Characterizing Security and Privacy Teaching Standards for Schools in the United States
This paper analyzes 11,954 U.S. K-12 computer science teaching standards to identify 3,778 security and privacy-related topics, finding that while they cover a broad range of technical and social subjects, they lack the emphasis on threat modeling and security mindset highlighted by industry professionals.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the internet as a massive, bustling city where everyone is connected. In this city, there are digital locks (encryption) to keep your diary safe, traffic laws (privacy policies) to protect your personal space, and friendly neighbors who help you spot trouble (cybersecurity). Just like we teach kids how to cross the street safely or how to share toys politely in real life, schools are trying to teach them how to navigate this digital city without getting lost or hurt. This field of study is called "Security and Privacy" (S&P), and it's about making sure people know how to protect their data, understand the rules of the road, and recognize when someone is trying to trick them. But here's the big question: Are all the schools in the country teaching the same things? Are they teaching the right things? Or is one school teaching kids how to pick a lock while another is just telling them to "be nice online"?
A team of researchers decided to play detective and find out. They didn't just guess; they went on a massive scavenger hunt through the official rulebooks used by schools across the United States. These rulebooks are called "teaching standards," and they are like the menu a school district gives to its teachers, listing exactly what students are supposed to learn by the time they graduate. The researchers looked at over 12,000 of these rules from 47 states and eight big national groups. They were hunting for anything related to keeping data safe or protecting privacy.
What they found was a bit of a mixed bag. Out of all those thousands of rules, they found about 3,920 that were actually about security and privacy. They sorted these into 109 different topics, ranging from the super technical (like how to use complex encryption codes) to the super practical (like how to behave nicely online or why you shouldn't share your password). But here's the twist: the menu looked very different depending on where you were. Some states had a huge list of rules about hacking and firewalls, while others barely mentioned them at all. Even the most popular topics, like "how to use a password," weren't on the menu in every single state.
The researchers also noticed that the rules were often written in a way that was a bit vague. It was like a teacher's guide saying, "Teach students about safety," without giving any examples of what that actually looks like. This leaves teachers, who might not be experts in cybersecurity themselves, to figure out the details on their own. The study suggests that the current system is a bit like a patchwork quilt: it covers the basics in some places, but the patterns are inconsistent, and some important stitches are missing entirely. The authors aren't saying the system is broken beyond repair, but they do suggest that to make sure every student is safe in the digital city, we need clearer maps, better examples for teachers, and a decision on whether we are teaching everyone to be a digital citizen or just training a few to be digital architects.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.