METHODOLOGICAL STRUCTURE OF A COURSE ON DLP SYSTEMS: A COMPETENCY-BASED APPROACH TO DEVELOPING PROFESSIONAL COMPETENCIES IN INFORMATION SECURITY USING DOMESTIC SOFTWARE
Abstract
This paper presents the methodological structure of an academic course aimed at developing professional competencies in protection against insider threats to corporate information security using DLP (Data Loss Prevention) systems. A competency-based approach is adopted as the theoretical foundation for course design, encompassing the unity of knowledge, skills, practical abilities, professional experience, and professionally significant personal qualities of the learner. The architecture of a virtual laboratory stand is described, comprising three nodes: a server running Windows Server 2025, a client workstation running Windows 11, and a client workstation running Alt Workstation 10.4 (developed by BaseALT LLC). The paper shows that incorporating a domestic operating system into the stand not only corresponds to the state import-substitution policy context but also expands the didactic capabilities of the course: students gain practical experience in configuring and operating a DLP agent in a heterogeneous environment close to real corporate conditions. A three-level logic for constructing laboratory assignments is proposed (20 sessions, 72 academic hours): from mastering basic domain infrastructure to configuring security policies and then to incident analysis and digital forensics. Pedagogical conditions for implementing the course are formulated (content-related, procedural, organisational, personnel-related, regulatory-methodological, and technological). Pilot results from two technical universities indicate the effectiveness of the proposed methodology for developing students’ competencies in DLP technologies.
Online viewer
References
- Sarhan, B. B., & Altwaijry, N. (2022). Insider threat detection using machine learning approach. Applied Sciences, 13(1), 259. https://doi.org/10.3390/app13010259
- Gheyas, I. A., & Abdallah, A. E. (2016). Detection and prediction of insider threats to cyber security: A systematic literature review and meta-analysis. Big Data Analytics, 1(1), 6. https://doi.org/10.1186/s41044-016-0006-0
- Zimnyaya, I. A. (2003). Key competencies as a new paradigm of educational outcomes. Higher Education Today, (5), 34–42.
- Zeer, E. F. (2009). Psychology of professional education. Akademiya.
- Bolotov, V. A., & Serikov, V. V. (2003). Competency model: From idea to educational program. Pedagogy, (10), 8–14.
- Liu, S., & Kuhn, R. (2010). Data loss prevention. IT Professional, 12(2), 10–13. https://doi.org/10.1109/MITP.2010.52
- Alsuwaie, A., Habibnia, B., & Gladyshev, P. (2021). Data leakage prevention adoption model & DLP maturity level assessment. In Proceedings of the International Symposium on Computer Science and Intelligent Controls (pp. 396–405). IEEE.
- Balinsky, H., Subiros Perez, D., & Simske, S. J. (2011). System call interception framework for data leak prevention. In Proceedings of the IEEE 15th International Enterprise Distributed Object Computing Conference (pp. 139–148). IEEE. https://doi.org/10.1109/EDOC.2011.25
- Data loss prevention solution for Linux endpoint devices. (2023). In Proceedings of the ACM Conference on Data and Application Security and Privacy. ACM. https://doi.org/10.1145/3600160.3605036
- Gupta, K., & Kush, A. (2023). A learning oriented DLP system based on classification model. arXiv. https://arxiv.org/abs/2312.13711
- Alammari, A., Sohaib, O., & Younes, S. (2022). Developing and evaluating cybersecurity competencies for students in computing programs. PeerJ Computer Science, 8, e827. https://doi.org/10.7717/peerj-cs.827
- Kebande, V. R. (2024). The impact of virtual laboratories on active learning and engagement in cybersecurity distance education. arXiv. https://arxiv.org/abs/2404.04952
- Willems, C., & Meinel, C. (2012). Online assessment for hands-on cyber security training in a virtual lab. In Proceedings of the 2012 IEEE Global Engineering Education Conference (EDUCON). IEEE. https://doi.org/10.1109/EDUCON.2012.6201104
- Pirta-Dreimane, R., et al. (2022). Application of intervention mapping in cybersecurity education design. Frontiers in Education, 7. https://doi.org/10.3389/feduc.2022.998335
- Švábenský, V., et al. (2021). Scalable learning environments for teaching cybersecurity hands-on. In Proceedings of the 2021 IEEE Frontiers in Education Conference. IEEE. https://doi.org/10.1109/FIE49875.2021.9637180
- Alsmadi, I. (2018). Practical information security: A competency-based education course. Springer. https://doi.org/10.1007/978-3-319-72119-4
- Burnyashov, B. A. (2022). Import substitution of software in the educational process of Russian universities. Informatics and Education, 37(1), 27–36. https://doi.org/10.32517/0234-0453-2022-37-1-27-36
- Burnyashov, B. A. (2023). Domestic cloud office application suites in the educational process of universities. Informatics and Education, 38(2), 5–15. https://doi.org/10.32517/0234-0453-2023-38-2-5-15
- Uymin, A. G. (2025). Practicum. Corporate protection against internal information security threats using modern DLP technologies: Textbook. Gubkin Russian State University of Oil and Gas.
License
Copyright (c) 2025 T. N. Gubina , S. A. Shmavonyan , A. G. Uymin (Authors)