Don’t dismiss community college grads with degrees in information assurance

Opinion
Jun 15, 20116 mins

Academic excellence in information assurance education for two-year colleges

The 15th Annual Colloquium on Information Systems Security Education (CISSE) convened in Fairborn, Ohio, on June 13-15, 2011. After a warm welcome from Dr. Vic Maconachy, PhD, Dr. Vera Zdravkovich, Senior Adviser for the CAE2Y program – the Centers for Academic Excellence in Information Assurance Education for Two-Year Institutions. Definition of the U.S. government recognition for excellence in information-assurance education began with the CAEIAE for four-year educational institutions in 1998 (seven institutions were named in the initial round); the CAE process has expanded to include research (2007-08, CAE-R with 23 institutions) and in 2009-10, the six two-year educational institutions designated as CAE2Y. Today (2011) there are 146 institutions in all that have qualified as centers of excellence.

Zdravkovich quoted Richard “Dickie” George, IA Technical Director at NSA: “Two-year colleges are vitally important to the future of our nation and its young citizens, especially those from economically challenged backgrounds. These institutions train many who become system administrators for industry and government, and therefore are our front line warriors in today’s cyber wars. To that end, the National CAE2Y/IAE Program recognizes stellar colleges that are models – providing innovative, comprehensive, and multidisciplinary education and training in the information assurance field.”

The CAE2Y program was established to meet the needs of cybersecurity professionals – not all of whom have baccalaureates and advanced degrees. Zdravkovich emphasized that our society needs all dimensions of diversity in the cybersecurity field. The pipeline for security professionals must reach even into the K-12 sphere, where we can encourage interest in cybersecurity among the children and youths we need for our growing field. Two-year community colleges fulfill an important role in education in the United States, providing educational opportunities not only for young people but also for adults returning to education for paths into four-year programs and graduate schools but also for terminal two-year degrees that can support professional advancement.

The needs of the rapidly changing security field depend on a steady stream of qualified graduates at every level. Having a community college designated as a Center of Academic Excellence in Information Assurance Education carries over to a more general perception in the community of the first half of the program name: Center of Academic Excellence. Even when administrators and community members don’t know what the program is about, the effects are strikingly positive. The community perceives the entire institution as dedicated to academic excellence; internally, even administrators and educators with no direct connection to information assurance can feel involved in raising educational standards. Internally, the faculty involved in information assurance gain increased visibility, leading to additional offers of collaboration with colleagues. Students seeing the designation in the college catalog experience a subtle and positive change of perception. Over time, businesses are developing a sense of additional value for graduates of programs from those institutions. CAE2Y institutions have even seen a general increase in community pride about their CAE2Y colleges.

There are only a handful of community colleges that have information assurance programs. Having the CAE2Y model can offer a structure for community colleges to emulate in developing their IA programs. The process is arduous, but worth the effort. It’s important that the designation is institutional, not program-specific. The institution as a whole is recognized, and college policies have to be examined in detail – forcing faculty and staff to re-examine their policies and bring them into alignment with their needs. Faculty development is raised in visibility and importance; because the CAE program requires continuous process improvement, the entire institution can benefit from improvements.

Departments which would not historically have been involved in IA – philosophy, chemistry, history – can contribute to a coherent view of security issues, leading to increased creativity and more innovations. The CAE emphasis on diversity can stimulate institutions to reconsider their admission policies, increasing the number of women and various minorities into our field. Finally, the CAE program pushes institutions to consider outreach – both horizontally into the wider community and vertically into K-12 schools and universities.

Challenges to the CAE2Y program start with growth: we currently have only 13 CAE2Ys out of about 1,200 community colleges across the U.S. We need community colleges from more states. We also need a seamless system of articulation agreements between CAE2Ys and CAEIAEs. We need increased buy-in from the business community and from professional societies. There is a dismissive attitude towards holders of two-year degrees in IA; publicizing the work of the students and faculty and the qualifications of graduates is a tremendous challenge. More broadly, we need political and societal awareness of IA programs; for example, baccalaureate and graduate-school students have access to scholarships, but two-year degree students do not. Similarly, there are student loans available for baccalaureate and graduate-degree students but not for students in two-year programs.

Professor Casey O’Brien, CISSP, CEH,  of Community College of Baltimore County, Md., is the founder of the Mid-Atlantic Collegiate Cyber Defense Competition (part of the national CCDC) that have become popular on the East Coast. O’Brien said the CAE2Y designation is important to his school because it provides credibility for the new Institute for Cyber Security

The process of curriculum mapping solidified the program through increased interactions with colleagues such as the college CIO and other administrators. The study even led to discussions of creating a new department and defining two new academic positions. In particular, the mapping revealed weaknesses in policy and management areas of security and led to improvements. 

Collaboration with the programming professors led to integration of smart-grid programming into the programming courses. Students have been able to introduce security topics into the English classes, where they have written term papers about topics in the field. Personally, O’Brien improved his relations with upper-level administrators and with the College public relations department. The CCBC has improved its status and visibility in Baltimore County among legislators and businesses. The program has also opened new research opportunities to students, which stimulate the students and also prepare those interested in entering four-year programs. Students have seen increased job opportunities through the increased visibility of the certification attached to their own degrees.

Readers might want to forward this article to appropriate contacts in their own local community colleges. For more information about the CAE2Y program, visit the CyberWatch Website or write to Dr. Zdravkovich