NIST's NICE: 3 ways to adapt the hiring framework for modern threats
ID: 859b9c43-9d20-5bb7-b83c-2d3a0790e53d
STIX ID: report--859b9c43-9d20-5bb7-b83c-2d3a0790e53d
Feed Name: ReversingLabs Blog
Date Published: 2024-10-31
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
This report analyzes the limitations of the NICE cybersecurity workforce framework in addressing software supply chain security (SSCS) and proposes updates across three areas: knowledge (e.g., SCA, SBOMs, dependency management, provenance), skills (e.g., SBOM tooling, container scanning, DevSecOps, partner access control), and roles (e.g., SSCS analyst, SBOM manager, AppSec engineer, third‑party risk analyst). Industry experts argue for integrating SSCS considerations across all roles while debating NICE’s broader adoption and potential downsides such as overspecialization and complexity. The piece emphasizes the need for practical, Secure-by-Design approaches and continuous monitoring to meet modern SSCS challenges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
