top of page
Cyber_pracittioner vs hacker_1.png

Cyber CapstoneTM

Defense by design simulations for real-world cybersecurity practice.

You will think like the attacker, build like an engineer, and prove your work.

Join architects and engineers worldwide shaping the future of cybersecurity through technical concepts, models, and our Defensible 10 Standards.

Cyber Capstones in the Mission Pack Model

ISAUnited Cyber Capstones (ICC) are structured simulation assignments delivered within the Cyber Academy's Learning Management System (LMS). Each Cyber Capstone assigns a defined cyber problem, requires participants to build a Tactical Battle Map, and evaluates the architecture, engineering, Security by Design, or Red Team Engineering decisions they produce.

 

Cyber Capstones are completed inside the LMS. Participants use ISAUnited’s Blue Team and Red Team resources to support their work, including:

  • Intrusion Vault: threat actors, threat vectors, and threat tools that help define how compromise may progress.

  • Defense Toolbox: Defensible 10 Standards and Defensible Engineering Catalog components used to design and justify the defense.

 

Each Cyber Capstone is designed to evaluate practical decision making, architecture level reasoning, threat mapping, defensible design, and the ability to produce evidence that withstands review.

Mission_pack_cover_CPM_3D_v2.png

Cybersecurity Project Manager

Mission Control - Mission Pack

Coordinate the mission. Validate the outcome. Prove readiness.

Mission_pack_cover_CDT_3D_v2.png

Cybersecurity Technician

First Watch - Mission Pack

Start the Cybersecurity Technician pathway and build practical cyber defense readiness through simulation-based learning.

Broken Trust ICC
Mission_pack_cover_ENG_2.png

Cyber Capstone Samples

Cyber Capstones focused on architecture and engineering trusted systems, identity paths, insider risk, and compromised trust relationships.

The Broken Trust Mission Pack domain challenges participants to study how compromise can move through systems, identities, applications, and integrations that were assumed to be safe. These Cyber Capstones emphasize trust boundaries, identity misuse, partner exposure, and defensible monitoring.

Broken_Trust_ICC_pic1.png

ICC-ARC-01: Cloud Landing Zone and New SaaS

Design a defensible architecture for a new SaaS environment with tenant separation, partner access, and identity risk.

Broken_Trust_ICC_pic2.png

ICC-ARC-02: Partner Integration and Trust Boundary Exposure

Map trusted connections, application programming interface exposure, and cross organization access paths that could expand compromise.

Broken_Trust_ICC_pic3.png

ICC-ENG-01: Identity Federation and Token Misuse Risk

Engineer controls that reduce identity abuse, token misuse, and unauthorized movement through trusted access paths.

Launch Shield ICC
Mission_pack_cover_SbD_2.png

Cyber Capstone Samples

Cyber Capstones focused on Security by Design before deployment across systems, applications, and infrastructure.

The Launch Shield Mission Pack domain focuses on planning, architecture, engineering, and design decisions before production deployment. These Cyber Capstones evaluate how participants identify exposure early, define requirements, place safeguards, and prove readiness before launch.

Launch_Shield_ICC_pic1.png

ICC-SbD-01: Product Launch Security Readiness

Apply Security by Design to a new product launch before production release.

Launch_Shield_ICC_pic2.png

ICC-SbD-02: Application Deployment and Exposure Review

Identify exposure early and define safeguards before a new application moves into production.

Launch_Shield_ICC_pic3.png

ICC-SbD-03: Industrial Platform Launch and Safety Aligned Security

Apply Security by Design to a connected industrial or operational environment where safety, resilience, and access control must be proven before deployment.

RTE ICC
Mission_pack_cover_RTE_2.png

Cyber Capstone Samples

Cyber Capstones focused on Red Team Engineering, controlled adversarial practice, and governed exercise conditions.

The Red Recon Mission Pack domain introduces disciplined red team engineering through an authorized scope, reconnaissance logic, threat mapping, and defensible reporting. These Cyber Capstones help participants study adversary behavior while connecting Red Team activity to Blue Team readiness and to the outcomes of governed exercises.

Red_Recon_ICC_pic1.png

ICC-RTE-01: Authority, Scope, and Mission Brief

Define lawful authority, boundaries, objectives, and rules of engagement for a controlled red team exercise.

Red_Recon_ICC_pic2.png

ICC-RTE-02: Threat Profile Selection and Vector Mapping

Select the threat profile and map likely entry paths, exposure conditions, and adversary movement.

Red_Recon_ICC_pic3.png

ICC-RTE-03: Architecture Exposure and Detection Objectives

Connect red team activity to architecture exposure, blue team detection goals, and defensible reporting.

Get Started

For the Cyber Academy

Enroll in your program pathway and complete your cyber capstone in the academy's LMS when you reach the graduation stage.

Enroll as a Student | Learn About Capstones.

For CPL Candidates

Learn how professional readiness exercises support serious technical validation.

For Organizations

Contact us below to choose a simulation track and set your annual readiness and evaluation plan.

Activate your tech teams' ISAUnited membership | Member organizations receive discounted rates.

bottom of page