Attachment 2 - RFI for Cyber Training Program 02-13-2025.pdf
PDF 172 KB Posted
- Attached to
- CISA Indefinite Delivery Indefinite Quantity Contract Federal contract opportunity
- Solicitation number
- 47QFRA25K0003
About this file
This is a Request for Information (RFI) issued by GSA Federal Acquisition Service on behalf of CISA seeking industry input on developing, enhancing, and operating a cloud-based Cybersecurity Virtual Learning Environment (CVLE) and delivering cybersecurity training programs. The RFI outlines three main requirement areas: 1) Providing cybersecurity training capabilities from entry to advanced levels through synchronous and asynchronous delivery methods, 2) Operating and maintaining the CVLE cloud-based system which includes five technical components (Range Learning Management System, Orchestration Layer, AWS infrastructure, Virtualization Layer, and Target Infrastructure), and 3) Supporting the Federal Cyber Defense Skilling Academy that trains approximately 500 students annually through micro-courses (1-2 weeks) and intensive pathways programs (1-3 months).
The government seeks responses from potential prime contractors regarding their expertise in cloud systems, virtual environments, learning management systems, and cybersecurity training development. Companies must describe their experience in managing cloud-based cyber ranges, developing target infrastructures, and delivering both synchronous and asynchronous training covering at least 8-10 identified cybersecurity topics. The RFI asks respondents to provide recommendations on acquisition approach and contract types, and whether the requirements should be split into separate functional areas or kept as a single comprehensive effort. This market research will inform a potential future solicitation, though the government is not obligated to release one based on this RFI.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Question and Answer Document 02-28-2025.pdf | ||
| RFI Revised - CISA IDIQ_02-28-2025 .pdf | ||
| Attachment 1 - CISA IDIQ - PWS as of 2-13-2025.pdf | ||
| Attachment 3 - Capacity Building Training Program Capabilities and Requirements.pdf | ||
| RFI - CISA IDIQ_47QFRA25K0003_02-13-2025 .pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 2 - Supplemental Request for Information (RFI) – Capacity Building Cybersecurity Training Program
I. GENERAL INFORMATION:
The General Services Administration (GSA), Federal Acquisition Service (FAS), Assisted Acquisition Services (AAS) is issuing a Request for Information (RFI) on behalf of the Cybersecurity and Infrastructure Security Agency (CISA).
II. PURPOSE:
The purpose of this supplemental RFI is to assist the Government in conducting market research focused on identifying industry partners that can 1) develop, enhance, operate and sustain a cloud-based Cybersecurity Virtual Learning Environment (CVLE); 2) plan, design, develop cybersecurity instructional materials and deliver synchronous and asynchronous training. The government has provided a draft requirements description document for reference. Responses to this RFI will be used for market research only. The Government is not obligated to release a future solicitation based on this market research.
Interested respondents shall refer to the details of the response to this RFI under Section
IV.
III. BACKGROUND:
The U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) leads the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure that Americans rely on every hour of every day. In its role as the nation’s cyber defense agency and the national coordinator for critical infrastructure security, CISA works with critical infrastructure partners every day to address the evolving threat landscape.
The risks it faces are complex and geographically dispersed, and they affect a diverse array of stakeholders, including Federal Civilian Executive Branch (FCEB) agencies; private sector companies; and state, local, tribal, and territorial (SLTT) governments and Critical Infrastructure (CI) entities. CISA spearheads a national effort to ensure the defense and resilience of cyberspace and is building the national capacity to defend against and recover from cyberattacks.
It works with federal partners to bolster their cybersecurity and incident response postures and safeguard the FCEB networks that support the nation’s essential operations and partners with the private sector and others to detect and mitigate cyber threats and vulnerabilities before they become incidents.
The federal enterprise relies heavily on information technology (IT) systems and computer networks for critical operations. CISA, via its Cybersecurity Division (CSD), collaborates with each FCEB agency to encourage the implementation of standardized policies and best practices.
These practices are designed to be risk-aware and dynamic enough to counter the rapidly evolving threat landscape.
CSD leads initiatives to safeguard the FCEB government networks and collaborates with the private sector to bolster the security of vital networks. The core mission of CSD centers on the FCEB, with a particular emphasis on comprehending the changing landscape of threats that impact national critical functions and high-value assets. This ensures that stakeholders have access to crucial data regarding the risk status of pivotal information systems. Within CSD, Capacity Building (CB) is responsible for providing support and fostering partnerships with various stakeholders throughout the FCEB. Additionally, CB is committed to ongoing collaboration with CISA and its various Divisions and Subdivisions.
The CB mission is to provide best-in-class services to advance and centralize cybersecurity capabilities across the FCEB and execute the agency’s statutory role under the Federal Information Security Modernization Act to improve federal cybersecurity via effective guidance, support, and directives.
Within CB, Cyber Training is a contributor to the CISA awareness and training mandates to increase the skills of federal, state, local, tribal, territorial, veterans, and private sector stakeholders in industrial control systems and critical infrastructures.
As a strategic partner, the Cyber Training organization shares cybersecurity training innovations, technological improvements, and cybersecurity relevant courses of instruction.
CB’s Cyber Training programs support the CISA mission by:
● Providing effective skill development and cyber training programs to cyber practitioners that increase the capacity to maintain secure networks and infrastructure.
● Expanding the availability of CISA-approved cybersecurity training courses across government and private sector critical infrastructure. The audience is typically federal civilian executive organizations, state, local, territorial, tribal, and critical infrastructure stakeholders.
● Leveraging the National Institute for Cybersecurity Education (NICE) Framework to standardize institutional implementation.
● Acquiring, developing, and maintaining professional cyber training programs that prepare the workforce to develop and maintain systems to be as resilient as possible to intrusions with course content that meets the highest standards of excellence in design, development, and delivery.
● Providing Virtual Learning Environment (VLE): A VLE, or Cyber Range provides lab and hands-on assessment components to CISA’s curriculum offerings.
CB’s training programs support the CISA mission: Defend Today, Secure Tomorrow.
To defend against urgent threats and vulnerabilities, CISA collaborates with partners to implement training strategies and develop curricula to help cybersecurity staff to address current cybersecurity threats. To secure against the ever-evolving cyber threat ecosystem, CISA works with key stakeholders to identify, prioritize, and address cybersecurity training gaps.
IV. OBJECTIVE:
The objective of the cybersecurity training program is to address critical skill gaps by offering entry-level, intermediate, and advanced cyber security training, leveraging interactive, hands-on labs, and developing innovative solutions to prepare the workforce for emerging threats. The intent is to offer a diverse training portfolio to allow for different types of delivery mechanisms and environments. The challenge is to scale these efforts efficiently while ensuring compliance, adaptability, and seamless integration across multiple stakeholders, systems, and environments.
V. REQUIREMENT OBJECTIVES:
Attachment 3 provides insights into draft capabilities and requirements the government is looking to implement to support the training program. The following is a high-level description of the functional areas for CB’s Training Program(s). Please note these are not final and not meant to be interpreted as comprehensive task areas:
1) Provide Cybersecurity Training Capabilities - The objective of the cybersecurity training program is to address critical skill gaps by offering entry-level, intermediate, and advanced cyber security training, leveraging interactive, hands-on labs, and developing innovative solutions to prepare the workforce for emerging threats. The challenge is to scale these efforts efficiently while ensuring compliance, adaptability, and seamless integration across multiple stakeholders, systems, and environments.
The objective of this requirement is to operate and maintain the existing cybersecurity training portfolio as well as provide for new development of cybersecurity training. This includes the supporting the objectives of the training programs which can be delivered through Synchronous and Asynchronous methodologies (See attachment for details):
2) Provide Cyber Range Training Capabilities - The objective of this requirement is to operate, maintain, and enhance the existing Cybersecurity Virtual Learning Environment (CVLE). The CVLE is a cloud-based system with dynamic virtual labs that can be instantiated and destroyed on demand. It provides the ability to conduct realistic, interactive cybersecurity training lab activities and is utilized for both synchronous and asynchronous training courses.
The Cyber Range provides simulated lab environments in a safe environment for student learning. The purpose of CVLE is to meet the expanding training requirements to deliver web-based courses with hands-on, interactive lab components. The five cyber range technical components are:
● Range Learning Management System (RLMS)– standard features of a Learning Management System as well as characteristics specific to a cyber range. CVLE currently has a customized Moodle implementation. The Landing Page serves as the entry point to the RLMS and is currently using Okta for PIV holders and email PIN for non-PIV holders.
● Orchestration Layer – brings together the various technology and service components of a cyber range. CVLE has a customized developed range management system.
● Underlying infrastructure – CVLE’s underlying infrastructure is an AWS environment utilizing various AWS Web services.
● Virtualization Layer – reduces the physical footprint of a cyber range and is essential in delivering the Target Infrastructure’s simulated environment. CVLE currently uses a custom-developed remote gateway to access virtualized training environments hosted in
AWS.
● Target Infrastructure – the simulated environment in which students are trained. CVLE currently has 8 distinct target infrastructures containing multiple virtual machines within the image.
● Cross-cutting Capabilities – capabilities which may exist across two or more technical components.
3) Provide Cyber Training for the Federal Cyber Defense Skilling Academy - The Skilling Academy strives to maximize access to cybersecurity training across federal government communities and establish alliances that strengthen CISA’s ability to reach the federal cyber talent pool. Through the Skilling Academy, CISA is able to address existing cyber workforce gaps by growing the availability of trained personnel, continuously improving the skillsets of existing cyber actors through education and training and fostering partnership to advance the cyber talent ecosystem across federal government departments and agencies.
The Skilling Academy provides training offerings for new skill development and enhancement for entry-level and intermediate audiences. Designated entry-level courses involve training participants to develop new skills that qualify them for different roles within various cybersecurity domains. Intermediate courses are tailored for existing cybersecurity professionals to develop new skills or improve on existing skills to better perform their current role. CB anticipates training roughly 500 students annually through Micro-Courses and Cyber Skilling Pathways.
Micro-courses are one-to-two-week training offerings, designed to equip federal employees with foundational and specialized cybersecurity skills. Each course emphasizes practical training to ensure that participants gain real-world experience in protecting and defending against cyber threats. Through this targeted training, participants learn introductory skills to help prepare them to take on essential cybersecurity roles, enhancing the security and resilience of the nation’s infrastructure (see topics in Attachment 3) Skilling Pathways are designed for students to go through an intense, full-time, one to three-month daily accelerated training program. Pathway students are provided with valuable opportunities to practice cybersecurity skills in lab environments, in a 100% virtual environment as the courses are live and led by an online instructor (see topics in Attachment 3)
VI. RFI RESPONSE:
The Government will only consider responses from Industry Partners which intend to do the work as a Prime contractor. Responses are required to include the following information:
CORPORATE EXPERIENCE:
1. Submit corporate experience IAW the RFI, table 2. Please identify any existing Government contract vehicle(s) (GWAC, Federal Supply Schedules, BPA, etc.) that your company currently holds which could support the Cybersecurity Training requirement.
QUESTIONS:
1. Given the scope areas and technical components included in the RFI Attachment 1 , please provide recommendations on an overarching acquisition approach, contract types and incentives.
2. Highlight expertise and experiences that account for the entirety of the requirement, such as:
A. Expertise required to develop, enhance, and maintain the Cyber Virtual Learning Environment (CVLE) (i.e., enhancing management of Cloud-based systems and virtualized environments)
B. Architectural and Cloud expertise to analyze, diagnose and make optimization recommendations for the CVLE approach.
C. Development, customization and sustainment of web-based learning management systems
D. Expertise to plan, design, develop, integrate, modify, update, and deliver the entry-level, intermediate and advanced cyber training and instructional materials associated with all of the Cyber Training programs.
3. Given the diversity of the technical areas, should the government consider truncating functional areas into more narrowly scoped efforts (ie, Engineering support for CVLE;
Cloud Support; Developer support; Training development support; Cyber Skilling Academy Support)? Or is your company positioned to execute all of the government’s training and hosting requirements?
4. Describe your experience providing synchronous and asynchronous cybersecurity awareness and training courses with at least 8-10 of the identified topics. Highlight the technical instructional design and instructor experience, as well as critical subject matter expertise.
5. Describe your experience managing and utilizing a virtual cloud based cyber range for delivering cybersecurity training courses, both synchronous and asynchronous that contain interactive virtual lab components. Highlight experience in system development and any experience in security control compliance and ATO support for the system.
6. Describe your experience in developing Target Infrastructures and how this has impacted the learner experience.
| I. GENERAL INFORMATION: |
| II. PURPOSE: |
| III. BACKGROUND: |
| IV. OBJECTIVE: |
| V. REQUIREMENT OBJECTIVES: |
| VI. RFI RESPONSE: |
File details come from the government source that posted it. Updated .