Questions for Supporting U.S. Cybersecurity Capacity-Building for ASEAN Countries NOFO (1).docx

DOCX document 28 KB Posted

Attached to
Supporting U.S. Cybersecurity Capacity Building for ASEAN Countries Federal grant opportunity
Opportunity number
ESF-CYBASEAN-FY20-01
Issued by
Department of State US Embassy Singapore

About this file

Q&A Document

View the file

Other files for this federal grant opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Questions for Supporting U.S. Cybersecurity Capacity-Building for ASEAN Countries NOFO

1. In Section A1 of the NOFO, you provide examples of past successful efforts, including the existing U.S.-Singapore CTAP which involves “comprehensive and in-depth training in establishing and maintaining a successful Community Emergency Response Team (CERT) addressing such issues as cyber threat landscapes, technical requirements of CERTs, and available tools for national and regional CERTs.” What are the functions/operational capabilities of CERT that have been assumed for this scope of work?

A CERT has a technical capacity to track and respond to cyber threats and computer network security incidents.

1. Does the scope of work involve training people to work at CERTs that already exist, with processes and procedures already in place, or rather we train people to set up the CERT and create those processes and procedures, thus establishing the CERT?

The applicant is free to design the program however they see fit. A successful program will likely have the ability to work with several levels of capability across ASEAN member states.

1. In Section A2 (“Program Goals”) of the NOFO, Objective 1.2 states, “Identify and recruit eligible individuals and organizations from ASEAN member states for the technical assistance workshops in conjunction with CSA and U.S. missions in the region, including logistical and organizational support.” Does this intend to suggest we would assist in hiring individuals to work at the CERTs, or instead that we would develop an awareness campaign that educates organizations and individuals based in the area on their local CERT capabilities and teach them how best to take advantage of the relationship?

Applicants will be identifying individuals and organizations to attend the technical assistance workshops.

1. Additionally, Objective 1.3 sets the expectation that we will “Deliver at least three trainings per year for an audience of 25-40 participants per training.” Is this understood to mean that the initial 25-40 participants, irrespective of which countries they’re from, will be trainees throughout the year and receive trainings at least thrice a year, or rather that for each of the trainings, the participants will be different?

The participants should be different per each iteration of the training to expand the reach of the program to the maximum number of participants.

1. Are there eligibility requirements for those selected to be training participants? For instance, will we be provided information regarding possible participants’ technical skillset?

The applicant organization should determine the eligibility requirements based on the technical training curricula each proposal will develop, working in close coordination with Embassy Singapore staff.

1. The NOFO puts forth a general goal of funding an initiative that effectively supports ongoing cybersecurity capacity-building efforts within ASEAN nations; however, it seems less clear on the overall goal of the trainings. What should be the central goal of the trainings, and what general areas should the developed curricula try to focus on to achieve the expected results?

The trainings should be specific to the goals and expected results the applicant hopes to achieve; a successful applicant will design/expand the trainings in coordination with Embassy Singapore to ensure the curricula and goals are in line with overall goals for the region.

1. Is there a specific range or threshold on the number of ASEAN countries expected to target and include in the proposal?

The applicant is free to choose whatever ESF-eligible ASEAN member countries they wish, but should target as many as possible rather than focus on any one country.

1. Can we have some further details about the previous US Embassy in Singapore funded programs, i.e. Cybersecurity Technical Assistance Program (CTAP), Third-Country Training Program (TCTP) and the ASEAN-Singapore Cybersecurity Center of Excellence (ASCCE)? We would like to know:

· Which standards/frameworks were used in the CTAP and TCTP? Or the programs used their own frameworks modified from the international ones?

Generally, our programs are structured under their own frameworks. A safe guideline to stay within the contours of U.S. policy is the APEC cross-border privacy rules (CPBR). Also, please review the latest Executive Order from the White House on Cybersecurity: Executive Order on Improving the Nation's Cybersecurity | The White House

· Can we have some bullet points of the outline of the training courses of CTAP and TCTP?

Please use the guidance in the above question to design your program curricula.

· Can you share any (evaluation) reports of CTAP, TCTP and ASCCE programs?

These reports are not available to the public.

1. Re objective 1.1 - 'development of technical and policy trainings' - please can you clarify your expectation, to what extent, for “technical” and “policy”? Can you give some examples on these so that we can be on the same page (because those words are quite broad and general)? For instance, technical training topics could be “access management technologies” or “secure software development lifecycle or secure coding” or hands-on vulnerability assessment training or something like that. Policy training could be “cyber risk assessment methodology” or just “information security policy”.

The applicant should design the trainings in such a manner that best achieves the goals they desire for the program.

1. What are administrative documents do our partners in the consortium for this program need to provide?

Please ensure they are aware of the program and their proposed participation. In addition, if they are intended to receive a sub-grant or otherwise be allotted grant funds from you as part of your proposal, they should also have a budget and budget narrative for their portion.

1. Can we reconfirm that this program targets officials only, not individuals from the private sector?

The intended audience is civilian government officials.

1. Can we confirm the 8 countries in the program are at our own choice? Do you have any preference of which countries should be included, apart from Singapore?

The Program is primarily focused on ASEAN members, although Myanmar may present challenges for U.S. engagement/support in the coming months.

1. There are some abbreviation in the NOFO that we don't understand. Please can you advise what 'PS.4.2-1' and 'PS.4.4' in the tables in section 'Performance indications' on page 6 of the NOFO? In particular, these lines are:

PS.4.2-1: Person hours of training completed and supported by the USG in a host country on intellectual property theft and/or cyber security.

PS.4.4: Number of individuals who have received USG supported Cybersecurity (or CERT) training These numbers refer to a coding system of the indicators used within the Department of State and USAID.

1. Is it possible to submit a proposal that only addresses Part 2 (i.e., “collaborate closely with the United States Department of State to analyze all areas of collaboration between the United States and Singapore in cybersecurity objectives and provide strategies for longer-term incorporation and partnership-strengthening to design an expanded United States-Singapore long-term cybersecurity training and support strategy that is sustainable and scalable for partner countries in Southeast Asia and to support the ASCCE”) without implementing the logistical and event support for holistic and rigorous technical programs (Part 1).

Unfortunately, your application must address the whole NOFO, and will be considered ineligible if it does not address both parts.

1. What are the ESF-eligible ASEAN countries?

· Cambodia

· Indonesia

· Laos

· Malaysia

· Myanmar (May require further review)

· The Philippines

· Thailand

· Vietnam

File details come from the government source that posted it. Updated .