The file's text, extracted by GovTribe without its formatting.
DEPARTMENT OF THE AIR FORCE
STRAWMAN CTS E3OBR17D1 002B
81st Training Group (AETC)
(PDS Code OKO)
Keesler Air Force Base, MS 39534-2494
October 2014 UNDERGRADUATE CYBERSPACE TRAINING (phase 2)
1. Implementation of training in support of this CTS is with class beginning 2016______ and graduating 2016______.
2. Purpose. This course training standard:
a. Establishes the training requirements using tasks, knowledge and training proficiency levels for training for course E3OBR17D1 002B, Undergraduate Cyberspace Training (phase 2).
b. Provides the basis for the development of more detailed training materials, training objectives, and the training evaluation instruments for the course.
3. Course Description. This group paced in-resident course provides initial skills training to selected Air Force officers with AFSC 17DX and civilian equivalents in the fundamental knowledge and skills needed to perform duties across the spectrum of the cyberspace domain. The scope of this course consists of an introduction to Network Warfare Concepts; Governance, Law, Ethics; Air Force Information Network (AFIN) Architecture; Advanced Networking; Packet/Traffic Analysis; Offensive Cyberspace Operations (OCO); Mobile Networks; Network Threats and Defense; Mitigating Threats; Cryptography & Authentication; Authentication Methods; Messaging Security; User and Role-Based Security; Public Key Infrastructure; Access Security; Ports, Protocols, and Services; Network Security; Wireless Security; Remote Access Security; Auditing, Logging, and Monitoring; Organizational Security; Business Continuity; Telephony; Space and Satellite Networks; Integrated Air Defense (IADS) Networks; Command & Control (C2) and Tactical Data Link (TDL) Networks; Industrial Control Systems; and Fighting through a Cyber Attack (Capstone).
4. Qualitative Requirements. Attachment 1 contains the tasks, knowledge, and training proficiency levels referenced in paragraph 2. Prerequisite: This course requires an active Top Secret/SCI clearance by class start date.
5. Recommendations. Comments and recommendations are invited concerning quality of AETC training. Reference this CTS and identify the specific area of concern (paragraph, training standard element, etc.) to 81 TRG/TGET, 825 Hercules Street, Suite 114, Keesler AFB, MS 39534-2037. A customer service information line has been installed for the supervisors’ convenience to identify graduates who may have received over or under training on task/knowledge items listed in this training standard. For a quick response to problems, call our customer information line at DSN 597-4566, or fax us at DSN 597-3790, or e-mail us at 81trg-tget@us.af.mil.
GEORGE W. TOMBE, IV, Colonel, USAF
Commander
1 Atch
Qualitative Requirements
Supersedes CTS E3OBR17D1 002A, 8 August 2013 Prepared by: 333 TRS/TRR
Approved by and Date: 333 TRS/TRR, 28 October 2014 Distribution:
SAF/A3CF-1; HQ AETC/A1MRT-1; AETC/A3TC-1; 81 FSS/FSMM-1; 81 TRG/TGET-1; 333 TRS/UMA-1
E3OBR17D1 002B
QUALITATIVE REQUIREMENTS
PROFICIENCY CODE KEY
| SCALE VALUE |
| DEFINITION: The individual |
TASK
PERFORMANCE
LEVELS
| 1 |
| Can do simple parts of the task. Needs to be told or shown how to do most of the task. (EXTREMELY LIMITED) |
| 2 |
| Can do most parts of the task. Needs help only on hardest parts. (PARTIALLY PROFICIENT) |
| 3 |
| Can do all parts of the task. Needs only a spot check of completed word. (COMPETENT) |
| 4 |
| Can do the complete task quickly and accurately. Can tell or show others how to do the tasks. (HIGHLY PROFICIENT) |
*TASK
KNOWLEDGE
LEVELS
| a |
| Can name parts, tools, and simple facts about the task. (NOMENCLATURE) |
| b |
| Can determine step by step procedures for doing the task. (PROCEDURES) |
| c |
| Can identify why and when the task must be done and why each step is needed. (OPERATING PRINCIPLES) |
| d |
| Can predict, isolate, and resolve problems about the task. (COMPLETE THEORY) |
**SUBJECT
KNOWLEDGE
LEVELS
| A |
| Can identify basic facts and terms about the subject. (FACTS) |
| B |
| Can identify relationship of basic facts and state general principles about the subject. (PRINCIPLES) |
| C |
| Can analyze facts and principles and draw conclusions about the subject. (ANALYSIS) |
| D |
| Can evaluate conditions and make proper decisions about the subject. (EVALUATION) |
EXPLANATIONS
* A task knowledge scale value may be used alone or with a task performance scale value to define a level of knowledge for a specific task. (Examples: b and 1b) A subject knowledge scale value is used alone to define a level of knowledge for a subject not directly related to any specific task, ** or for a subject common to several tasks.
- This mark is used alone instead of a scale value to show that no proficiency training is provided in the course.
X This mark is used alone in course columns to show that training is required but not given due to limitations in resources.
E3OBR17D1 002B
Task, Knowledge, and Proficiency Level
| 1. NETWORK WARFARE CONCEPTS |
| - |
| 1.1. Terms and Definitions |
| B |
| 1.2. Roles and Responsibilities |
| B |
| 1.3. Area of Responsibility (AOR) |
| B |
| 1.4. Hacker Methodology |
| B |
| 1.5. Capabilities & Weapons Systems |
| B |
| 1.6. Tactics, Techniques and Procedures |
| B |
| 1.7. Capabilities and Vectors |
| B |
| 1.8. Plan, Brief, Execute & Debrief Process |
| B |
| 1.9. Measures of Effectiveness/Performance |
| B |
| 1.10. Intelligence and Technical Gain/Loss |
| B |
| 1.11. Operations and Resource Management |
| B |
| 1.12. Platform Defensive Measures |
| B |
| 1.13. Network Operations Orders |
| B |
| 1.14. Perform Targeting |
| 2b |
| 1.15. Perform Operational Analysis |
| 2b |
| 2. GOVERNANCE, LAW, ETHICS |
| - |
| 2.2. Law of Armed Conflict |
| B |
| 2.3. Uniform Code of Military Justice |
| B |
| 2.4. Domestic Law, Policy and Rules of Engagement |
| A |
| 2.5. International Legal Considerations |
| A |
| 2.9. Consent to Monitoring |
| B |
| 2.10. Military Cyberspace Implications |
| B |
| 2.11. Cyberspace Operations Law |
| B |
| 2.12. Regulations for the Networking Environment |
| B |
| 2.13. Air Force Instructions |
| B |
| 3. Air Force Information Network (AFIN) Architecture |
| - |
| 3.1. Network Management Functions |
| B |
| 3.3. Operate Administrative Tools |
| 2b |
| 3.4. Perform Network Management |
| 2b |
| 3.5. Perform Security Measures & Defense |
| 2b |
| 3.6. Perform Network Simulations and Configurations |
| 2b |
| 4.1. Identify IP Packet Generation/Flags |
| 2b |
| 4.2. Identify TCP Packet Generation/Flags |
| 2b |
| 4.3. Demonstrate Encapsulation/Fragmentation |
| 2b |
| 4.4. Identify Internet Control Message Protocol (ICMP) |
| 2b |
| 4.5. Establish maintain and close TCP connections |
| 2b |
| 5. PACKET/TRAFFIC ANALYSIS |
| - |
| 5.1. Normal traffic header/payloads |
| B |
| 5.3. Anomalous - Benign |
| B |
| 5.4. Malicious Traffic (Beaconing, Spearfishing, Exfil, Worm, and EXE) |
| B |
| 5.5. Deep vs. Shallow Packet Inspection |
| B |
| 5.6. Stateful Inspection |
| B |
| 5.7. Behavioral Traffic Analysis within the AFNET |
| B |
| 6. OFFENSIVE CYBERSPACE OPERATIONS (OCO) |
| - |
| 6.1. Perform Nodal Analysis |
| 2b |
| 6.2. Perform OCO Mission Planning |
| 2b |
| 6.3. Employ Mission Execution |
| 2b |
| 6.4. Prepare and Present OCO Mission Debrief |
| 2b |
| 6.5. Prepare and Present a Master Station Log Brief |
| 2b |
| 7.1. Attack & Exploit Methods |
| B |
| 7.2. Perform Mobile Mission Planning |
| 2b |
| 7.3. Execute Mobile Mission |
| 2b |
| 7.4. Prepare and Present Mobile Mission Debrief |
| 2b |
| 8. NETWORK THREATS AND DEFENSE |
| - |
| 8.1. Operate and Manage Incident Prevention, Detection, Response and Handling |
| 2b |
| 8.2. Current Cyber Threats and Attacks |
| B |
| 8.3. Cyber Network Defensive Strategies and TTP’s |
| B |
| 8.4. Perform Network Defense Mission Planning |
| 2b |
| 8.5. Intel support to cyber warfare |
| B |
| 8.6. Execute a Network Defense Mission |
| 2b |
| 8.7. Prepare and Present Network Defense Mission Debrief |
| 2b |
| 9.1. Virus and Spyware Management |
| B |
| 9.3. Social Engineering Threats |
| B |
| 10. CRYPTOGRAPHY & AUTHENTICATION |
| - |
| 10.1. Symmetric Cryptography |
| B |
| 10.2. Asymmetric Cryptography |
| B |
| 11. AUTHENTICATION METHODS |
| - |
| 12.2. Messaging and Peer-to-Peer Security |
| B |
| 13. USER AND ROLE-BASED SECURITY |
| - |
| 13.1. Security Policies |
| B |
| 13.2. Securing File and Print Resources |
| B |
| 14. PUBLIC KEY INFRASTRUCTURE |
| - |
| 14.1. Key Management and Life Cycle |
| B |
| 14.2. Certificate Server Setup |
| B |
| 14.3. Web Server Security with PKI |
| B |
| 15.1. Biometric Systems |
| B |
| 15.2. Physical Access Security |
| B |
| 15.3. Peripheral and Component Security |
| B |
| 15.4. Storage Device Security |
| B |
| 16. PORTS, PROTOCOLS, AND SERVICES |
| - |
| 16.2. Perform Protocol-based Attacks |
| 2b |
| 16.3. Common System Services |
| B |
| 17.1. Common Network Devices |
| B |
| 17.2. Secure Network Topologies |
| B |
| 17.3. Browser-related Network Security |
| B |
| 18.1. Non-PC Wireless Devices |
| B |
| 19. REMOTE ACCESS SECURITY |
| - |
| 19.1. Perform Remote Access |
| 2b |
| 19.2. Operate Virtual Private Networks |
| 2b |
| 20. AUDITING, LOGGING, AND MONITORING |
| - |
| 20.2. Server Monitoring |
| B |
| 21. ORGANIZATIONAL SECURITY |
| - |
| 21.1. Organizational Policies |
| B |
| 21.2. Education and Training |
| B |
| 21.3. Disposal and Destruction |
| B |
| 22. BUSINESS CONTINUITY |
| - |
| 22.1. Redundancy Planning |
| B |
| 22.3. Environmental Controls |
| B |
| 23.1. Design and Architecture |
| B |
| 23.2. Manipulate Components and Configurations |
| 2b |
| 23.3. Attack, Exploit & Defensive Strategies |
| B |
| 23.4. Perform Security Measures & Defense |
| 2b |
| 23.5. Perform Telephony Mission Planning |
| 2b |
| 23.6. Execute Telephony Mission |
| 2b |
| 23.7. Prepare and Present Telephony Mission Debrief |
| 2b |
| 23.8. Approved Products List |
| B |
| 24. SPACE AND SATELLITE NETWORKS |
| - |
| 24.1. Design and Architecture |
| B |
| 24.2. Components and Configurations |
| B |
| 24.3. Commercial and MILSATCOM |
| B |
| 24.5. National Technical Means |
| B |
| 24.6. Attack, Exploit & Defensive Strategies |
| B |
| 25. INTEGRATED AIR DEFENSE (IADS) NETWORKS |
| - |
| 25.1. Design and Architecture |
| B |
| 25.2. Components and Configurations |
| B |
| 25.3. Attack, Exploit & Defensive Strategies |
| B |
| 25.4. Perform Security Measures and Defense |
| 2b |
| 25.5. Perform IADS Mission Analysis |
| 2b |
| 25.6. Develop Defensive and Offensive Courses of Action |
| 2b |
| 25.7. Prepare and Present IADS C2 and TDL Mission Analysis Brief |
| 2b |
| 26. COMMAND & CONTROL(C2) AND TACTICAL DATA LINK (TDL) NETWORKS |
| - |
| 26.1. Design and Architecture |
| B |
| 26.2. Components and Configurations |
| B |
| 26.4. Attack, Exploit & Defensive Strategies |
| 2b |
| 26.5. Perform Security Measures & Defense |
| 2b |
| 26.6. Perform C2 & TDL Mission Analysis |
| 2b |
| 26.7. Develop Defensive and Offensive Courses of Action |
| 2b |
| 26.8. Prepare and Present C2 & TDL Mission Analysis Brief |
| 2b |
| 27. INDUSTRIAL CONTROL SYSTEMS |
| - |
| 27.1. Design and Architecture |
| B |
| 27.2. Manipulate Components and Configurations |
| B |
| 27.3. Attack, Exploit & Defensive Strategies |
| B |
| 27.4. Perform Security Measures & Defense |
| 2b |
| 27.5. Perform ICS Mission Planning |
| 2b |
| 27.6. Execute an ICS Mission |
| 2b |
| 27.7. Prepare and Present ICS Mission Debrief |
| 2b |
| 28. FIGHTING THROUGH A CYBER ATTACK (CAPSTONE) |
| - |
| 28.1. Plan Cyber Operations |
| 2b |
| 28.2. Attack Cyber Technologies |
| 2b |
| 28.3. Defend Networks and Systems |
| 2b |
28.4. Prepare and Present Mission Brief and Debrief
SUMMARY OF CHANGES
This course training standard is the result of the April 2014 – 17X Specialty Training Requirements Team (STRT) tasking to review and update training requirements for Undergraduate Cyberspace Training; the realignment of all training task elements to produce a logical training progression flow from initial training, to awarding the Air Force Specialty Code (AFSC), to awarding the A-shred.
2b