CyOFTS_II_Section_L_Attachment_2_.docx

DOCX document 15 KB Posted

Attached to
Cyber Operations Formal Training Support (CyOFTS II) Federal contract opportunity
Solicitation number
FA8773-17-R-8005
Issued by
Department of the Air Force Space Command

About this file

Section L, Attachment 2

View the file

Other files for this federal contract opportunity

Other files attached to Cyber Operations Formal Training Support (CyOFTS II), newest first.
File Type Posted
RFP_Questions_and_Answers_consolidated_(003).xlsx XLSX spreadsheet
Combined_CyOFTS_II_Questions.xlsx XLSX spreadsheet
CyOFTS_II__Section_J_Attachment_2_-_Pricing_Table.xlsx XLSX spreadsheet
CyOFTS_II,_Section_L,_Attachment_5_PPQ_Tracking_Record.doc DOC document
CyOFTS_II,_Section_L,_Attachment_3_Pt_IV.docx DOCX document
FA8773-17-R-8005,_CyOFTS_II.docx DOCX document
CyOFTS_II,_Section_L,_Attachment_3,_Pt_III.docx DOCX document
CyOFTS_II_PWS_May_2017.docx DOCX document
CyOFTSII_Draft_RFP_Q&A.xlsx XLSX spreadsheet
CyOFTS_II_Section_L,_Attachment_4_PPI_Instruction.docx DOCX document
CyOFTS_II_Section_M-_Attachment_1_.docx DOCX document
CyOFTS_II_Section_L-_Attachment_1.docx DOCX document
CyOFTS_II,_Section_L_Attachment_8_-_Reading_Library_Instructions.docx DOCX document
CyOFTS_II_Section_L,_Attachment_7_Past_Performance_Questionnaire.docx DOCX document
DD_254,_CyOFTS_II.pdf PDF
CyOFTS_II,_Section_L,_Attachment_3_Part_II.pptx PPTX presentation
CyOFTS_II,_Section_L,_Attachment_6_PPQ_Cover_Letter.doc DOC document
CyOFTS_II,_Section_L,_Attachment_3_Pt_I.docx DOCX document
Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Section L, Attachment 2 Training Task List This requirement is to create a one hour cognitive lesson and a one hour hands-on lesson. The cognitive lesson should cover the incident response process as defined by the National Institute of Standards and Technology (NIST) (Additional sources may be used for amplification), and how this process is applied across the USAF Enterprise network through the AF Cyber Weapon Systems. The weapon systems should be defined and it should be thoroughly explained their specific responsibilities and how they work together to respond to incidents within the AF network. Additionally, the lesson should define how understanding the configuration of the systems in the environment can aid the incident response process through the creation of baseline documentation.

The one hour hands-on lesson must cover the considerations for creating a host baseline for Windows systems. The lesson must cover the necessary Windows command-line commands and select components of the Sysinternals Suite and how they can be used for conducting a host baseline on local and remote Windows systems located within a small domain.

Lesson Parts I, II, III, and IV must be included.

The Virtual Environment configuration should be set-up as follows:

1. Setup a Windows 2012 R2 Server as a Domain Controller with the following parameters:

Domain Accounts

1. 10 - Domain user accounts

2. 1 - Domain administrator account Services enabled on the Domain Controller

1. DNS

2. DHCP with a Subnet of 10.0.0.0/24 providing dynamic leases to one of the windows 7 workstation.

3. Active Directory

4. Active Directory with LDAP integration Services that must be enabled/disabled within the domain by GPO:

1. Enable – SMB

2. Enable – RDP

3. Enable – NetBios

4. Enable – WinRM

5. Enable – Remote Registry

6. Enable – Firewall only allowing connections within the domain to utilize the above listed services.

7. Disable – Network Discovery

8. Disable – Windows Defender 2 - Windows 7 Service Pack 1 connected to the domain First Windows 7 Workstation

1. Added to the Domain

2. All GPO’s Applied

3. Set with Static IP Second Windows 7 Workstation

1. Added to the Domain

2. All GPO’s Applied

3. Dynamic IP from DHCP Server 1 – CentOS 6.0 Workstation connected to the domain with dynamic IP set.

The Training Task List (TTL) is as follows:

Task
Knowledge Level
Performance Level
A01: Incident Response
B
N/A
A02: USAF Cyber Weapon Systems
B
N/A
A03: Windows OS Baseline
B
2b
A03a: Windows command-line
B
2b
A03b: Sysinternals Autoruns and Autorunsc
B
2b
A03c: Sysinternals TCPView and TCPvcon
B
2b

File details come from the government source that posted it. Updated .