Effectiveness of Hands-On Lab Training for Improving Zero-Trust and Identity-Access Management Competencies Among Hybrid Cloud Engineers
Keywords:
access control, workforce training, cloud securityAbstract
Hybrid-cloud security increasingly depends on identity-centered controls, continuous authorization, federation, least privilege, and policy enforcement across heterogeneous platforms. These competencies are difficult to develop through lecture-only or awareness-oriented instruction because engineers must be able to configure, observe, troubleshoot, and validate security controls in realistic systems. This review evaluates the effectiveness of hands-on laboratory training for developing zero-trust and identity-access management (IAM) competencies relevant to hybrid-cloud engineering and proposes an evidence-based framework for training delivery and assessment. A structured evidence review synthesized peer-reviewed studies involving cybersecurity laboratories, virtual laboratories, cyber ranges, learner-controlled security training, gamified security education, and practical assessment, together with authoritative zero-trust and IAM standards. Evidence was mapped to operational competency domains including authentication, federation, role- and attribute-based authorization, least privilege, conditional access, workload identity, policy troubleshooting, and security telemetry. Across heterogeneous educational settings, practical training environments consistently supported procedural learning, realistic task execution, self-efficacy, engagement, and directly observable performance. Stronger training designs combined realistic scenarios with learner control, immediate feedback, repeatable environments, objective task instrumentation, and delayed or transfer assessment. Cyber-range and virtual-laboratory platforms also improved scalability and enabled systematic collection of command, log, configuration, and policy evidence. For zero-trust and IAM training, the most defensible outcome measures include policy correctness, task completion time, excess-privilege errors, authentication and federation troubleshooting accuracy, recovery from misconfiguration, and performance on unfamiliar scenarios. Overall, hands-on laboratories are well suited to hybrid-cloud zero-trust and IAM skill development because they convert abstract access-control principles into observable configuration and diagnostic behavior. Their effectiveness is greatest when training is scenario-based, instrumented, progressively scaffolded, and evaluated using task-level security outcomes rather than participant satisfaction alone.
References
Rose S, Borchert O, Mitchell S, Connelly S. Zero Trust Architecture. NIST Special Publication 800-207. Gaithersburg (MD): National Institute of Standards and Technology; 2020. doi:10.6028/NIST.SP.800-207.
Grassi PA, Garcia ME, Fenton JL. Digital Identity Guidelines. NIST Special Publication 800-63-3. Gaithersburg (MD): National Institute of Standards and Technology; 2017. doi:10.6028/NIST.SP.800-63-3.
Hu VC, Ferraiolo D, Kuhn R, Schnitzer A, Sandlin K, Miller R, et al. Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST Special Publication 800-162. Gaithersburg (MD): National Institute of Standards and Technology; 2019. doi:10.6028/NIST.SP.800-162.
Newhouse W, Keith S, Scribner B, Witte G. National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework. NIST Special Publication 800-181. Gaithersburg (MD): National Institute of Standards and Technology; 2017. doi:10.6028/NIST.SP.800-181.
Sandhu RS, Coyne EJ, Feinstein HL, Youman CE. Role-based access control models. Computer. 1996;29(2):38-47.
Hu J, Meinel C. Tele-Lab “IT-Security” on CD: portable, reliable and safe IT security training. Comput Secur. 2004;23(4):282-289. doi:10.1016/j.cose.2004.02.005.
Willems C, Klingbeil T, Radvilavicius L, Cenys A, Meinel C. A distributed virtual laboratory architecture for cybersecurity training. In: 2011 International Conference for Internet Technology and Secured Transactions. IEEE; 2011. p. 408-415.
Willems C, Meinel C. Online assessment for hands-on cyber security training in a virtual lab. In: 2012 IEEE Global Engineering Education Conference (EDUCON). IEEE; 2012. p. 1-10. doi:10.1109/EDUCON.2012.6201149.
Pham C, Tang D, Chinen K, Beuran R. CyRIS: a cyber range instantiation system for facilitating security training. In: Proceedings of the Seventh Symposium on Information and Communication Technology. New York: ACM; 2016. p. 251-258. doi:10.1145/3011077.3011087.
Frank M, Leitner M, Pahi T. Design considerations for cyber security testbeds: a case study on a cyber security testbed for education. In: 2017 IEEE DASC/PiCom/DataCom/CyberSciTech. IEEE; 2017. p. 38-46. doi:10.1109/DASC-PICom-DataCom-CyberSciTec.2017.23.
Domínguez M, Prada MA, Reguera P, Fuertes JJ, Alonso S, Morán A. Cybersecurity training in control systems using real equipment. IFAC-PapersOnLine. 2017;50(1):12179-12184. doi:10.1016/j.ifacol.2017.08.2151.
Tobarra L, Robles-Gómez A, Pastor R, Hernández R, Duque A, Cano J. A cybersecurity experience with cloud virtual-remote laboratories. Proceedings. 2019;31(1):3. doi:10.3390/proceedings2019031003.
Abawajy J. User preference of cyber security awareness delivery methods. Behav Inf Technol. 2014;33(3):237-248. doi:10.1080/0144929X.2012.708787.
González-Manzano L, de Fuentes JM. Design recommendations for online cybersecurity courses. Comput Secur. 2019;80:238-256. doi:10.1016/j.cose.2018.09.009.
Estriegana R, Medina-Merodio JA, Barchino R. Student acceptance of virtual laboratory and practical work: an extension of the technology acceptance model. Comput Educ. 2019;135:1-14. doi:10.1016/j.compedu.2019.02.010.
Abraham S, Chengalur-Smith I. Evaluating the effectiveness of learner controlled information security training. Comput Secur. 2019;87:101586. doi:10.1016/j.cose.2019.101586.
Dincelli E, Chengalur-Smith I. Choose your own training adventure: designing a gamified SETA artefact for improving information security and privacy through interactive storytelling. Eur J Inf Syst. 2020;29(6):669-687. doi:10.1080/0960085X.2020.1797546.
Vykopal J, Celeda P, Seda P, Svabensky V, Tovarnak D. Scalable learning environments for teaching cybersecurity hands-on. In: 2021 IEEE Frontiers in Education Conference (FIE). IEEE; 2021. doi:10.1109/FIE49875.2021.9637180.
Švábenský V, Vykopal J, Tovarňák D, Čeleda P. Toolset for collecting shell commands and its application in hands-on cybersecurity training. In: 2021 IEEE Frontiers in Education Conference (FIE). IEEE; 2021. doi:10.1109/FIE49875.2021.9637052.
Vykopal J, Švábenský V, Chang EC. Benefits and pitfalls of using Capture the Flag games in university courses. In: Proceedings of the 51st ACM Technical Symposium on Computer Science Education. New York: ACM; 2020. p. 752-758. doi:10.1145/3328778.3366893.