-2.9 C
New York
Thursday, January 30, 2025

6 Classes Discovered from Internet hosting the President’s Cup Cybersecurity Competitors


A robust cybersecurity protection is significant to most public- or private-sector actions in the US. In 2019, Government Order 13870 acknowledged that, “America’s cybersecurity workforce is a strategic asset that protects the American individuals, the homeland, and the American lifestyle.” One consequence of this govt order is an effort to foster cybersecurity training by means of competitions. These occasions enable members to sort out real-world cybersecurity issues in a timed, aggressive, protected surroundings by means of hands-on challenges that assess and construct cybersecurity expertise. Opponents join particular person or staff tracks or each to strengthen their skills and be examined by offensive or defensive challenges. A cybersecurity competitors is a perfect surroundings for these professionals to dive into and discover sensible eventualities.

The Division of Homeland Safety’s Cybersecurity & Infrastructure Safety Company (CISA) was tasked with holding a cybersecurity competitors for the federal cyber workforce. It selected to associate with the SEI to develop and run the President’s Cup Cybersecurity Competitors, a nationwide cyber competitors that identifies, acknowledges, and rewards the most effective cybersecurity expertise within the federal govt workforce.

In six years greater than 8,000 individuals have taken half within the President’s Cup. In that very same time span practically 4,000 help-desk tickets regarding questions with challenges/the platform/registration, and so forth., have been created to assist the President’s Cup. Whereas designing high-level challenges is an important a part of a cybersecurity competitors, having a assist staff that may course of and resolve opponents’ considerations in a well timed vogue is a crucial a part of making a cybersecurity competitors profitable. On this submit we current classes realized from six years of internet hosting President’s Cup Cybersecurity Competitions together with the need of competitors assist staffing.

Help Workforce Function and Construction

Though members are competing, they nonetheless often want the help of a assist staff. The objective of the assist staff is to assist opponents expertise a seamless occasion. The assist staff doesn’t supply hints to the people and groups after they get caught throughout a problem; it serves as an middleman between opponents and the competitors’s platform and problem engineers at any time when problem questions and/or platform points come up. Typically a technical concern with a problem or the competitors surroundings wants restore, whereas different instances a competitor seeks readability a couple of explicit a part of the problem. The assist staff retains the wheels shifting.

Help Hours and Tiers

The primary resolution when planning assist for a contest is deciding when to supply dwell assist. Some competitions supply dwell assist 24/7, whereas others supply dwell assist for particular instances in the course of the rounds. Both method, it’s vital to obviously talk the hours when opponents can and can’t anticipate dwell help.

The President’s Cup Cybersecurity Competitors is run by means of Gameboard, an open supply software, the place customers entry the challenges and attain out to the assist staff by means of the Gameboard-hosted ticketing system. Earlier than tickets begin arriving, it’s a good suggestion to interrupt the assist staff into three tiers to finest triage and resolve points.

  • Tier 1. Through the competitors, Tier 1 assist employees are liable for fielding preliminary assist tickets, acknowledging motion is being taken and speaking with the opponents till the difficulty is resolved. The emphasis is to resolve assist requests as quickly as doable since there are time constraints in the course of the aggressive rounds. Some examples of Tier 1 points embody registration questions, profile updates, and common questions on guidelines.
  • Tier 2. Typically a problem should be escalated to builders for decision. Maybe a function requires troubleshooting, or an engineer should decide if the problem is working appropriately. These engineers type the Tier 2 a part of the assist staff. Another examples of Tier 2 points embody issues with grading, digital machines that fail to launch, or clarification questions on wording in problem documentation.
  • Tier 3. Tier-3 issues, equivalent to infrastructure outages or bugs, could be essentially the most severe to deal with due to their potential severity. For instance, if digital machines for all challenges are all of the sudden unable to begin, the complete competitors grinds to a halt till the issue is rectified. Subsequently, infrastructure specialists should be obtainable or on name in case an pressing state of affairs emerges.

How do opponents attain assist, and the way is an issue funneled to the proper tier for decision?

Help Workflow and Responses

Through the President’s Cup, customers submit assist tickets by means of the Gameboard software. The assist interface mechanically captures the particular President’s Cup problem, the consumer’s PlayerID, and a assist code that helps the assist staff pinpoint the difficulty. When the Tier 1 staff receives the ticket, they triage the state of affairs both for decision or elevation to Tier 2. Both method, the Tier 1 group communicates with the opponents that they’ve obtained their request and can maintain them knowledgeable of progress towards decision. It’s vital to quickly talk with opponents and attempt to resolve most tickets inside quarter-hour for the reason that opponents solely have a sure period of time to participate in every spherical.

Whereas inventory solutions to typical consumer questions can function a common start line for support-team responses, it’s finest to strategy every assist ticket individually in order that customers know their particular query is getting addressed. The objective is to not reply questions in a rote vogue however to answer every competitor’s state of affairs in a passable method.

Weekend and after-hour responses current distinctive conditions. If opponents can take part throughout instances when dwell assist received’t be staffed, the unavailability of assist should be communicated clearly (customers can entry the President’s Cup web site 24/7 to learn the competitors’s guidelines and FAQ part, nonetheless).

Adjudication Points

Some points are uncommon sufficient (e.g., a competitor discovers an sudden solution to remedy a problem) or extreme sufficient (e.g., an infrastructure outage causes a contest delay) to require fast or post-round adjudication.

Sometimes a consumer’s assist ticket reveals an unknown downside or infrastructure concern. If, after investigation, directors decide that an issue with the problem or different competitors infrastructure was the trigger, they might award additional time within the participant’s session or factors for solutions that the participant discovered.

Further time is awarded to a competitor when an issue with a problem or competitors infrastructure prevented the competitor from making progress on a problem. The additional time is usually awarded in keeping with how a lot time directors imagine the competitor misplaced because of the error.

Awarding factors as a part of an adjudication is uncommon. Factors ought to solely be awarded if directors decide that gamers submitted a solution that needs to be thought of appropriate however was graded as incorrect by the problem. This will occur in rare circumstances when a problem inadvertently has a number of appropriate solutions that weren’t accounted for throughout problem design, QA, and grading.

The President’s Cup Gameboard reporting options present useful knowledge to the assist staff. Help studies summarize details about the assist tickets dealt with in the course of the competitors. They are often filtered for a selected spherical, a selected problem and/or different parameters equivalent to labels. Labels are tags added to particular person tickets that enable the assist staff to simply determine, classify and search all tickets. Tickets could be labeled by spherical, concern (e.g., VM-outage), or any parameter the assist staff decides to make use of. As soon as tickets are tagged with labels, it’s straightforward to run studies. Studies enable the assist staff to focus on competitors downside areas or points that should be addressed earlier than an ensuing spherical. Studies can even function a place to begin for the planning of future competitions.

Six Classes Discovered in Supporting Cybersecurity Competitions

  • Perceive Your Limits. Think about your plan for assist when providing a cybersecurity competitors. If 24/7 assist shall be provided, don’t promote that to potential opponents and assume you possibly can fill the assist schedule later. It’s tougher than you suppose to safe staffing for each time slot, particularly in a single day. Remember that for those who observe a tiered-support technique, not less than two individuals should be scheduled for each shift. Ensure you have sufficient staff members who possess the talents and availability to deal with assist assignments.
  • Analyze Information. Use your assist web site’s reporting options throughout and after a contest to take a look at knowledge. With the President’s Cup, CISA and the SEI use Gameboard’s intensive, built-in reporting options to glean key details about competitors challenges and logistics (equivalent to growing assist employees throughout sure hours or realizing assist isn’t wanted as a lot as initially thought throughout in a single day hours). Utilizing reporting knowledge will help decide a contest’s staffing wants.
  • Guarantee a robust challenge-review course of. A robust problem testing-and-review course of as highlighted within the Designing Nice Challenges for Cybersecurity Competitors weblog submit is integral to a profitable competitors. The objective right here is to determine and repair any problem points earlier than the competitors even begins. Consider this course of as providing assist earlier than assist is even vital. Extra challenge-testing earlier than a contest ends in
    • Fewer challenge-specific assist tickets in the course of the competitors,
    • happier members,
    • and a extra passable buyer expertise for the competitors proprietor.

One other space the place a contest web site’s reporting capabilities can present helpful info is problem improvement. Examine what challenges drew essentially the most assist tickets. Are there frequent threads to among the issues highlighted within the tickets? For instance, if Safety Onion takes a very long time to begin when used within the problem surroundings, it may be useful to future opponents to focus on that actuality within the problem documentation in order that they know the challenges that make the most of Safety Onion are working as anticipated.

  • Keep an energetic backup staffing plan. Have backup plans in case somebody in your assist staff is unable to deal with their shift. Whether or not it’s a proper backup schedule or an on-call listing, have a plan helpful for when life interferes along with your competitors.
  • Have a simple communication methodology that your assist staff can use. In right now’s work surroundings it’s not going your assist staff will bodily be in the identical room throughout aggressive rounds (particularly after enterprise hours and on weekends). Collaborative instruments equivalent to Mattermost and Microsoft Groups are perfect for permitting real-time communication amongst your staff members. Video-communication platforms like Zoom are additionally helpful for emergency conditions that require impromptu conferences (equivalent to a sudden downside along with your competitors’s cloud supplier).
  • Hold a working support-team classes realized listing all through the competitors that will help you evolve your assist course of for upcoming rounds and future competitions. Strategy any feedback or inside ideas about your assist methodology by means of the eyes of your opponents and clients. Hold the next questions in thoughts:
    • How can we enhance our competitors to raised fulfill our buyer’s wants?
    • How can we make our assist course of higher for opponents?

It’s additionally a good suggestion to maintain classes realized monitoring in thoughts not simply on your assist course of however for all facets of your cybersecurity competitors.

Help Audiences – Who Advantages?

These assist practices are the results of the SEI’s expertise working with CISA’s President’s Cup Cybersecurity Competitors. Help technique works in tandem with problem improvement when planning a cybersecurity competitors, so support-team concerns usually are not incidental to attaining the strategic objective of growing and strengthening America’s cybersecurity personnel. A assist staff that’s capable of deal with points that come up throughout a contest whereas serving as concierge to opponents satisfies three audiences: competitors members, competitors stakeholders, and people who need the US to have a superior cybersecurity workforce.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles