Attachment 3 - Capacity Building Training Program Capabilities and Requirements.pdf
PDF 266 KB Posted
- Attached to
- CISA Indefinite Delivery Indefinite Quantity Contract Federal contract opportunity
- Solicitation number
- 47QFRA25K0003
About this file
This is a training requirements document detailing CISA's cybersecurity training program needs across three main categories. The document outlines requirements for cybersecurity training capabilities, cyber range training capabilities, and cyber skilling training programs.
The requirements include providing both synchronous and asynchronous cybersecurity training courses ranging from 1-hour webinars to 5-day intensive programs, with topics covering system security, incident response, and forensics. A key component is the Cybersecurity Virtual Learning Environment (CVLE), a cloud-based AWS system that must support up to 150 concurrent students across three different target infrastructures. The Skilling Academy portion requires delivering entry-level and intermediate cybersecurity courses to federal employees (excluding contractors), with capacity for 500 students annually through micro-courses (1-2 weeks) and pathways (1-3 months). The system must include a comprehensive Learning Management System with automated registration, tracking, and reporting capabilities, while maintaining FISMA compliance and ATO status. Course delivery methods include live instructor-led training, hands-on labs, and virtual environments, with topics ranging from IT fundamentals to advanced cybersecurity concepts like artificial intelligence and machine learning.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Question and Answer Document 02-28-2025.pdf | ||
| RFI Revised - CISA IDIQ_02-28-2025 .pdf | ||
| Attachment 1 - CISA IDIQ - PWS as of 2-13-2025.pdf | ||
| RFI - CISA IDIQ_47QFRA25K0003_02-13-2025 .pdf | ||
| Attachment 2 - RFI for Cyber Training Program 02-13-2025.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 3 – Training Requirements Document
1.0 Background
The Cybersecurity and Infrastructure Security Agency (CISA) is the Nation’s risk advisor, working with partners to defend against today’s threats and collaborating to build more secure and resilient infrastructure for the future. In this role, CISA builds the Nation’s capacity to defend against cyber-attacks: the Agency works to provide cybersecurity tools, incident response capabilities, and assessment services to safeguard the Federal civilian executive branch (FCEB) ‘.gov’ systems and systems that support national critical functions.
Within CISA, the Cybersecurity Training program is a cornerstone contributor to the CISA awareness and training mandates to increase the skills of federal, state, local, tribal, territorial, veterans, and private sector stakeholders in industrial control systems and critical infrastructures.
As a strategic partner, we wish to work together to share cybersecurity training innovations, technological improvements, and cybersecurity relevant courses of instruction.
Cybersecurity training programs support the CISA mission by:
1) Providing effective skill development and cyber training programs to cyber practitioners that increase the capacity to maintain secure networks and infrastructure.
2) Expanding the availability of CISA-approved cybersecurity training courses across government and private sector critical infrastructure. Our audience is typically federal civilian executive organizations, state, local, territorial, tribal, and critical infrastructure stakeholders.
3) Leveraging the National Institute for Cybersecurity Education (NICE) Framework to standardize institutional implementation.
4) Acquiring, developing, and maintaining professional cyber training programs that prepare the workforce to develop and maintain systems to be as resilient as possible to intrusions with course content that meets the highest standards of excellence in design, development, and delivery.
5) Providing Virtual Learning Environment (VLE): A VLE, or Cyber Range provides lab and hands-on assessment components to CISA’s curriculum offerings.
6) Maximize access to cybersecurity training across federal government communities and establish alliances that strengthen CISA’s ability to reach the national cyber talent pool
The cybersecurity training program supports the CISA mission: Defend Today, Secure Tomorrow. To defend against urgent threats and vulnerabilities, we collaborate with partners to implement training strategies and develop curricula to help cybersecurity staff to address current cybersecurity threats. To secure against the ever-evolving cyber threat ecosystem, we work with key stakeholders to identify, prioritize, and address cybersecurity training gaps.
2.0 Training Capabilities and Requirements Description
Category 1: Cybersecurity Training Capabilities
The objective of the cybersecurity training program is to address critical skill gaps by offering entry-level, intermediate, and advanced cyber security training, leveraging interactive, hands-on labs, and developing innovative solutions to prepare the workforce for emerging threats. The challenge is to scale these efforts efficiently while ensuring compliance, adaptability, and seamless integration across multiple stakeholders, systems, and environments.
The objective of this requirement is to operate and maintain the existing cybersecurity training portfolio as well as provide for new development of cybersecurity training. This includes the following high level training programs:
1. Provide Securing Systems Awareness and Training Program: includes synchronous and asynchronous awareness and training for securing systems, what we refer to as the “left of boom” cybersecurity requirements. These topics include asynchronous instructor-led training, which is offered both in-person and virtual in-person. In addition, some courses are offered as asynchronous, see the definitions below for synchronous and asynchronous delivery methods which are included in the existing training program.
Topics for Securing Systems could include, but are not limited to:
1) Defending Internet Accessible Systems
2) Preventing Web and Email Server Attacks
3) Preventing DNS Infrastructure Tampering
4) Network Diagramming
5) Defend Against Ransomware Attacks
6) Log Management
7) Software as a Service Security with SCuBA
8) Zero Trust
a) Open-Source Software and Zero Trust
b) Zero Trust for Portfolio and Pillar Managers
c) Micro-segmentation and Zero Trust
d) ICAM and Zero Trust
9) Principles and Approaches for Secure By Design Software
10) Cyber Supply Chain Risk Management
11) Cyber Defense
12) Cybersecurity Management, Leadership, and Legal Topics
13) Cyber Culture, Policy, and Compliance
14) Common Attack Vectors
15) Network Security Basics (access control, network segmentation, etc.)
16) Access Control - ICAM, MFA
17) Data Protection and Privacy
18) Endpoint Security and Secure Devices
19) Cloud Security Basics
20) Operational Technology components
21) Continuous Monitoring
22) Elastic Stack Capabilities, including query knowledge and report generation
2. Provide Incident Response Awareness and Training Program: includes synchronous and asynchronous awareness and training for incident response, what we refer to as the “right of boom” cybersecurity requirements. These topics include asynchronous instructor-led training, which is offered both in-person and virtual in-person. In addition, some courses are offered as asynchronous, see the definitions below for synchronous and asynchronous delivery methods which are included in the existing training program.
Topics for Incident Response could include, but are not limited to:
1) Understanding Indicators of Compromise
2) Using the CISA Incident Response Playbook at your Organization
3) Incident Response Triage
4) Incident Response for Cloud Systems for SOC Analysts
5) Incident Response for Azure Cloud (entry level and intermediate)
6) Anatomy of a Ransomware Attack
7) Anatomy of Advanced Persistent Threats
8) Anatomy of Living off the Land attack vectors
9) Digital Evidence and Forensics
10) Network Investigations
11) Online Investigations
12) Threat Awareness and Intelligence
13) Windows Forensics
14) Kali tools and capabilities
Both of these training programs include full life-cycle requirements: planning, analysis, design, development, implementation, evaluation. In addition to life-cycle training requirements, the contractor shall have instructional design in technical subjects, instructors with experience teaching technical topics, and subject matter expertise in proposed topics and be able to leverage that expertise to ensure content meets learning requirements and cybersecurity relevancy. Key to the success is providing cybersecurity subject matter expertise during all phases and activities of the awareness and training life cycle. From the planning to the implementation, the contractor is responsible for ensuring content delivered is cybersecurity valid and relevant, as well as meeting adult learning principles. Implementation includes event management (scheduling, registration, announcements, reminders, etc.), After-Action Reports and Summaries, Monthly Status Reports, Course Update and Maintenance, and Measurements and Metrics.
Synchronous Training Delivery Models
To provide context, the following models of synchronous training formats currently exist in the programs and would be expected to continue:
1) One-Hour Webinar/Seminar Style (12 existing courses)
2) Two-Hour Webinar with Technical Demonstration (two existing courses)
3) Four-Hour Workshop with cyber labs (15 existing courses)
4) Seven-Hour Training with cyber Labs (3 existing courses)
5) Two-Day Training with cyber labs (3 existing courses)
6) Five-Day Training with cyber labs (2 existing courses)
Cyber labs encompass skill development, skill practice and may be scenarios/challenges or step-actions. Online labs provide hands-on practice in a live network environment. Unlike a simulation or demo, labs provide real-world step-by-step actions, scenarios, and challenges in a virtual environment. This requirement includes providing technical instructional staff for the development of the course material as well as the instructors to deliver the technical content.
Asynchronous Training Delivery Models
To provide context, the following models of asynchronous training formats currently exist in the programs and would be expected to continue (all must meet 508 compliance):
1) One-Hour Basic Design – 30% custom graphics, 15% student interactions, 10% customized graphical scenarios, and audio
2) One-Hour Intermediate Design – 50% custom graphics, 30% custom interactions and 20% customized graphical scenarios, and audio
3) 15-30 Minute Video Editing – record interviews with key executives, edit, and produce final versions
4) Micro-Learns: 8-10 minute or 15-20 Minute Lab Walk-Throughs (demonstrations) with Audio/Video interactions – provide micro-learn trainings for technical topics with video or audio introduction and lab demonstration/walk-through
Category 2: Cyber Range Training Capabilities
The objective of this requirement is to operate, maintain, and enhance the existing Cybersecurity Virtual Learning Environment (CVLE). The CVLE is a cloud-based system with dynamic virtual labs that can be instantiated and destroyed on demand. It provides the ability to conduct realistic, interactive cybersecurity training lab activities and is utilized for both synchronous and asynchronous training courses. The Cyber Range provides simulated lab environments in a safe environment for student learning. The purpose of CVLE is to meet the expanding training requirements to deliver courses with hands-on, interactive lab components.
The CVLE is a simulation (virtual instances) range with three primary components – a Landing Page, a Range Learning Management System (RLMS), and the Cyber Range for lab activities.
For this RFI, we are using the NIST NICE The Cyber Range A Guide (September 2023) definitions for the technical components to provide an established lexicon for all responses. We realize there may be overlaps between the technical components, we encourage you to explain how your experience and expertise melds within this framework. For example, there are many technical components that provide “tracking,” such as the Range Learning Management System providing course completion or the tracking of student interactions within a Target Infrastructure. In your response, please identify the multiple components providing the capability. The five cyber range technical components are:
● Range Learning Management System (RLMS)– standard features of a Learning Management System as well as characteristics specific to a cyber range. CVLE currently has a customized Moodle implementation. The Landing Page serves as the entry point to the RLMS and is currently using Okta for PIV holders and email PIN for non-PIV holders.
● Orchestration Layer – brings together the various technology and service components of a cyber range. CVLE has a customized developed range management system.
● Underlying infrastructure – CVLE’s underlying infrastructure is an AWS environment utilizing various AWS Web services.
● Virtualization Layer – reduces the physical footprint of a cyber range and is essential in delivering the Target Infrastructure’s simulated environment. CVLE currently uses a custom-developed remote gateway to access virtualized training environment hosted in
AWS.
● Target Infrastructure – the simulated environment in which students are trained. CVLE currently has 8 distinct target infrastructures containing multiple virtual machines within the image.
● Cross-cutting Capabilities – capabilities which may exist across two or more technical components.
The following provides the key requirements for the CVLE based on the technical components outlined in the NIST NICE The Cyber Range A Guide (September 2023) as well as several cross-cutting capabilities:
Cross-Cutting Capabilities:
● System must provide the capability for students to use virtual labs to conduct simulated, hands-on training for a variety of customizable cybersecurity scenarios.
● Users can access the system via a web browser without requiring additional software installations.
● To support scalability, the underlying infrastructure is in a CISA AWS cloud space. The system must be capable of supporting up to 150 concurrent students per day in three different target infrastructures. For example, there are three unique classes on one day with three unique target infrastructures and each class has 50 concurrent users requiring their own unique target infrastructure.
● Security and Compliance: Maintain Authority to Operate (ATO). The CVLE is currently in an AWS environment. An important component of the CVLE management is to maintain an ATO status, including ongoing authorization through continuous monitoring to ensure all FISMA, DHS, and CISA security requirements are met in a timely manner.
To include, but not limited to:
o Monitoring and detection functions, such as activity logging o Incident Response and Alerts o Compliance and Security Reporting o Software Updates and Patching o Privacy data protection (at rest and in transit) o Role-based access controls to ensure appropriate permissions for different work roles, such as administrators, instructors, course coordinators, and users accessing content and resources.
o Multifactor authentication to control access to the platform and resources. This includes managing the existing DHS Okta solution for DHS PIV holders.
● Integration: The RLMS and target infrastructure should be integrated with one another, as well as other third-party systems via application programming interface (API).
o Target infrastructure should integrate with front-end RLMS to display training course scores, progress, reports, etc.
o As needed, third-party integration with cloud service providers, security tools (e.g., detection/prevention), code repositories (e.g. GitLab, Azure DevOps) and tools to deliver or aid in delivering training (e.g., Netlab, WebEx, MS Teams)
● Administrative: The RLMS and target infrastructure should offer customizable environments for CISA-themed branding, course templates, dashboards, portals, etc.
o License/Subscription Management (Cloud, on-prem, surges, DR, etc.)
o Technical support
● Functional Reporting and Analytics: The CVLE should provide reporting and analytics on system performance including student behavioral analytics (leveraging AI) that track patterns to suggest training courses based on strength/weaknesses.
o Exportable Reports (System and User activities)
The system must also include the ability to add capabilities in each technical component to meet new functional or security requirements.
Range Learning Management System (RLMS) and Landing Page
● The RLMS must serve as a comprehensive learning management system capable of hosting online content, facilitating registration, tracking students, managing course administration functions, and generating reports. The RLMS must support robust interactivity features for students and administrators, including course tracking, self-registration, announcements, and reminders.
● The RLMS must provide an easy-to-use interface for instructors and course coordinators to manage and control the overall workflow of their courses effectively, to include uploading course material, creating online assessments, and typical course management functions.
● The RLMS must offer a course catalog that allows students to register for one or more courses seamlessly. The RLMS must provide the capability to “filter” course content into a subject matter area (CDM Only) or an audience group (.gov versus non.gov) and then restrict the view in the course catalog.
● The RLMS must facilitate automated email communication for announcements and course information, to include acceptance, waitlisting, denial, or course completion information.
● The RLMS must provide customizable analytics to facilitate detailed monitoring of events and performance metrics, using both built-in and third-party monitoring tools as appropriate. This includes built in and customizable reports of captured measurements from tracking features.
Orchestration Layer
● The orchestration layer must implement tools to automate the configuration and build out of complex network environments, reducing the time and effort required to set up and maintain these environments.
● The orchestration layer must include tools that optimize the use of the virtual environment to make the cyber range more accessible and scalable.
● The orchestration layer must automate the implementation and management of labs to reduce the resources needed for event setup and execution, thus improving efficiency, and lowering costs by minimizing manual intervention and labor.
● Cyber range integrates with existing tools and security systems both internally and externally (e.g., internal RLMS and external SIEMs).
● The orchestration layer must store user interaction and scenario data necessary to create the simulated environment, facilitating the transfer of information between layers.
Underlying infrastructure
● The underlying infrastructure must continue to be operated and maintained in the existing CISA AWS commercial environment.
● The underlying infrastructure must have backup and recovery capabilities to archive and restore user access to training content.
● In the event of an outage, the underlying infrastructure must ensure that the system can return to full operations within seven to ten business days.
● The underlying infrastructure must ensure remote access is available 24/7 for students, instructors, and administrators.
Virtualization Layer
● The virtualization layer must enable the CVLE platform to host individual virtual labs for each student, which can be instantiated or destroyed on demand.
● The virtualization layer must provide tools to automate the configuration and build out of complex network environments, reducing the time and effort required for setup and maintenance.
● The virtualization layer must automate the provision of virtual machines, and the management of server reset or upgrades to ensure efficient and correct setups of virtual machines and applications.
● The virtualization layer must include automated tools for validating simulated environments prior to events, ensuring they meet predefined requirements and function correctly.\
● The virtualization layer must allow for the connection to or import and export of existing virtual images of environments for training classes.
● The virtualization layer must allow instructors to view a student’s lab environment during synchronous lab activities for monitoring purposes.
Target Infrastructure
● The target infrastructure capabilities must provide the ability to build virtual labs efficiently and automatically – must show the ability to plan and design the complex capabilities needed to build realistic training environments and how to effectively organize, utilize, and retain them. Including the automation for participant measurements and metrics.
● The target infrastructure environment must provide at a minimum, but is not limited to the following:
o Simulate high-fidelity network traffic, web content and applications, including background and malicious traffic, to create realistic cybersecurity environments.
o Automated tools for lab activity or exercise management o Automated tools to generate templates for simulated environments o Automated tools to simulate realistic user behavior and generate network traffic, creating an authentic training environment.
o Capabilities to detect, log, and analyze attacks in real-time, providing feedback and insights for improving security measures o Automated tools to inject traffic or other lab attributes during training events, allowing seamless training without manual intervention o Simulation of a cloud environment.
o Ability to train on adversary attack methods o Labs on windows environment, including SaaS cloud environments o Virtual labs containing images /profiles with commercially available servers, storage, end points, applications, firewalls, IP Address ranges, routing information, server stacks, etc. for student training use.
Category 3: Cyber Skilling Training Program Requirements The primary focus of the Skilling Academy is to provide course offerings that positively impact cyber workforce growth and preparedness. Following the NICE Framework, the Skilling Academy offers structured training to ensure that graduates possess industry-relevant skills aligned to key cybersecurity work roles. By providing tailored education, CISA aims to diminish the existing and future cybersecurity skill gap and foster a workforce that is adept and prepared to face evolving cyber threats.
The Skilling Academy strives to maximize access to cybersecurity training across federal government communities and establish alliances that strengthen CISA’s ability to reach the national cyber talent pool. Through the Skilling Academy, CISA is able to address existing cyber workforce gaps by growing the availability of trained personnel, continuously improving the skillsets of existing cyber actors through education and training and fostering partnership to advance the cyber talent ecosystem across federal government departments and agencies.
Target Audience
All full-time federal employees, in any job series and any grade or grade equivalent for non- General Schedule (GS) employees, are eligible to apply to CISA's Federal Cyber Defense Skilling Academy. Government contractors are not permitted to participate.
The Skilling Academy primarily includes offerings for new skill development and enhancement for entry-level and intermediate audiences both with distinct purposes to enhance the cybersecurity workforce. Designated entry-level courses involve training participants to develop new skills that qualify them for different roles within various cybersecurity domains.
Intermediate courses are tailored for existing cybersecurity professionals to develop new skills or improve on existing skills to better perform their current role.
Student Throughput Metrics and Insights
The skilling academy currently supports the annual training of up to 500 students each year. This number could double, or triple based on the expansions of micro-course offerings over the anticipated period of performance.
Training Offerings:
Micro-Courses - Skilling Academy offers one-to-two-week courses designed to equip federal employees with foundational and specialized cybersecurity skills. Each course emphasizes practical training to ensure that participants gain real-world experience in protecting and defending against cyber threats. Through this targeted training, participants will learn introductory skills to help prepare them to take on essential cybersecurity roles, enhancing the security and resilience of the federal infrastructure. The virtual, synchronous courses shall include a virtual face-to-face instructor for the 40 or 80 hour course timeframe. These courses include hands-on virtual cyber range lab activities to enhance the training experience. These can be existing COTS training courses that may be customized to suit the needs of CBs Cyber Training Portfolio. Baseline Micro-Course Topics – The following topics serve as an initial baseline for the Skilling Program. This list is not exhaustive and may expand based on vendor recommendation and diversity of offerings:
● IT Fundamentals Micro-Course: 80-hour, ten-day, course that provides comprehensive knowledge in core IT and cybersecurity concepts. Students learn essential skills in operating systems, secure coding, Linux administration, network security, privacy compliance, and Python programming.
● Basics of Threat Analysis Micro-Course: 80-hour, ten-day, course that provides comprehensive knowledge in threat identification, analysis, and mitigation strategies. The program expands on foundational cybersecurity concepts and delivers in-depth coverage of threat modeling, vulnerability management, incident response, and advanced analysis techniques
● Introduction to Incident Detection, Response, and Handling Micro-Course: 80-hour, ten-day, course that provides comprehensive instruction in identifying, analyzing, and responding to security incidents in enterprise environments. The program builds from foundational security concepts through advanced incident handling techniques.
● Introduction to Forensics Analysis Micro-Course: 80-hour, ten-day, training program providing comprehensive training in digital forensics, evidence handling, and security analysis. This extensive course equips students with advanced skills in digital forensic investigations, security assessment, and incident analysis.
● Introduction to Incident Response Micro-Course: 40-hour, five-day, course that provides entry-level training in incident response, detection, and handling. This foundational course equips students with essential cybersecurity knowledge and practical skills needed to identify, respond to, and manage security incidents in modern IT environments.
● Introduction to Pen-Testing Micro-Course: 40-hour, five-day, course that provides foundational knowledge and hands-on experience in ethical hacking. Participants learn key concepts like vulnerability management, network, and web security, and advanced pen testing techniques.
Pathways: Skilling Academy Pathways are designed for students to go through an intense, full-time, one to three-month accelerated training program. Pathway students are provided with valuable opportunities to practice cybersecurity skills in lab environments, offered at no cost to students in a 100% virtual environment as the courses are live and led by an online instructor.
Students will be required to attend Monday through Friday from 8 a.m. to 5 p.m. ET for the entire duration of the course (excluding federal holidays and predetermined session breaks).
For FY25 the Skilling Academy is offering 13 different course topics ranging from 1-12 weeks in duration. Each course is available to individuals of all cyber experience though the content is generally beginner friendly. Brief details on each course are listed below.
FY25 Pathway Topics:
● Defensive Cybersecurity Pathway: 12-week live, instructor-led cybersecurity training course that provides comprehensive education in cybersecurity defense and vulnerability analysis.
Through hands-on labs and real-world scenarios, participants master essential skills in identifying and mitigating vulnerabilities across networks, systems, and cloud environments.
● Vulnerability Analysis Pathway: 4-week live, instructor led, cybersecurity training course that teaches professionals how to identify, assess, and manage security vulnerabilities across digital systems. Through hands-on labs and real-world scenarios, participants learn essential skills in vulnerability scanning, web application security, and enterprise-level vulnerability management, preparing them to tackle modern organizational security challenges.
● Infrastructure Support Pathway: 4-week live, instructor-led cybersecurity training course that provides comprehensive hands-on experience in managing and troubleshooting essential IT infrastructure components. Through practical labs and real-world scenarios, participants master hardware, software, and network management while gaining expertise in cloud services integration and professional IT support delivery.
● Incident Response Pathway: 4-week live, instructor-led cybersecurity training course that equips professionals with essential skills in cybersecurity incident handling. Through hands-on labs and real-world scenarios, participants master incident detection, analysis, containment, and recovery techniques across both traditional and cloud environments.
● Digital Forensics Pathway: 4-week live, instructor-led cybersecurity training course that equips professionals with essential skills in digital evidence handling and analysis. Through hands-on labs and real-world scenarios, participants master forensic tools and techniques for investigating devices, networks, and cloud environments.
● Systems Security Analysis Pathway: 4-week live, instructor-led cybersecurity training course that equips professionals with essential skills in analyzing and securing modern IT infrastructures. Through hands-on labs and real-world simulations, participants master vulnerability assessment, system hardening, and security control implementation across traditional and cloud environments.
● Artificial Intelligence/Machine Learning Pathway: 4-week live, instructor-led cybersecurity training course that teaches essential skills in developing generative AI applications. Through hands-on labs and practical projects, participants master neural networks, natural language processing, and modern generative models like GANs, VAEs, and transformers.
Skilling LMS and Application Portal
The Skilling Program requires a Learning Management System and landing page to support a portal for students to apply for the Skilling Academy. It is anticipated that the Skilling Program would leverage the same RLMS required for the broader Cyber Training Portfolio (see Category 2 above) but at minimum the Skilling Academy Portal shall serve as the comprehensive management system capable of hosting online content, facilitating registration, tracking students, managing course administration functions, and generating reports.
The LMS must support robust interactivity features for students and administrators, including course tracking, self-registration, announcements, and reminders.
The LMS must provide an easy-to-use interface for instructors and course coordinators to manage and control the overall workflow of their courses effectively, to include uploading course material, creating online assessments, and typical course management functions.
The LMS must offer a course catalog that allows students to register for one or more courses seamlessly. The LMS must provide the capability to “filter” course content into a subject matter area (CDM Only) or an audience group (.gov versus non.gov) and then restrict the view in the course catalog.
The LMS must facilitate automated email communication for announcements and course information, to include acceptance, waitlisting, denial, or course completion information.
The LMS must provide customizable analytics to facilitate detailed monitoring of events and performance metrics, using both built-in and third-party monitoring tools as appropriate. This includes built in and customizable reports of captured measurements from tracking features.
Further specifications shall be provided after receipt of RFI responses.
| Attachment 3 – Training Requirements Document |
| 1.0 Background |
| 2.0 Training Capabilities and Requirements Description |
| Category 1: Cybersecurity Training Capabilities |
| Category 2: Cyber Range Training Capabilities |
| Category 3: Cyber Skilling Training Program Requirements |
File details come from the government source that posted it. Updated .