CPRs: Community Project Requirements

CPRs:

Community Project Requirements

Version 1.2

Current Version
Archives

The community of security professionals in government, commercial, and academic and research organizations is a powerful force for good. They often work together in ad hoc teams to fight against cyber crime and to help organizations block attacks or recover from attacks. When they learn about a major new vulnerability and wonder how best to respond, or when their organization is attacked and they are seeking tools that can help them defend their systems, security practitioners look to their network of practitioners for ideas, proven techniques and help in avoiding major mistakes. The SANS Technology Institute education provides opportunities for you to build your own network of security professionals from the other students and the faculty. These are the people you can call on, and who can call on you, when in need. This is such an important component of your education that we have engineered team activities into the programs to enrich your educational experience, to begin contributing to the security community, and to expand your network of peers. The projects, which involve research, writing and speaking, are graded. The sum of your scores on these exercises will be your final Community Project grade; or, if they are graded on a pass/fail basis, you must pass each exercise to receive a passing Community Project grade.

Residential Institutes - General

Attendance at Three Residential Institutes

Residential Institutes (RI) are the large six-day conferences that SANS Institute offers on a periodic basis in various U.S. cities and some international sites. Examples are SANSFIRE, SANS Annual Conferences, and SANS Network Security. SANS CDI (Cyber Defense Initiative) also qualifies, though it is not as large as the others. For the first RI where the Work Study is done, smaller six-day conferences may qualify. Also, smaller conferences may be authorized for international students in certain situations. Students may take some or all of their courses at the Residential Institutes. It is possible for a student to take some of the courses through different delivery systems such as SANS OnDemand, SANS SelfStudy, SANS Mentor, SANS@Home (also known as webcast), etc.; but the student still must attend three Residential Institutes.

Planning Spreadsheet for Residential Institutes. In advance of an RI that a student wishes to attend, he/she must complete the excel spreadsheet which can be downloaded here. The student will attach it to an e-mail and send it to info@sans.edu.

Hotel Expenses. Students must pay for their own hotel room and hotel tax as well as their other expenses for travel and food with the following exception: When a student proctors to satisfy the Proctoring Community Project Requirement, the Institute pays for the hotel room and hotel tax; but the student does not receive a proctor fee, and the Institute does not pay for any other expenses. When the student is proctoring under the general proctor pool, the student receives a proctor fee, and the student's authorized expenses are paid for.

Why does the student have to attend the three RIs?

The RIs provides live face- to- face time among students, faculty, and instructors. It provides students with opportunities to build their own network of security professionals with other students, faculty, and instructors.

Oral Presentations at two of the three RIs - Students must make an oral presentation at TWO of the three RIs. Generally, the presentation occurs at the second and third RIs, but it is possible for the student to do the first presentation at the first RI if they coordinate it with SANS Technology Institute's senior staff. The presentation topic is based on the student's previously earned Gold GIAC certification research. Students may request resource material about "How to Give Effective Presentations" by e-mailing info@sans.edu - see www.sans.edu/resources for more information. The presentation will be given in front of a member of SANS Technology Institute's senior staff. Generally it is done in the evening, and there will be other people in the audience as well. The grade will be on a pass/fail basis, but that may change in the future. The evaluation form used is similar to the Event Evaluation form that SANS uses when students are asked to evaluate faculty/special speakers. A "passing score" for a student on that form is 8.4 and above. The other audience members also will provide feedback on the Event Evaluation forms which the grader may use for information purposes. A sample of the Event Evaluation form may be downloaded here. SANS Technology Institute may, but is not required to, post passing presentations onto its website.

First Residential Institute

You will participate in the Work Study Program (previously called Volunteer Program) as a Facilitator. In addition to attending class, you will be a part of a live SANS conference. Teamwork is the primary focus of your first RI; and, as a side benefit, you will probably develop relationships that last for years. Your performance will be evaluated by a SANS staff member experienced in the management of the residential institute/conference program. The student will coordinate with the SANS Work Study coordinator (www.sans.org/training/volunteer.php) well in advance of the scheduled RI. The student should let the Work Study coordinator know that the student is in SANS Technology Institute's masters degree program. Some examples of Facilitator duties include room monitor or bookroom Facilitator. Students can participate in those two types of activities without significantly affecting their ability to take a course at the conference. A Facilitator pays a reduced fee for the course in which he or she is a Facilitator. The student will be graded on a pass/fail basis, but that may change in the future. See the following for an example of an evaluation form that may be used: Facilitator Evaluation Form

Joint Written Project

A student must engage in ONE joint written project during the term of the masters program. (It generally is completed after the first RI preferably, or after the second RI). The student must select at least one other student to be his or her partner(s) in the Joint Written Project. Joint Written Projects can either be assigned to the student partners at a conference by senior staff so that the partners have a little time to talk directly to make plans; or the student partners can request that the assignment be provided to them by e-mail. A senior staff member will select a Learning and Assessment Objective (LAO) for the team. The LAO will have an associated Outcome Statement. In general, the team will:

  • Perform a critical analysis of the LAO.
  • Perform a gap analysis and determine the project steps to improve the LAO. A gap analysis means the team determines where they are and where they want to be.
  • Conduct original research on new developments that may have altered the LAO subject matter
  • Students create an assessment tool to measure whether students have mastered the subject material.
  • Submit the project results for evaluation and grading.

The Joint Written Project is written, and does not involve an oral presentation. The students will collaborate with their partner(s) by e-mail, phone, etc. to coordinate their efforts. In life, partners often must coordinate a project by e-mail, phone, etc. rather than face-to-face, so this project gives students experience working virtually. The project must be completed and submitted to SANS Technology Institute within 30 days after the students received the topic. The grade will be a team grade / each student in that team will receive the same grade. The grade will be on a pass/fail basis, but that may change in the future. SANS Technology Institute may, but is not required to, post passing projects onto its website.

Second Residential Institute

Group Discussion and Written Project

The student will arrive two days BEFORE the scheduled RI to participate in a Group Discussion and Written Project. A problem will be presented to the student's team the evening before the project is to be presented; and, as a team, the team prepares to present a recommended solution to senior staff about 24 hours later. As a leader, you will be expected to deal with situations with short turnaround times, so this project allows you to demonstrate those skills and to improve them. The actual presentation is given by one member of the team which the team selects. The presentation usually occurs in the evening in front of a member of SANS Technology Institute's senior staff. Generally, there are no other people in the audience, or only a few. The grade will be a team grade / each student in that team will receive the same grade. The grade will be on a pass/fail basis, but that may change in the future. SANS Technology Institute may, but is not required to, post passing projects onto its website.

Joint Written Project

If not already completed, see discussion above.

Oral Presentation

See the Oral Presentation discussion in the "Attendance at Three Residential Institutes" section above.

Third Residential Institute

Proctor

The student will assist an instructor as a proctor in a hands-on course. Leaders have to be good at troubleshooting, whether the problem is technical, process or personal. A proctor's job is to help other students, and that usually involves a lot of troubleshooting. The student will benefit from being exposed to an excellent hands-on instructor, and the student will be able to exercise important skills while assisting others in the hands-on instruction. The instructor in the room will observe your grace under fire as you face various challenges, and then evaluate your performance. You will be graded on a pass/fail basis. As proctors, students likely will have access to the faculty speaker room to enhance their relationships with the faculty. For successful students, this can be the milestone event during which they become a full-fledged member of the defensive information security community. The student may not be able to take courses at this RI since he or she may be a proctor about 36 hours over the span of the conference. The student will not be paid a fee for this proctoring requirement. When a student proctors to satisfy the proctoring Community Project Requirement, the Institute pays for the hotel room and hotel tax; but the student does not receive a proctor fee, and the Institute does not pay for any other expenses. (If a student later wants to apply to be a proctor under SANS' general proctor pool, the student may be able to receive a proctor fee When the student is proctoring under the general proctor pool, the student receives a proctor fee and the student's authorized expenses are paid for). A sample of the Proctor Evaluation form may be downloaded here.

Oral Presentation

See the Oral Presentation discussion in the "Attendance at Three Residential Institutes" section above.

After Completion of the above Presentations/Projects

Security Awareness Talk in Student's Community - Plan

The Plan for the Security Awareness Talk. Within 30 days after the student finishes the presentations and projects described above, the student must present a plan to SANS Technology Institute describing how the student intends to satisfy the Awareness Talk. (This paragraph about "the Plan" applies to students admitted June 1, 2006 and after).

Teaching Security Awareness in the Community (Applies to all students)

The student will teach SANS SECURITY 351 - Computer and Network Security Awareness, or a similar awareness course, at no cost or low cost to members of the public in the student's own community. Upon student's request to staysharp@sans.org with a copy to info@sans.edu, the Institute will allow the student to use the SEC 351 course material for a low cost, or the student can devise his or her own course content. The student, and possibly SANS Technology Institute, will invite members of the public to attend. At least one representative from the student's own organization (place of employment) must be present. That person will provide evidence to SANS Technology Institute that the talk was made. The talk is a Community Project Requirement, but the student will not receive a specific grade for it.