Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cybersecurity & Infrastructure Security Agency
America's Cyber Defense Agency

Search

 
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help Locally
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
    Work @ CISA
  • About
    Culture
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Contact Us
    Site Links
    Reporting Employee and Contractor Misconduct
    CISA GitHub
Report a Cyber Issue
America's Cyber Defense Agency
Breadcrumb
  1. Home
  2. Resources & Tools
  3. Programs
Share:

Resources & Tools

  • All Resources & Tools
  • Services
  • Programs
  • Resources
  • Training
  • Groups

Continuous Diagnostics and Mitigation (CDM) Training

Cyber city

Welcome to the Continuous Diagnostics and Mitigation (CDM) Training page. Here you will discover numerous CDM training resources available in multiple formats and forms of media. These options are meant to enrich your learning experience and help you gain further awareness, understanding, and overall knowledge of the CDM Program. The delivery methods we offer include In-person, On-demand, Virtual In-person, Micro-learns, and Webinars.

Sign up! Receive training opportunity notices and learn more about our online, interactive, self-paced training options, webinars, and micro-learns. Email CyberInsights@cisa.dhs.gov for registration information.

Audience: Those who monitor, manage, and oversee information systems controls, such as Information System Security Officers (ISSO), Systems Administrators, CDM Points of Contact (POC), Information Systems Security Managers (ISSM), and others who report measurements and/or metrics.

People at a computer

Register Now

Visit the Cybersecurity Training Event Catalog to register for an event. CDM Dashboard training is geared toward the Federal Civilian Executive Branch (FCEB) agencies; attendance will be restricted to attendees from these agencies.

Register

CDM Dashboard Cyber Range Training

CISA provides Continuous Diagnostics and Mitigation (CDM) dashboard cyber range training within a virtual environment, which provides students a simulated version of the ES-5 CDM Dashboard currently in production at participating federal agencies. Students will have the opportunity to complete hands-on lab activities with knowledge check questions at the conclusion of each lab.

Training Topics:

CDM CDM111: Analyzing Cyber Risks with the CDM Agency Dashboard

A two-day in-person course that explores the features of the current CDM Agency Dashboard version ES-5 such as Data Quality Reporting, Security Technical Implementation Guide (STIG) Reference Data, Federal Information Security Modernization Act (FISMA) Metrics, Summary Reporting, and other capabilities.

The hands-on lab activities in the current CDM Agency Dashboard version ES-5 include identifying the top network risks using CVEs; targeting legacy software and identifying unmanaged devices; prioritizing mitigation activities using the Agency Wide Adaptive Risk Enumeration (AWARE) 1.5 supplemental scoring algorithm; monitoring users’ Identity and Access Management (IdAM) capability status; creating filters; using unique queries; and producing tailored status reports.

CDM141: Introduction to the CDM Agency Dashboard

This four-hour course will review the current CDM Agency Dashboard enhancements including Risk Scoring, AWARE 1.5, Data Quality Reporting, STIG Reference Data, IdAM, FISMA Metrics, Summary Reporting, and other capabilities. Participate in hands-on lab activities to learn how to navigate and search the data within CDM using the Elastic Stack tools. See how that data can be used to create meaningful custom reports to communicate query results to leadership and stakeholders. Learn how to use AWARE to prioritize vulnerability management activities to address (or mitigate) the most critical vulnerabilities first.

CDM142: Asset Management with the CDM Agency Dashboard

This four-hour course will review the CDM Agency Dashboard enhancements including Risk Scoring, AWARE 1.5, Data Quality Reporting, STIG Reference Data, IdAM, FISMA Metrics, Summary Reporting, and other capabilities. Learn how you can use the CDM Agency Dashboard unified data to enhance situational awareness, mitigation prioritization, and cybersecurity outcomes within your organization. Participate in hands-on lab exercises to navigate and search the data within the CDM Agency Dashboard. See how you can use that data to create meaningful and visually appealing custom reports to communicate query results to leadership and stakeholders. Learn how to use AWARE to prioritize asset management activities to address or mitigate the most urgent or highest impact vulnerabilities first.

CDM143: Vulnerability Management using the CDM Agency Dashboard

This four-hour course provides an engaging review of the current operational version of the CDM Agency Dashboard, including Risk Scoring, AWARE 1.5, Data Quality Reporting, STIG Reference Data, IdAM, FISMA Metrics, Summary Reporting, and other capabilities. Students will gain foundational knowledge to effectively use the CDM Agency Dashboard AWARE 1.5 risk algorithm and prioritize vulnerability management activities to address the worst vulnerabilities first.

CDM201: Identity and Access Management using the CDM Agency Dashboard

This four-hour course will provide a demonstration and explore how the current version of the CDM Agency Dashboard incorporates “Who is on the Network” security capabilities. Create custom reports to determine how to effectively communicate search results through customizable reports. Discuss IdAM policies and "desired state" requirements and how they compare against the “actual state" data the CDM Agency Dashboard provides.

CDM202: Configuration Settings Management (CSM) with the CDM Agency Dashboard

This four-hour course will discuss the basic concepts associated with the CSM capability and the security configuration benchmarks used for the CDM Dashboard. Participants will engage in lab activities that explore how the CDM Agency Dashboard incorporates the CSM capability and demonstrate the basic steps to identify, analyze, and report configuration setting discrepancies within a given system boundary using the CDM Agency Dashboard. The course provides a basic overview of how CSM-related vulnerabilities contribute to an Agency's AWARE score.

CDM203: Systems Security Analyst

This four-hour course will identify and discuss the dashboard role of the System Security Analyst, recommended continuous monitoring activities, and use of the dashboard to support those activities. The course will demonstrate how to search and save routine queries to support recurring reporting responsibilities and identify and analyze system discrepancies within a given system boundary using the CDM Agency Dashboard.

CDM210: CDM Enabled Threat Hunting (CETH) using the CDM Agency Dashboard

This four-hour course will define CETH and describe its purpose, benefits, and how CETH is a key component in responding to the current governmental directives such as Executive Orders and Binding Operational Directives. Gain hands-on experience through guided lab activities in the current CDM Agency Dashboard training environment. Discover how to use the CDM Agency Dashboard to identify Known Exploited Vulnerabilities and other specific vulnerabilities currently affecting government. Discuss mitigation and remediation processes at your agency.

CDM220: CDM & Federal Mandates—How to use the CDM Dashboard to enable automated BOD 22-01 Reporting

This four-hour course presents information regarding current federal cybersecurity directives, mandates, and policies and CDM Agency Dashboard support capabilities. The course will prominently feature details regarding use of the CDM Dashboard to enable automated Binding Operational Directive (BOD) 22-01 reporting. The key features of this course include policy origination and history, current directives and mandates, agency and CISA responsibilities, subject matter expertise regarding directives and mandates, and an overview of the new BOD 23-01

This course will provide information regarding use of the CDM Dashboard to address the requirements of a directive, adhere to policies, and understand how to identify and monitor known exploitable vulnerabilities. CISA recommends knowledge of cybersecurity and privacy principles and a familiarity with organizational cybersecurity requirements and procedures.

CDM301: Management Overview of CDM and the CDM Agency Dashboard

This two-hour course will describe the key elements of the Management Leadership Role as the National Initiative for Cybersecurity Education (NICE) Framework defines them, review the principles of information assurance, identify the Federal laws that govern cybersecurity and required executive and senior-level management responsibilities, and discuss the purpose of the CDM Program. The course will show how the CDM Agency Dashboard can help establish a cybersecurity baseline. A demonstration of how the CDM Agency Dashboard can be used to make risk-based decisions at the enterprise level will also be discussed.

CDM320: Using the CDM Agency Dashboard to Respond to Federal Directives—BOD 22-01 & BOD 23-01

This two-hour course presents information regarding current Federal cybersecurity directives BOD 22-01 and BOD 23-01 and the CDM Agency Dashboard can support these directives. The course will explain the BODs’ scope and cover reporting responsibilities. The hands-on labs will enable students to practice using the CDM Agency Dashboard to enable automated BOD 22-01 reporting. This course will provide an overview of BOD 23-01 and guide the learner on use of the CDM Dashboard to address the requirements of a directive, adhere to policies, and understand how to identify and monitor Known Exploitable Vulnerabilities.

CDM Agency Dashboard Micro-Learn Videos

These short (3–10 minutes) CDM Agency Dashboard videos will provide a foundation level of knowledge and background to help dashboard end users prepare for in-person training demonstrations and hands-on activities, as well as the new dashboard implementation.

  • CDM Agency Dashboard—Kibana User Interface
  • CDM Agency Dashboard Architecture and Data Flow
  • CDM Agency Dashboard Data Structure and Schema
  • CDM Agency Dashboard—Understanding JSON Documents

Upcoming CDM Training Events

Mar 29, 2023 - Mar 30, 2023
Training | In-person

IN-PERSON EVENT - Analyzing Cyber Risk with the CDM Agency Dashboard ES-5 (CDM111)

Apr 04, 2023
Training | Virtual/Online

Introduction to CDM Enabled Threat Hunting (CETH) Using the CDM Agency Dashboard ES-5 (CDM210)

Apr 12, 2023
Training | Virtual/Online

Introduction to the CDM Agency Dashboard ES-5 (CDM141)

Apr 20, 2023
Training | Virtual/Online

Asset Management with the CDM Agency Dashboard ES-5 (CDM142)

Apr 25, 2023
Training | Virtual/Online

Using the CDM Agency Dashboard ES-5 to Respond to Federal Directives – BOD 22-01 & BOD 23-01

Virtual Learning Training Environment

The Federal Virtual Training Environment (FedVTE) Continuous Diagnostics and Mitigation (CDM) Training Program is a library of online video vignettes for Government employees and contractors. All the Micro-learn videos and CDM Dashboard course recordings are available via FedVTE.

FEDERAL VIRTUAL TRAINING ENVIRONMENT (FEDVTE)

AWARE (Agency-wide Adaptive Risk Enumeration)

These Agency-Wide Adaptive Risk Enumeration (AWARE) videos discuss how agencies can optimize the use of AWARE—an algorithm tied into the CDM Federal Dashboard that helps agencies measure risk. The video explains what AWARE is, what it does, and how agencies can use AWARE to improve their risk management decisions.

AWARE Videos

Learn How CDM’s AWARE Scoring Can Help You Reduce Cyber Risk

Learn how AWARE works and how it can reduce risks across the federal enterprise. Mr. Dave Otto, CDM Program Management Office, presents a one-hour webinar on AWARE, providing an overview of the scoring methodology behind AWARE and what you need to do to improve your agency’s score. He also offers insights on how AWARE could evolve as agencies gain more experience with CDM to support information security continuous monitoring policies.

Learn How CDM's AWARE Scoring Can Help You Reduce Cyber Risk Recording

Learn How CDM's AWARE Scoring Can Help You Reduce Cyber Risk Slide Deck

Learn How CDM's AWARE Scoring Can Help You Reduce Cyber Risk Certificate of Attendance

Incident Response Training

CISA offers no-cost cybersecurity Incident Response (IR) Training series with a range of offerings for beginner and intermediate cybersecurity analysts, including basic cybersecurity awareness, best practices for organizations, and facilitated lab activities. Course types include Awareness Webinars (100-level) and Cyber Range (200-level) Training. To learn more about CISA’s IR Training Program, please visit Incident Response Training | CISA.

Contact Information

To ask a question or provide other feedback on CDM training, contact us at CyberInsights@cisa.dhs.gov. For CDM Knowledge Base Access, register at https://maestro.dhs.gov/register/component/CISA  or contact your agency system integrator for access.

CyberInsights@cisa.dhs.gov

CISA Resources

Continuous Diagnostics and Mitigation (CDM) Program

Cybersecurity Training & Exercises

Cyber Hygiene Services

Cyber Resource Hub

CISA Cybersecurity Awareness Program

Alerts

Bulletins

Privacy Act Statement

Authority: 5 U.S.C. § 301 and 44 U.S.C. § 3101 authorize the collection of this information.

Purpose: The information on this website is intended for government cybersecurity professionals who are participating in the Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) Program and for cybersecurity professionals who would like more information on implementing a continuous monitoring program. The primary purpose for the collection of this information is to allow the DHS to contact you about your registration using an approved version of Adobe Connect for the DHS CDM training program.

Routine Uses: The information collected may be disclosed as generally permitted under 5 U.S.C. § 552a(b) of the Privacy Act of 1974, as amended. This includes using the information as necessary and authorized by the routine uses published in DHS/ALL-002 - Department of Homeland Security (DHS) Mailing and Other Lists System November 25, 2008, 73 FR 71659.

Disclosure: Providing this information is voluntary. However, failure to provide this information will prevent DHS from contacting you in the event there are queries about your request or registration.

Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 888-282-0870 Central@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Accessibility
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • The White House
  • USA.gov
  • Website Feedback