | | | |
| ⏺ All remaining knowledge units, and students must complete at least (4) elective knowledge units before graduation. | | | |

2-3 Bachelor's Degree (Program in Cybersecurity)

| 2-3-1 Program Descriptions | | |
| Knowledge | Skills | Values, Responsibility, and Autonomy |
| ⏺ Broad and deep knowledge of the foundations, theories, principles, and basic concepts in the field of cybersecurity.
⏺ In-depth knowledge and understanding of the operations, tools, techniques, policies, and practices used in cybersecurity.
⏺ A set of specialized knowledge related to current developments, emerging issues, and advanced topics in the field of cybersecurity. | ⏺ Analyze and evaluate complex and diverse information in the field of cybersecurity.
⏺ Critical assessment, selection, and use of cybersecurity methods, methodologies, and tools to solve problems, reduce risks, and perform cybersecurity tasks.
⏺ Use study, investigation, and research methodologies in cybersecurity projects and activities.
⏺ Perform a wide range of tasks and procedures using cybersecurity tools in complex and diverse operations, with creativity and innovation in this area.
⏺ Communicate appropriately and transfer specialized knowledge, skills, and advanced concepts, and build professional and social relationships.
⏺ Use mathematical operations and quantitative methods to process data and information in complex and diverse contexts in cybersecurity. | ⏺ Commitment to the ethics and professional standards of cybersecurity, and demonstrating responsible citizenship.
⏺ Make constructive decisions in situations requiring self-reliance for work, learning, and innovation independently.
⏺ Manage cybersecurity-related tasks independently.
⏺ Work cooperatively and constructively, with the ability to lead, undertake entrepreneurship, and perform a wide range of tasks responsibly.
⏺ Actively participate in the development of the cybersecurity specialization and community service. |
| 2-3-2 Admission Requirements | | |
| ⏺ High school certificate or its equivalent. | | |
| 2-3-3 Core Knowledge Units | | |
| ⏺ Cybersecurity Foundations (CSF)
⏺ Cybersecurity Design Principles (CDP)
⏺ IT Systems Components (ISC)
⏺ Basic Cryptography (BCY)
⏺ Basic Networking (BNW)
⏺ Basic Scripting and Programming (BSP)
⏺ Network Defense (NDF)
⏺ Operating Systems Concepts (OSC)
⏺ Cyber Threats (CTH)
⏺ Policy, Legal, Ethics and Compliance (PLE)
⏺ Security Risk Analysis (SRA)
⏺ Algorithms (ALG)
⏺ Data Structures (DST)
⏺ Databases (DAT)
⏺ Network Technology and Protocols (NTP)
⏺ Network Security Administration (NSA)
⏺ Operating Systems Hardening (OSH) | | |
| 2-3-4 Elective Knowledge Units | | |
| ⏺ All remaining knowledge units, and students must complete at least (8) elective knowledge units before graduation. | | |

Next section title

Next section content