Thursday, February 6, 2025
HomeSoftware Engineering6 Classes Discovered from Internet hosting the President’s Cup Cybersecurity Competitors

6 Classes Discovered from Internet hosting the President’s Cup Cybersecurity Competitors


A robust cybersecurity protection is important to most public- or private-sector actions in america. In 2019, Government Order 13870 acknowledged that, “America’s cybersecurity workforce is a strategic asset that protects the American individuals, the homeland, and the American lifestyle.” One consequence of this govt order is an effort to foster cybersecurity training by means of competitions. These occasions permit individuals to sort out real-world cybersecurity issues in a timed, aggressive, protected setting by means of hands-on challenges that assess and construct cybersecurity abilities. Rivals join particular person or group tracks or each to strengthen their skills and be examined by offensive or defensive challenges. A cybersecurity competitors is a perfect setting for these professionals to dive into and discover lifelike eventualities.

The Division of Homeland Safety’s Cybersecurity & Infrastructure Safety Company (CISA) was tasked with holding a cybersecurity competitors for the federal cyber workforce. It selected to accomplice with the SEI to develop and run the President’s Cup Cybersecurity Competitors, a nationwide cyber competitors that identifies, acknowledges, and rewards the most effective cybersecurity expertise within the federal govt workforce.

In six years greater than 8,000 individuals have taken half within the President’s Cup. In that very same time span practically 4,000 help-desk tickets regarding questions with challenges/the platform/registration, and so on., have been created to help the President’s Cup. Whereas designing high-level challenges is crucial a part of a cybersecurity competitors, having a help group that may course of and resolve rivals’ issues in a well timed vogue is a vital a part of making a cybersecurity competitors profitable. On this submit we current classes realized from six years of internet hosting President’s Cup Cybersecurity Competitions together with the need of competitors help staffing.

Help Workforce Objective and Construction

Regardless that individuals are competing, they nonetheless often want the help of a help group. The aim of the help group is to assist rivals expertise a seamless occasion. The help group doesn’t provide hints to the people and groups after they get caught throughout a problem; it serves as an middleman between rivals and the competitors’s platform and problem engineers every time problem questions and/or platform points come up. Generally a technical subject with a problem or the competitors setting wants restore, whereas different instances a competitor seeks readability a few specific a part of the problem. The help group retains the wheels transferring.

Help Hours and Tiers

The primary resolution when planning help for a contest is deciding when to supply dwell help. Some competitions provide dwell help 24/7, whereas others provide dwell help for particular instances through the rounds. Both manner, it’s necessary to obviously talk the hours when rivals can and can’t anticipate dwell help.

The President’s Cup Cybersecurity Competitors is run by means of Gameboard, an open supply utility, the place customers entry the challenges and attain out to the help group by means of the Gameboard-hosted ticketing system. Earlier than tickets begin arriving, it’s a good suggestion to interrupt the help group into three tiers to greatest triage and resolve points.

  • Tier 1. Throughout the competitors, Tier 1 help employees are accountable for fielding preliminary help tickets, acknowledging motion is being taken and speaking with the rivals till the problem is resolved. The emphasis is to resolve assist requests as quickly as attainable since there are time constraints through the aggressive rounds. Some examples of Tier 1 points embrace registration questions, profile updates, and basic questions on guidelines.
  • Tier 2. Generally a problem should be escalated to builders for decision. Maybe a characteristic requires troubleshooting, or an engineer should decide if the problem is working accurately. These engineers kind the Tier 2 a part of the help group. Another examples of Tier 2 points embrace issues with grading, digital machines that fail to launch, or clarification questions on wording in problem documentation.
  • Tier 3. Tier-3 issues, similar to infrastructure outages or bugs, might be probably the most critical to deal with due to their potential severity. For instance, if digital machines for all challenges are immediately unable to start out, your complete competitors grinds to a halt till the issue is rectified. Subsequently, infrastructure consultants should be accessible or on name in case an pressing scenario emerges.

How do rivals attain help, and the way is an issue funneled to the proper tier for decision?

Help Workflow and Responses

Throughout the President’s Cup, customers submit help tickets by means of the Gameboard utility. The help interface mechanically captures the particular President’s Cup problem, the consumer’s PlayerID, and a help code that helps the help group pinpoint the problem. When the Tier 1 group receives the ticket, they triage the scenario both for decision or elevation to Tier 2. Both manner, the Tier 1 group communicates with the rivals that they’ve acquired their request and can preserve them knowledgeable of progress towards decision. It’s necessary to quickly talk with rivals and attempt to resolve most tickets inside quarter-hour because the rivals solely have a sure period of time to participate in every spherical.

Whereas inventory solutions to typical consumer questions can function a basic start line for support-team responses, it’s greatest to method every help ticket individually in order that customers know their particular query is getting addressed. The aim is to not reply questions in a rote vogue however to reply to every competitor’s scenario in a passable manner.

Weekend and after-hour responses current distinctive conditions. If rivals can take part throughout instances when dwell help received’t be staffed, the unavailability of help should be communicated clearly (customers can entry the President’s Cup website 24/7 to learn the competitors’s guidelines and FAQ part, nonetheless).

Adjudication Points

Some points are uncommon sufficient (e.g., a competitor discovers an surprising method to remedy a problem) or extreme sufficient (e.g., an infrastructure outage causes a contest delay) to require rapid or post-round adjudication.

Often a consumer’s help ticket reveals an unknown drawback or infrastructure subject. If, after investigation, directors decide that an issue with the problem or different competitors infrastructure was the trigger, they might award additional time within the participant’s session or factors for solutions that the participant discovered.

Further time is awarded to a competitor when an issue with a problem or competitors infrastructure prevented the competitor from making progress on a problem. The additional time is usually awarded in response to how a lot time directors consider the competitor misplaced as a result of error.

Awarding factors as a part of an adjudication is uncommon. Factors ought to solely be awarded if directors decide that gamers submitted a solution that must be thought of right however was graded as incorrect by the problem. This could occur in rare circumstances when a problem inadvertently has a number of right solutions that weren’t accounted for throughout problem design, QA, and grading.

The President’s Cup Gameboard reporting options present useful information to the help group. Help studies summarize details about the help tickets dealt with through the competitors. They are often filtered for a selected spherical, a selected problem and/or different parameters similar to labels. Labels are tags added to particular person tickets that permit the help group to simply determine, classify and search all tickets. Tickets might be labeled by spherical, subject (e.g., VM-outage), or any parameter the help group decides to make use of. As soon as tickets are tagged with labels, it’s straightforward to run studies. Reviews permit the help group to spotlight competitors drawback areas or points that should be addressed earlier than an ensuing spherical. Reviews may function a place to begin for the planning of future competitions.

Six Classes Discovered in Supporting Cybersecurity Competitions

  • Perceive Your Limits. Contemplate your plan for help when providing a cybersecurity competitors. If 24/7 help will probably be provided, don’t promote that to potential rivals and assume you may fill the help schedule later. It’s more durable than you assume to safe staffing for each time slot, particularly in a single day. Remember that should you observe a tiered-support technique, at the least two individuals should be scheduled for each shift. Be sure you have sufficient group members who possess the talents and availability to deal with help assignments.
  • Analyze Information. Use your help website’s reporting options throughout and after a contest to take a look at information. With the President’s Cup, CISA and the SEI use Gameboard’s in depth, built-in reporting options to glean key details about competitors challenges and logistics (similar to growing help employees throughout sure hours or realizing help isn’t wanted as a lot as initially thought throughout in a single day hours). Utilizing reporting information may help decide a contest’s staffing wants.
  • Guarantee a powerful challenge-review course of. A robust problem testing-and-review course of as highlighted within the Designing Nice Challenges for Cybersecurity Competitors weblog submit is integral to a profitable competitors. The aim right here is to determine and repair any problem points earlier than the competitors even begins. Consider this course of as providing help earlier than help is even vital. Extra challenge-testing earlier than a contest ends in
    • Fewer challenge-specific help tickets through the competitors,
    • happier individuals,
    • and a extra passable buyer expertise for the competitors proprietor.

One other space the place a contest website’s reporting capabilities can present helpful data is problem growth. Examine what challenges drew probably the most help tickets. Are there frequent threads to a number of the issues highlighted within the tickets? For instance, if Safety Onion takes a very long time to start out when used within the problem setting, it is likely to be useful to future rivals to spotlight that actuality within the problem documentation in order that they know the challenges that make the most of Safety Onion are working as anticipated.

  • Keep an energetic backup staffing plan. Have backup plans in case somebody in your help group is unable to deal with their shift. Whether or not it’s a proper backup schedule or an on-call listing, have a plan helpful for when life interferes along with your competitors.
  • Have a simple communication methodology that your help group can use. In immediately’s work setting it’s not going your help group will bodily be in the identical room throughout aggressive rounds (particularly after enterprise hours and on weekends). Collaborative instruments similar to Mattermost and Microsoft Groups are perfect for permitting real-time communication amongst your group members. Video-communication platforms like Zoom are additionally helpful for emergency conditions that require impromptu conferences (similar to a sudden drawback along with your competitors’s cloud supplier).
  • Maintain a operating support-team classes realized listing all through the competitors that will help you evolve your help course of for upcoming rounds and future competitions. Strategy any feedback or inside solutions about your help methodology by means of the eyes of your rivals and prospects. Maintain the next questions in thoughts:
    • How can we enhance our competitors to raised fulfill our buyer’s wants?
    • How can we make our help course of higher for rivals?

It’s additionally a good suggestion to maintain classes realized monitoring in thoughts not simply to your help course of however for all points of your cybersecurity competitors.

Help Audiences – Who Advantages?

These help practices are the results of the SEI’s expertise working with CISA’s President’s Cup Cybersecurity Competitors. Help technique works in tandem with problem growth when planning a cybersecurity competitors, so support-team issues are usually not incidental to attaining the strategic aim of growing and strengthening America’s cybersecurity personnel. A help group that’s capable of deal with points that come up throughout a contest whereas serving as concierge to rivals satisfies three audiences: competitors individuals, competitors stakeholders, and people who need america to have a superior cybersecurity workforce.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments