Executive Summary CYBER SECURITY COMPETITION SECONDARY SCHOOLS CZECH REPUBLIC The school year 2016 / 2017

Similar documents
Executive Summary CYBER SECURITY COMPETITION SECONDARY SCHOOLS CZECH REPUBLIC. The school year 2017 / 2018

Global Alliance Against Child Sexual Abuse Online 2014 Reporting Form

NATIONAL CYBER SECURITY STRATEGY. - Version 2.0 -

Security and resilience in Information Society: the European approach

Itu regional workshop

EISAS Enhanced Roadmap 2012

National Open Source Strategy

The role of COP/ITU on international level. Dr Ibrahim Al dabal chair of child on line council working group

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

JEAS-Accredited Environmental Assessor Qualification Scheme

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

National CIRT - Montenegro. Ministry for Information Society and Telecommunications

Child Online Protection

Overview. Objectives. Components. Information and Communication Technologies Sector Development Project. Project

Cyber Security Strategy

State Planning Organization Information Society Department

RESOLUTION 67 (Rev. Buenos Aires, 2017)

INDEX ABOUT US 3 ARAB CERTIFIED QUALITY MANAGER PROGRAM. Body of Knowledge 6 UNESCO ICT INDICATORS 8 MESSAGE FROM THE CHAIRM AN

NEW INNOVATIONS NEED FOR NEW LAW ENFORCEMENT CAPABILITIES

Provisional Translation

ehealth Ministerial Conference 2013 Dublin May 2013 Irish Presidency Declaration

Commonwealth Cyber Declaration

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

Promoting Global Cybersecurity

The challenges of the NIS directive from the viewpoint of the Vienna Hospital Association

Cyber Security in Europe

Cybersecurity & Digital Privacy in the Energy sector

MASTER OF SCIENCE IN COMPUTER SCIENCE

13967/16 MK/mj 1 DG D 2B

Helping shape your future

Way to new challenges

Cyber Security School

Cybersecurity in Asia-Pacific State of play, key issues for trade and e-commerce

10025/16 MP/mj 1 DG D 2B

ECSC Brief Razvan GAVRILA NIS Expert. European Union Agency for Network and Information Security

Resolution adopted by the General Assembly on 21 December [on the report of the Second Committee (A/64/422/Add.3)]

RESOLUTION 179 (REV. BUSAN, 2014) ITU's role in child online protection

RESOLUTION 179 (REV. BUSAN, 2014) ITU's role in child online protection

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

HEALTH INFORMATION INFRASTRUCTURE PROJECT: PROGRESS REPORT

Implementation Strategy for Cybersecurity Workshop ITU 2016

ENISA EU Threat Landscape

Cybersecurity for ALL

International Policy Division, Global ICT Strategy Bureau

Stakeholders are key to Kyvyt, which is a tool largely based on informal LMI offered by its end-users/students.

European Directives and reglements for Information security

Package of initiatives on Cybersecurity

Action Plan for the Implementation of the Cyber Security Concept of the Slovak Republic for

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

Cybersecurity Strategy of the Republic of Cyprus

Strategy for information security in Sweden

European Diplomatic Programme. The EU Global Strategy: from Vision to Action

ANNUAL PROGRAM REPORT. Multiple and Single Subject Credential Programs. Credential programs are not subject to 5 year reviews

CESNET-CERTS. Academic CSIRT Meeting 17 Jun 2012 Malta. Andrea Kropáčová,

Cloud. Cloud Innovation World Cup 2013/14 15 OCT - 15 MAR. Special Prize Evolve Insurance Award. Participant Information INDUSTRY 4.

EU policy on Network and Information Security & Critical Information Infrastructures Protection

Legal framework of ensuring of cyber security in the Republic of Azerbaijan

Germany Candidate for the ITU Council

Implementing a National Strategy : the case of the Tunisian CERT

Intellectual Property Office of Serbia

Special Action Plan on Countermeasures to Cyber-terrorism of Critical Infrastructure (Provisional Translation)

Vademecum of Speakers

National Council for Special Education. NCSE Support Service Advisor Job Description and General Notes

Evolve Your Security Operations Strategy To Account For Cloud

Fostering Competitiveness, Growth and Jobs. Wrocław, Poland, 15 October 2014

Working with investment professionals

Critical Information Infrastructure Protection. Role of CIRTs and Cooperation at National Level

THE CYBER SECURITY ENVIRONMENT IN LITHUANIA

The National Qualifications System Instruments to support Qualification and Lifelong Learning

COUNCIL OF THE EUROPEAN UNION. Brussels, 28 January 2003 (OR. en) 15723/02 TELECOM 78 JAI 307 PESC 593

CyberSecurity Training and Capacity Building: A Starting Point for Collaboration and Partnerships. from the most trusted name in information security

ISTQB in a Nutshell. ISTQB Marketing Working Group. February 2012 v10

WORKSHOP CYBER SECURITY AND CYBERCRIME POLICIES FOR AFRICAN DIPLOMATS. Okechukwu Emmanuel Ibe

Directive on security of network and information systems (NIS): State of Play

Training courses held by the Kazakh and foreign experts for financial system specialists in 2011 in the Republic of Kazakhstan

Critical Infrastructure Protection (CIP) as example of a multi-stakeholder approach.

2011 NetRiders Skills Challenge Post Secondary Frequently Asked Questions (FAQ)

Chartered Membership: Professional Standards Framework

GEORGIA CYBERSECURITY WORKFORCE ACADEMY. NASCIO 2018 State IT Recognition Awards

Poland: Initiative for Polish Industry 4.0 The Future Industry Platform

ENISA s Position on the NIS Directive

IMPACT Global Response Centre. Technical Note GLOBAL RESPONSE CENTRE

The Republic of Korea. economic and social benefits. However, on account of its open, anonymous and borderless

Hannover Declaration

DIGITAL AGENDA FOR EUROPE

First Session of the Asia Pacific Information Superhighway Steering Committee, 1 2 November 2017, Dhaka, Bangladesh.

A Strategy for a secure Information Society Dialogue, Partnership and empowerment

IPv6 Migration Framework Case of Institutions in Ethiopia

Current skills gap for capable CTI analysts: Training for forensics & analysis

Featured Articles II Security Research and Development Research and Development of Advanced Security Technology

European Diplomatic Programme. The EU Global Strategy: from Vision to Action

GUIDELINES FOR SUBMITTING CONTINUING PROFESSIONAL EDUCATION (CPE) CREDITS

OF ELECTRICAL AND ELECTRONICS ENGINEERS POWER & ENERGY SOCIETY

CSI Program Action Plan Table (Department)

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 21 October /13 LIMITE CO EUR-PREP 37. NOTE General Secretariat of the Council

VdTÜV Statement on the Communication from the EU Commission A Digital Single Market Strategy for Europe

UK-NL Cyber Security Showcase DIT The Netherlands

13.f Toronto Catholic District School Board's IT Strategic Review - Draft Executive Summary (Refer 8b)

Project Title: INFRASTRUCTURE AND INTEGRATED TOOLS FOR PERSONALIZED LEARNING OF READING SKILL

Ministry of Government and Consumer Services. ServiceOntario. Figure 1: Summary Status of Actions Recommended in June 2016 Committee Report

Transcription:

Executive Summary CYBER SECURITY COMPETITION SECONDARY SCHOOLS CZECH REPUBLIC The school year 2016 / 2017 Petr Jirásek et al Praha 2017

Executive Summary Substantial growth in the use of information technologies in the current world leads towards a precipitous formation of the information society. On the one hand, the attendant acceleration of communications and the rapid development of digital services promote the growth of the whole society; however, on the other hand, we see a marked growing risk of abusing these technologies. Our society depends increasingly on digital data and communications, and thus successful attacks on the infrastructure or data result in extensive impacts on accessibility and trust and can potentially lead to large economic and material damage. In those cases when attacks, external or internal, are directed towards the critical infrastructure elements, this may ultimately result in putting the security or integrity of whole states in danger. The response to this situation is a global effort for a quality protection of information and communication technologies against incidents that may jeopardize or change their operations, and this logically leads to a substantial increase in demands for the availability and education of new professionals in cyber security 1. At the same time, we can see much stress being put on the dissemination and deepening of general public awareness, the public being the broadest potential source of mass proliferation of harmful codes (unsecured IoT, laxity towards identity protection, and similar). The National strategy of cyber security of the Czech Republic and the Action plan of the National strategy of the Czech Republic for 2015-2020 was adopted by a government decree on 25 May 2015. This action plan includes several requirements for the education of experts, members of the public and students at all levels of education. The universities have been trying to respond to this state of affairs and step by step launch (albeit uncoordinated) educational programmes in the cyber security and defence. Secondary schools have not been involved yet in any focused way which explains the low interest of their students in continuing their studies in cyber security at the universities. The Action plan of National strategy of cyber security of the Czech Republic contains, mostly in Part F, many objectives aimed at the students and teachers of secondary schools, for example: (a) increase the awareness and literacy in cyber security for secondary-school students; (b) contribute to the modernization of secondary-school educational programmes; (c) support the training of experts; (d) prepare methodological learning materials for the teachers; (e) promote talents among students in cyber security in cooperation with the universities. AFCEA Czech Cyber Security Working Group (from now on Working Group ) has been implementing awareness, educational and professional activities in cyber security and defence since as early as 2004. The group organises, on a regular basis, security seminars for the employees and professionals from among the state sphere, the academia and the private sphere. It put together and has been updating (as required by the dynamic development of cyber security) the Cyber Security Glossary. The glossary has become an official publication and won several professional awards. The group has also organised many lectures, practical 1 Cyber security is a collection of legal, organizational, technological, physical and educational means aimed at providing undisturbed and fault-free operation of the cyberspace. The cyberspace is a digital environment making possible the origin, processing and exchange of information created by information and communication technologies including access to a public network (internet). [Jirásek, Novák, Požár, Výkladový slovník kybernetické bezpečnosti, Praha, 2013. ISBN 978-80-7251-397-0] 2 Petr Jirásek et al

workshops and exhibitions of modern security trends and technologies. The group has a close cooperation with the universities. At the end of 2015, activities of the Working Group gave birth to the idea of a nation-wide cyber security competition aimed at secondary-school students. Preliminary efforts to implement the original idea were substantially accelerated in the spring of 2016 thanks to the offer of the European agency ENISA 2 to nominate the Czech national team, made up of secondary-school and university students, take part in the European Cyber Challenge (from now on European finals ). Thanks to the rapid response and support on the part of selected state institutions, a decision was made in July 2016 to organise the first class of the Czech Secondary School Cyber Security Competition as early as the school year 2016/2017. The list of state institutions was headed by the National Security Authority, Ministry of the Interior of the Czech Republic, Ministry of Labour and Social Affairs, partner professional associations (in particular ICT unie, ČIMIB, NCBI) and there were also academic institutions headed by ČVUT (Czech Technical University), University of Defence, Police Academy, Masaryk University and Brno Technical University. Competition Committee was made up of cyber security professionals and faced no easy task. A quality competition had to be prepared in a relatively short time; the competition had one objective of verifying the knowledge of secondary-school students and selecting the best candidates for the European finals; the primary goal, however, was to address the young generation and arouse the interest in cyber security. In order to achieve these objectives, it was, of course, necessary to speak to the teaching staff and prepare for them the learning resources to teach cyber security as well as teach at least the fundamentals of how the cyber space operates. 2 European Union Agency for Network and Information Security. Executive Summary - Cyber Security Competition Secondary schools Czech republic 2016/2017 3

Despite minor technical issues in the initial phase and high time constraints of the whole process of preparations it was possible to issue a report in October 2016 that the competition was ready to start. This situation was made possible due to the efforts of many professional partners who took part there. Big thankyou is due to all; however, two companies must be singled out- Corpus Solutions, a.s., which put up a completely new competition portal for the first and second competition rounds using the Lime Survey technology- and DataSpring a.s., which provided hosting and technical support for this portal in their data centre. These events contributed substantially to the fault-free progress of the competition in the first year. However, the greatest challenge and a chapter in its own right in the first year of the competition was using the appropriate communication methods to students themselves, arouse their interest and thus get them involved in active participation. The competition committee left nothing to chance and created a series of campaigns reaching out not only to students but also to the teachers and parents and not only in the secondary schools (and their controllers) but also to various associations which cooperate with the secondary schools on a long-term basis. Participation by regions 350 300 250 200 150 100 50 0 As a result, the participation was more than a thousand students from about 12 per cent of secondary schools organised in the Czech Republic. The greatest provable influence on getting the students participation was by the social media headed by Facebook. Direct communication with the schools resulted 4 Petr Jirásek et al

in cooperation with the headmasters and headmistresses, and thus, among other things, representatives of the Competition Committee carried out more than sixty professional presentations at the secondary schools throughout the Czech Republic. Almost 2,500 students and about 150 of their teachers took part. This activity got a wide reception and created space for further cooperation and deeper involvement of the remaining secondary schools in the next years. The competition was divided into three rounds. The difficulties and complexities of the questions and tasks increased with each succeeding round. The first round was online at the turn of November and December 2016 and contained 15 more or less general questions from five areas of cyber security. The second round was also online in March 2017 and had ten practical tasks. The third round was held in Brno in the framework of the International Fair IDET 2017 and the finals, with a required registration, were held on 1 June 2017. There thirty best contestants had to solve six complex team tasks within a time limit. As the finals were held on the premises of the fair, there was an additional bonus for the students and the accompanying staff: they could get acquainted with modern technologies and new trends in cyber security and defence, and more. Contestants Secondary schools Finalists Succesfull Engaging Qualifying Non-qualifying Outgoing In final Participated Non-participated The final round provided the candidates for the participation in the Czech national team in the European Finals. Their qualification was confirmed during the summer camp in the Cyber polygon of the Masaryk University in Brno in July 2017. The Competition Committee would like, on behalf of the members and organisers, to thank all partners and supporters of the first year of the competition for its smooth progress. The competition was organised as a non-profit, no-loss and low-cost event with the participation of volunteers. The volunteers have spent more than 1,750 unpaid hours during the preparation and course of the competition. There would be no competition without the help and active cooperation of all of the above subjects. Thank you ever so much. The organizers and the Competition Committee, having used the experience from the first year, have decided to continue the work so well begun and organise the second year of the competition in 2017/2018, in order to increase the awareness among the secondary-school students in the cyber security issues, motivate the young people for a deeper (not only user-like) interest in modern technologies and, last but Executive Summary - Cyber Security Competition Secondary schools Czech republic 2016/2017 5

not least, make them compare their knowledge with their peers in fair and open contests in their schools, regions, and the whole of the Czech Republic. The complete report from the first year of the competition is available on https://www.kybersoutez.cz. We are looking forward to your participation and support. Competition Committee 6 Petr Jirásek et al

For more information, please contact: Competition Committee Czech Secondary School Cyber Competition Cyber Security Working Group AFCEA Czech Chapter kybersoutez@kybersoutez.cz www.kybersoutez.cz Cyber Security Working Group, AFCEA Czech Chapter, All rights reserved. Executive Summary - Cyber Security Competition Secondary schools Czech republic 2016/2017 7