Cybersecurity Learning Hub — From Knowledge to Practice
Cyber Hiroshima

How to Learn Cybersecurity Systematically — Using CyBOK as a “Map”

When you begin learning cybersecurity, many fields appear at once: networking, cryptography, malware, forensics, risk management and more. This article introduces a way to use CyBOK, which organises knowledge into 21 Knowledge Areas, as a map for learning — helping you understand what you are learning now and where you might go next.

Cybersecurity needs a “map”

When people begin learning cybersecurity, the first problem they encounter is often not a lack of information.

It is the opposite: there is too much information.

Network security, Web security, cryptography, authentication, malware, incident response, digital forensics, cloud, AI — search for any of these topics and you will find large numbers of articles, videos, courses and certification materials.

The difficulty is understanding:

“How do all these subjects connect?”

Learning individual technologies is important, but doing only that can make it difficult to see where your learning sits within cybersecurity as a whole.

This is where the Cyber Security Body of Knowledge (CyBOK) can help.

CyBOK is a Body of Knowledge that systematically organises established and widely recognised knowledge in cybersecurity.

At Cyber Hiroshima, we do not see CyBOK simply as “a large resource to read”.

We see it as:

a map for understanding the world of cybersecurity.

What is CyBOK?

CyBOK is a Knowledge Base designed to organise foundational and widely recognised knowledge in cybersecurity.

The currently published CyBOK Version 1.1 organises cybersecurity knowledge into 21 Knowledge Areas (KAs).

Those 21 Knowledge Areas are further grouped into five broad Categories:

  • Human, Organisational & Regulatory Aspects
  • Attacks & Defences
  • Systems Security
  • Software & Platform Security
  • Infrastructure Security

Take Network Security as an example. It does not exist in isolation.

Protecting networks also requires an understanding of surrounding areas such as Cryptography, Authentication, Authorisation & Accountability, Operating Systems & Virtualisation Security, and Security Operations & Incident Management.

CyBOK itself shows that its Knowledge Areas are not completely independent and have many relationships with one another.

For that reason, CyBOK is often more useful when viewed not as “a textbook containing 21 subjects that must be studied in order”, but as a structured body of knowledge for understanding the shape of the wider cybersecurity field.

You do not need to read everything from the beginning

CyBOK Version 1.1 is a very large body of material.

There is therefore no need to think:

“I have to read it from the first page to the last.”

What matters first is identifying where your interests and objectives sit within CyBOK.

If you are interested in Web application security, for example, Web & Mobile Security can be your entry point.

If you want to learn about networks, you can begin with Network Security.

If you want to understand attacker behaviour, you can begin with Adversarial Behaviours.

If you are interested in incident response, Security Operations & Incident Management may be a useful starting point.

From there, you can expand your learning into related Knowledge Areas.

For example:

Web & Mobile Security
Software Security
Authentication, Authorisation & Accountability
Network Security

Someone approaching security from an organisational perspective might instead follow a route such as:

Risk Management & Governance
Human Factors
Law & Regulation
Security Operations & Incident Management

Not everyone needs to start from the same place.

With CyBOK as a shared map, learners can begin from different entry points while still understanding how the knowledge they are studying relates to the wider field.

Linking “knowing” and “doing”

Reading CyBOK alone does not make someone able to practise cybersecurity.

That is not a limitation of CyBOK. Knowledge and practical experience simply play different roles in learning.

For example, even after studying Network Security and understanding concepts such as:

  • TCP/IP
  • network architecture
  • Firewall
  • IDS/IPS
  • network attacks
  • approaches to defence

separate experience is still needed to inspect packets, change configurations and detect attacks in a real or simulated environment.

Cyber Hiroshima describes this relationship as:

Knowledge → Practice

First, use CyBOK to understand what you should know.

Then use a practical environment such as a Cyber Range to explore how that knowledge is actually used.

After the exercise, return to CyBOK and review the parts that were not fully understood.

Moving back and forth between the two is important.

Rather than completing all theory before moving into practice, repeat a cycle of:

Learn → Try → Discover what you do not understand → Learn again

This is how knowledge begins to develop into practical understanding.

CyBOK can also help you find what you do not know

One of the biggest barriers in learning is the state of:

“I do not know what I do not know.”

Suppose you attempt a Web application challenge in a CTF and cannot solve it.

You could simply decide:

“I should do more CTFs.”

But what are you actually missing?

Understanding of the Web?

Authentication?

Cryptography?

Networking?

Secure Software Lifecycle concepts?

CyBOK allows you to relate one problem to the surrounding Knowledge Areas.

This is useful not only for learners, but also for educators.

If it is possible to organise questions such as:

“What should learners gain from this exercise?”

“Which CyBOK Knowledge Area does this course cover?”

then individual teaching materials and exercises can be positioned within a larger learning framework.

Cyber Hiroshima uses CyBOK as the starting point for learning

Cyber Hiroshima is not aiming only to introduce CyBOK in Japanese.

We aim to use CyBOK as a shared body of knowledge connecting:

Knowledge × Practice × AI × Community

Use CyBOK to understand the overall structure of the knowledge.

Try it in practice using a Cyber Range such as SudoRange.

In the future, use AI to help explain difficult areas and support Learning Paths.

Use Cyber Challenge to test what has been learned through problem solving.

And rather than keeping that learning within Hiroshima, connect with Communities in Japan and overseas, including Cyber Wales.

CyBOK sits at the centre of this approach.

Rather than being “a resource that gives you every correct answer”, CyBOK can be used as:

a shared map for understanding where you are and where you might go next.

First, find your own entry point

There is no single starting point in cybersecurity learning that is right for everyone.

Someone with programming experience.

A network engineer.

A corporate IT professional.

A student.

Someone involved in management or risk.

Each person begins with different existing knowledge and different objectives.

Instead of trying to “learn everything from the beginning”, start by:

understanding where you are now and finding the Knowledge Area that can become your entry point.

Cyber Hiroshima’s Learn with CyBOK page organises the 21 Knowledge Areas into five Categories and provides Japanese-language explanations of their scope and role in learning.

Open the CyBOK map and find your own entry point into cybersecurity learning.


5. Read Next

Learn with CyBOK

Explore the structure of cybersecurity knowledge through the 21 Knowledge Areas and five Categories.

Where Should You Start with Cybersecurity? — A Learning Path for Beginners

The next article explains how beginners can use CyBOK to begin building a practical Learning Path.


6. References

CyBOK Attribution

CyBOK Version 1.1.0 © Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence v3.0.