Attach 28_Compare Doc.pdf

PDF 749 KB Posted

Attached to
National Cyber Range Complex Event Planning, Operations and Support Federal contract opportunity
Solicitation number
W900KK-20-R-0011
Issued by
Department of the Army Materiel Command Contracting Command Orlando Contracting Center

About this file

This document provides a sample training event scenario and related federal contract opportunity. The sample scenario outlines a proposed one-week cybersecurity training event for Army National Guard blue teams, focusing on incident response, digital forensics, vulnerability analysis, and system hardening. The event objectives, network topology, and red team techniques are to be detailed in an event support plan. The related federal contract opportunity is solicitation number W900KK-20-R-0011 for National Cyber Range Complex event planning, operations, and support services. Key dates include a February 2020 solicitation release, March 2020 question submission and pre-proposal conference, and April 2020 proposal submission with contract award planned for December 2020. The Army Materiel Command Contracting Command Orlando Contracting Center is the issuing agency.

View the file

Other files for this federal contract opportunity

Other files attached to National Cyber Range Complex Event Planning, Operations and Support, newest first.
File Type Posted
W900KK-20-R-0011_NCRC_EPOS_Conformed_at_Amendment_0014_20201218.pdf PDF
Amendment 0014_Deltas From_Amendment 0013.pdf PDF
W900KK-20-R-0011_Amendment 0012_Executed.pdf PDF
W900KK-20-R-0011_Amendment 0011_Executed.pdf PDF
W900KK-20-R-0011_Amendment 0010_Executed.pdf PDF
W900KK20R0011_Attach_03_NCRC_EPOS_IDIQ_DSL_ITSM_CHS_20200410r1.XLSX XLSX spreadsheet
W900KK20R0011_Attach_37_NCRC_EPOS_Lot_1_Proposal_Cost_Price_Workbook_20200410.xlsx XLSX spreadsheet
Exhibit_B_20200410.pdf PDF
W900KK20R0011_Attach_30_NCRC_EPOS_Event_Support_Plan_Outline_20200410.pdf PDF
W900KK20R0011_Attach_35_NCRC_EPOS_Past_Performance_Contract_Description_20200410.docx DOCX document
W900KK-20-R-0011_Amendment 0007_Executed.pdf PDF
W900KK20R0011_Attach_16_NCRC_Sample_Range_Event_Schedule_20200330.pdf PDF
Amendment 0007_Deltas From_Amendment 0006.pdf PDF
Attach 18_Compare Doc.pdf PDF
W900KK20R0011_Attach_37_NCRC_EPOS_Lot_1_Proposal_Cost_Price_Workbook_20200327.xlsx XLSX spreadsheet
Attach 21_Compare Doc.pdf PDF
Amendment 0006_Deltas From_Amendment 0005.pdf PDF
W900KK20R0011_Exhibit_C_CDRLs_20200327.pdf PDF
W900KK20R0011_Exhibit_B_CDRLs_20200327.pdf PDF
W900KK20R0011_Attach_08_NITC_QASP_20200327.pdf PDF
W900KK-20-R-0011_Amendment 0006_Executed.pdf PDF
W900KK20R0011_Attach_02_NCRC_EPOS_IDIQ_QASP_20200327.pdf PDF
Attach 32_Compare Doc.pdf PDF
W900KK20R0011_Attach_11_NITC_DD254_andContinuation_Sheet_20200327.pdf PDF
Attach 15_Compare Doc.pdf PDF
W900KK20R0011_Attach_35_NCRC_EPOS_Past_Performance_Contract_Description_20200327.docx DOCX document
Attach 2_Compare Doc.pdf PDF
Amendment 0005_Deltas From_Amendment 0004.pdf PDF
W900KK-20-R-0011_Amendment 0004_Executed.pdf PDF
W900KK-20-R-0011_NCRC_EPOS_Conformed_at_Amendment_0003_20200312.pdf PDF
[Non-DoD Source] NCRC EPOS W900KK-20-R-0011 Document request.pdf PDF
W900KK20R0011_Attach_29_NCRC_EPOS_Closed_Environment_Challenges_Scenario.docx DOCX document
W900KK20R0011_Attach_06_NITC_Model_Task_Order.docx DOCX document
W900KK20R0011_Attach_33_NCRC_EPOS_Past_Performance_Questionnaire.docx DOCX document
W900KK20R0011_Attach_08_NITC_QASP.docx DOCX document
W900KK20R0011_Exhibit_A_CDRLs.pdf PDF
W900KK20R0011_Attach_11_NITC_DD254_andContinuation_Sheet.pdf PDF
W900KK20R0011_Attach_34_NCRC_EPOS_Past_Performance_Questionnaire_Cover_Letter.docx DOCX document
W900KK20R0011_Attach_32_NCRC_EPOS_List_of_Past_Performance_Contracts.docx DOCX document
W900KK20R0011_Attach_18_Sample_ITSM_Model_Task_Order.docx DOCX document
W900KK20R0011_Exhibit_C_CDRLs.pdf PDF
W900KK20R0011_Attach_16_NCRC_Sample_Range_Event_Schedule.docx DOCX document
W900KK20R0011_Attach_37_NCRC_EPOS_Lot_1_Proposal_Cost_Price_Workbook_20200220 (002).xlsx XLSX spreadsheet
W900KK20R0011_Attach_39_NCRC_EPOS_DCMA_Form_1620_Guaranty_Agrmnt_for_Corp_Guarantor.docx DOCX document
W900KK20R0011_Attach_21_ITSM_QASP.docx DOCX document
W900KK20R0011_Attach_35_NCRC_EPOS_Past_Performance_Contract_Description.docx DOCX document
W900KK20R0011_Attach_05_NCRC_EPOS_Ordering_Procedures.docx DOCX document
W900KK20R0011_Attach_02_NCRC_EPOS_IDIQ_QASP.docx DOCX document
W900KK20R0011_Attach_27_NCRC_EPOS_Cyber_T+E_Event_Scenario.docx DOCX document
Solicitation W900KK-20-R-0011 NCRC EPOS.pdf PDF
Show all 50

National Cyber Range Complex Event Planning, Operations and Support has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 28 Solicitation #: W900KK-20-R-0011 Rev Date: 7 Feb27 Mar 2020

Sample Training Event Scenario Page 1 of 4

National Cyber Range Complex Event Planning, Operations, and Maintenance

(NCRC EPOS)

Sample Training Event Scenario

I. Event Overview The US Army National Guard (ARNG) contacts the Test Resource Management Center (TRMC) and requests support for an upcoming, intermediate-sized,1, one week cybersecurity training event. The training event will focus on “Blue Team” operations training, which shall include assessing the following skill areas:

Cyber Incident Response Digital Forensic Analysis & Basic Malware Analysis System and Network Vulnerability Analysis

System and Network Hardening/Vulnerability Remediation

The prompt that will be briefed to the training participants on Day 1 of the event reads as follows:

“ARNG Blue Teams are dispatched in response to a possible cyber intrusion at a major maritime port in the Continental United States. The Blue Teams’ mission is to augment the port’s Network Security and Information Technology (IT) teams to assist in the intrusion incident response and investigation and to remediate any vulnerabilities discovered during the investigation.”

ARNG will supply “White Team” personnel to assess the Blue Teams’ performance against their training objectives. The NCRC shall supply “Red Team” personnel that shall execute offensive cyber operations at multiple levels of sophistication (i.e. Low level/”Script Kiddie” and Nation-State level/Advanced Persistent Threat). Further, the NCRC shall supply the entirety of the training event’s network topology to include virtualized workstations, servers, and routers, as well as physical Industrial Control Systems (ICS)/ Supervisory Control and Data Acquisition (SCADA) devices that shall be made accessible to the virtualized hosts.

II. Event Objectives ARNG has identified the following training objectives for each of the given Blue Team skill areas:

Cyber Incident Response

1. Perform volatile memory capture and hard drive imaging from selected endpoint systems.

1 The reference to intermediate-sized event here is the same as the medium sized training event described in attachment

Sample Training Event Scenario Page 2 of 4

2. Deploy a virtual network security device (e.g. virtual machine running Bro, SNORT, Security Onion) to capture and analyze network traffic.

Digital Forensic Analysis & Basic Malware Analysis

1. Analyze SYSLOG files from Linux servers.

2. Analyze Event Logs and Registry entries from Windows servers and workstations.

3. Conduct volatile memory forensics on the captured volatile memory dumps.

System and Network Vulnerability Analysis

1. Conduct network port scans from within the enterprise network.

2. Conduct system vulnerability scans from within the enterprise network.

System and Network Hardening/Vulnerability Remediation

1. Manipulate network and host firewall rules to block suspicious traffic.

2. Disable unnecessary services and user accounts across the enterprise.

3. Restrict access control for critical systems to specific users (i.e. audit and enforce least privilege).

At a minimum, the maritime port’s network shall comprise a Corporate Demilitarized Zone (DMZ), an Enterprise Server Local Area Network (LAN), a user/workstation LAN, a Network & Security Administration (ADMIN) LAN, and an ICS Network (controls the ashore systems responsible for fueling ships).

The maritime port’s network services shall include— but not be limited to— the following:

Domain Name System (DNS) (external and internal resolution) External corporate web server connecting to a sales/shipping database Internal Human Resources Department web server connecting to a personnel database Virtual Private Network (VPN) for remote and teleworking users Microsoft Active Directory Microsoft Exchange Dynamic Host Configuration Protocol (DHCP)

File and Print Services

The overall event network topology shall include a high-fidelity, simulated Internet “gray space” to which the maritime port’s network is connected via (virtualized) commercial perimeter router. Further, the overall event network topology shall include a “red space” network from which the Red Team will operate. The red space network shall be connected to the Internet gray space in a realistic manner, and the maritime port’s external network interface shall be reachable from the red space.

Sample Training Event Scenario Page 3 of 4

The ARNG, acting as the event sponsor, has provided the following notional architecture diagram:

Finally, the network shall appear to the training participants as though it is currently being used by the maritime port’s personnel, as normal business operations have not ceased during the investigation.

III. Training Event Planning Based on the aforementioned information, address the following items:

1. Describe the analysis methodology and approach that will be applied to scope, plan, design and execute the training environment.

2. Develop an Event Support Plan using Attachment 30 (Event Support Plan template) that includes, but is not limited to:

Specification of the event objectives, A detailed network topology suitable for design of the event environment, Range instrumentation details relevant to the event objectives.

3. The Event Support Plan shall include the offensive cyber operations techniques the Red Team will apply to allow the White Team to evaluate Blue Team performance.

Sample Training Event Scenario Page 4 of 4

4. Describe the post-event activities that will be executed at the conclusion of the event execution.

5. Describe any customized content capabilities (e.g. traffic generation, web sites, Tactic, Techniques, and Procedures [TTP’s] etc.) required to conduct this event in a closed-loop, cyber range environment.

6. Describe how the capabilities developed for the environment will be managed following completion of the event.

File details come from the government source that posted it. Updated .