DHS FEMA EMI Cyber Virtual Tabletop Exercise Series Course: V-0001 – Virtual Tabletop Exercise Series (VTTX) –Cyber Focus – October 30, 31 & November 1 2018 & National Cyber Security Awareness Month Toolkit
https://www.dhs.gov/publication/ncsam-resources
Course: V-0001 – Virtual Tabletop Exercise Series (VTTX) –
Cyber Focus
Exercise Date & Location: October 30, 31 & November 1 2018. Virtual Exercise – Multiple Locations
(Note: Three separate offerings to accommodate as many site applicants as possible.)
Exercise Length: 4 Hours. Start time is 12:00 P.M. Eastern Standard Time (EST) and end time is 4:00 P.M. EST.
Exercise Description:
This VTTX is designed for organizations interested in raising awareness of cyber risk management, cyber-related planning, and other issues related to cyber incident prevention, protection, and response. The scenario will focus on increasingly complex and severe cyber threats, beginning with general information on a potential security risk and culminating with the containment, eradication, and recovery from a cyber-incident. The complexity of this exercise will largely depend on your organization’s choice of recommended discussion questions (beginner, intermediate, advanced), based on your audience and general level of cybersecurity preparedness experience.
Scenarios threat vectors may consist of one or several of the following:
• Distributed Denial of Service (DDoS)
• PII breach/data exfiltration
• Wiper Malware
• Phishing/spear phishing
• User error
• Website defacement
Exercise Goals:
This virtual exercise will enable the participants to exercise their knowledge, skills, and abilities needed to effectively prevent, protect, and respond to cyber incidents of varying complexities. Overall objectives include:
1.) Prepare participants for a cyber-based event affecting their organization or community.
2.) Assess cybersecurity integration into an organization’s all-hazards preparedness.
3.) Enable participants to better coordinate their response operations with counterparts from Federal, state, local, tribal and territorial governments; private sector organizations; and non-governmental agencies.
4.) Examine cybersecurity incident information sharing, escalation criteria, and related courses of action.
5.) Provide a virtual, experiential education environment to increase cybersecurity awareness.
Target Audience:
It is STRONGLY RECOMMENDED that Cyber VTTX participating organizations include all of the following disciplines: Emergency Management; Information Technology; Public Safety; Legal; Communications & Other government or private sector personnel involved in cyber incident response, as appropriate.
Exercise Design:
This VTTX is designed to engage the participants in a no-fault hazard-specific exercise discussion. Facilitation will occur via VTC from the EMI campus and will be complemented by a dedicated local agency facilitator at each VTC site.
To Apply:
Locations interested in participating in the VTTX series should submit an email request to participate in the exercise to Doug Kahn at douglas.kahn@fema.dhs.gov, phone (301) 447-7645, with the preferred date of participation. Your email is your program application. When applying, please provide a central point of contact from your organization to work all VTTX issues. Each location will receive a notice from EMI and will be provided with relevant logistical information and exercise materials to set up and facilitate the exercise locally.
Participation Requirements:
The VTTX will be limited to approximately 10-15 locations per broadcast. Participating locations must have an appropriate site equipped with VTC capability (this is not an Adobe Connect® session) that can access the Federal Emergency Management Agency (FEMA) VTC site (connection information will be provided by EMI). Participating locations will be responsible for local exercise logistics, and should designate an exercise coordinator to implement the logistical requirements for the exercise. In addition, the location must provide a person capable of facilitating the on-site portion of the exercise. Electronic copies of the related exercise materials (Exercise and Coordination Facilitation Guide, Situation Manual, agenda, etc.) will be provided in advance by EMI.
How do I obtain my FEMA SID number?
Step 1: To register, go to https://cdp.dhs.gov/femasid
Step 2: Click on the “Register for a FEMA SID” button on the screen.
Step 3: Follow the instructions and provide the necessary information to create your account.
Step 4: You will receive an email with your SID number. You should save this number in a secure location.
DHS FEMA EMI Cyber Virtual Tabletop Exercise Series Course: V-0001 – Virtual Tabletop Exercise Series (VTTX) –Cyber Focus – October 30, 31 & November 1, 2018, & National Cyber Security Awareness Month Toolkit