Concordance

Licenses

This subsite carries layered licensing. Site content, site source code, and the upstream framework data each fall under different terms.

Site content (CC BY 4.0)

Prose, headings, captions, persona scenarios, query interpretations, and other written content on this site are licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).

You are free to share and adapt this content for any purpose, including commercial, provided you give appropriate credit, link to the license, and indicate any changes.

Suggested attribution:

Straight, R. Cybersecurity Framework Concordance. Licensed under CC BY 4.0. https://ryanstraight.github.io/cybedtools/concordance/

Site source code (MIT)

The R scripts, Quarto configurations, SCSS, JavaScript, and SVG assets that build this site are licensed under the MIT License, matching the cybedtools R package this site documents.

Framework source data (per-framework upstream terms)

The cybersecurity workforce and learning frameworks displayed on this site retain their upstream licenses. Full detail, including every quoted grant, is in the package’s LICENSING.md.

  • NICE Framework v2: a work of the United States Government, not subject to copyright in the United States under 17 U.S.C. 105. NIST reserves foreign rights and grants them back, giving the public a non-exclusive, perpetual, paid-up, royalty-free, worldwide right to reprint the work in all formats and in derivative works.
  • DCWF v5.1: a work of the United States Government prepared by DoD personnel, so not subject to copyright in the United States under 17 U.S.C. 105. The v5.1 workbook carries no distribution statement, so nothing in the artifact either grants or restricts distribution.
  • ENISA ECSF v1: the Role Profiles report PDF is CC BY 4.0 by its own notice. The JSON and XLSX that cybedtools ingests carry no notice of any kind, and rest instead on ENISA’s site-wide notice, which authorises reproduction of ENISA material provided the source is acknowledged.
  • SFIA 9: all use of SFIA is under licence from the SFIA Foundation, and the protected material is the concept, content and structure of SFIA. Redistribution and sub-licensing are prohibited at every tier. cybedtools uses SFIA for local analysis only, and this site shows SFIA skill names and aggregate counts and nothing more. A permission request to the SFIA Foundation is being prepared.
  • Cyber.org K-12 v1.0: Creative Commons BY-NC 4.0, attribution and non-commercial use.
  • CSTA K-12 CS Standards (Rev 2017): Creative Commons BY-NC-SA 4.0, attribution, non-commercial use and share-alike. The ingested workbook carries no licence statement, so the label is read from CSTA’s publication page for the 2017 edition.
  • DigComp 3.0: Creative Commons BY 4.0, verified against the dataset’s own copyright notice, the JRC Data Catalogue record, and the DigComp 3.0 resources page. The European Commission logo is excluded from reuse; cybedtools reproduces no logo. The prescribed citation is: Cosgrove, J. and Cachia, R., DigComp 3.0: The Digital Competence Framework for Citizens, EUR 40491, Publications Office of the European Union, Luxembourg, 2025, ISBN 978-92-68-32677-0, doi:10.2760/0001149. Dataset: doi:10.2905/JRC.FR75K8R.
  • ACM/IEEE CSEC2017: copyright 2017 by ACM, IEEE, AIS, IFIP, all rights reserved, with permission granted only “to use these curricular guidelines for the development of educational materials and programs”. This site shows Knowledge Area names, counts and alignment scores, and no statement text. A permission request to ACM is being prepared.

Frameworks included by steward permission

Three frameworks are here on their stewards’ terms. All three gave written permission. Those terms were given to cybedtools and do not pass to you.

  • CyQUAL 1.2.0: CyQUAL, the Czech national cybersecurity qualifications framework, developed at Masaryk University. Open data, version 1.2.0, https://platform.cyqual.cz/.
  • CCSSF 2022: Canadian Centre for Cyber Security, The Canadian Cyber Security Skills Framework (ITSM.00.039), 2022 edition. Copyright Government of Canada. Used with permission of the Canadian Centre for Cyber Security.
  • OTCCF v1.1: Derived from the Operational Technology Cybersecurity Competency Framework (OTCCF), published by the Cyber Security Agency of Singapore (CSA). Available at: https://www.csa.gov.sg/resources/publications/operational-technology-cybersecurity-competency-framework--otccf-/

CSA’s permission covers the OTCCF’s structure for non-commercial, academic and research use, and this site does not reproduce OTCCF statement text.

Each framework’s per-page provenance section names its license. Truncated text fragments shown in the searchable lookup widgets fall within each framework’s terms as academic illustration; this site does not redistribute full framework source text.

To run the underlying queries against full framework text, install the cybedtools R package and stage the framework source data per docs/framework-data-sources.md.

Back to top