Skip to content

ossf/global-cybersecurity-skills-framework

Cybersecurity Skills Framework

A free, open, and customizable web-based tool developed by the Open Source Security Foundation (OpenSSF) and the Linux Foundation to help organizations assess and build cybersecurity skills across various IT roles. The framework provides skill mapping for 14 job families at different experience levels and aligns with industry standards like NIST NICE, DoD 8140, and ICT e-CF.

Motivation

Today’s organizations face an urgent need to build cybersecurity capacity across their software, DevOps, operations, and GRC teams. However, most frameworks are overly complex, vendor-driven, or narrowly scoped.

This initiative addresses the need for a simplified, practical, and open cybersecurity skills framework that is:

  • Role-based and job family-oriented
  • Lightweight and customizable
  • Mapped to real-world proficiencies and responsibilities
  • Open source and vendor-neutral

Use cases include:

  • Building internal security career paths
  • Mapping workforce training needs
  • Conducting cybersecurity skills assessments
  • Bridging the gap between HR, team leads, and technical staff

Objective

To provide an open-source, extensible cybersecurity skills framework that:

  • Defines clear roles and responsibilities across 14 job families
  • Maps each role to foundational, intermediate, and advanced skill levels
  • Aligns with common cybersecurity standards and frameworks
  • Encourages adoption across enterprises, education, and governments

Get Involved / Quick Start

  • Areas that need contributions:
    • New job role definitions
    • Skill description refinements
    • Translations and localization
    • UI/UX suggestions
  • Contributing instructions: See CONTRIBUTING.md
  • File issues or suggestions on GitHub Issues

Governance

The CHARTER.md outlines the scope and governance of our group activities.

Intellectual Property

In accordance with the OpenSSF Charter (PDF), work produced by this group is licensed as follows:

  1. Software source code
  2. Data
  3. Specifications
  4. All other Documentation

Antitrust Policy Notice

Linux Foundation meetings involve participation by industry competitors, and it is the intention of the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws.

Examples of types of actions that are prohibited at Linux Foundation meetings and in connection with Linux Foundation activities are described in the Linux Foundation Antitrust Policy available at http://www.linuxfoundation.org/antitrust-policy. If you have questions about these matters, please contact your company counsel, or if you are a member of the Linux Foundation, feel free to contact Andrew Updegrove of the firm of Gesmer Updegrove LLP, which provides legal counsel to the Linux Foundation.

About

Global CyberSecurity Skills Framework

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •