CyBOK v1.1.0

Cyber Security Body of Knowledge

pedagogy
uk
Published

September 21, 2026

At a glance

Steward National Cyber Security Centre (NCSC)
Canonical page Cyber Security Body of Knowledge
Version 1.1.0
Released 2021-07
Source format PDF only (Introduction, per-Knowledge-Area trees, and an alphabetical index)
License Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence v3.0
framework_summary slug cybok-v1.1.0

Structure in cybed: terms

CyBOK structural mapping Frameworkcybok:FrameworkKnowledge Area(21 KAs across 5 categories)cybok:KnowledgeArea= cybed:OrganizingUnit(no cybed:Role)Topic / Indicative Materialcybok:Topic, cybok:IndicativeMaterial = cybed:RoleElementcontainscybed:hasOrganizingUnithas elementcybed:hasElement
Topics come one layer below the Knowledge Tree's root; Indicative Material comes one layer further down, from a tree structure read off each Knowledge Tree diagram rather than from tabular data. Click any box or edge label to flip between plain English and the technical schema name.

Counts

Table 1
Measure Value
Knowledge Areas 21
Strict elements (Topics) 119
Subpoints (Indicative Material, parsed from Knowledge Trees) 477
With-examples elements 596
Elements per Knowledge Area, strict 5.7
Elements per Knowledge Area, with-examples 28.4

CyBOK publishes no CSV, JSON, or XML: every count here comes from reading a Knowledge Tree as a drawing. Node labels come from the PDF text layer; parent-child links come from the drawing itself, recovered by blanking out each node box and tracing the remaining ink. The gap between the strict and with-examples counts reflects how much of CyBOK’s specification depth sits in Indicative Material terms one layer below the Topic level, rather than in the Topics themselves.

Provenance

Source

The Introduction to CyBOK Knowledge Area (for KA names and categories), one Knowledge Tree PDF per KA (for Topics and Indicative Material), and the alphabetical Indicative Material index (for KA acronyms and cross-checking).

Ingestion

scripts/010-ingest-cybok.R renders each Knowledge Tree page, blanks out the node boxes, and reconstructs the tree from the remaining connecting ink plus the PDF’s own text-layer word coordinates for labels.

License

Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence v3.0, which permits copying, publishing, adapting, and commercial use on condition of attribution. Every source document (the Introduction, each Knowledge Tree, and the A-to-Z index) carries the same notice.

Caveats

  • Knowledge Tree parsing is drawing recovery, not text extraction. A KA whose tree uses an unusual layout is the most likely source of a structural error; cross-checking against the alphabetical index catches most but not all of these.
  • CyBOK defines its own vocabulary for tree depth (Topic, then Indicative Material one layer further down); deeper layers in a given tree, where they exist, are not separately typed.
  • Case is preserved exactly as printed in each source: Knowledge Trees mostly print Topics in lower case, and the A-to-Z index prints everything in capitals. Matching a Topic name across the two requires case-insensitive comparison.
Back to top

Reuse

OGL v3.0