Configurable role profile
Build the foundations for confident cyber practice.
Green Team pathways provide the progressive entry route into cyber practice. Learners build networking, operating system, security fundamentals and scripting capability through guided laboratories with checkpoints, then move into supervised team exercises. Lab discipline and evidence basics are taught from the start, so safe tool use and clear record-keeping become habits before a learner reaches a higher-risk environment. Progression is evidence-based rather than time-based.
CLIP · Green Team role profile
Illustrative view- 01 · Mission outcomeProvide a progressive entry pathway for foundational knowledge and guided skill development.
- 02 · CompetenciesNetworks · Operating systems · Security basics · Scripting
- 03 · Exercise activityGuided network investigation
- 04 · EvidenceLab completion with checkpoint results
Team-colour terminology varies by organization
Mission intent
The role's purpose and its boundaries.
Provide a progressive entry pathway for foundational knowledge and guided skill development.
Core competencies
What this pathway develops.
Competencies are versioned and mapped to organizational, NICE, relevant SKKNI or custom frameworks without duplicating the underlying evidence.
- 01Networks
- 02Operating systems
- 03Security basics
- 04Scripting
- 05Lab discipline
- 06Evidence basics
Learning pathway
Progressive difficulty, evidence at every step.
- 01FoundationStructured learning and prerequisites.
- 02Guided labSupervised practice with checkpoints.
- 03Team labCoordination and handoffs within the role.
- 04Integrated exerciseMulti-team scenario under exercise control.
- 05AssessmentObserved performance and assessor adjudication.
In sequence: Foundation knowledge leads into a guided laboratory, then a team laboratory, then an integrated multi-team exercise, and finally an assessment that produces competency evidence.
Representative scenarios
How the pathway is exercised.
Guided network investigation
Following traffic through a small synthetic topology to answer a defined question.
Vulnerable application basics
Understanding a weakness class and its remediation in a contained environment.
First incident timeline
Assembling an ordered account of events from provided telemetry.
Tools and environments
Capability categories, not a tool list.
Specific tooling is selected per deployment after security, licence and air-gap review. The categories below describe what the pathway needs to work.
- Guided container and virtual machine laboratories
- Structured courses and learning pathways
- Introductory challenge and objective sets
Evidence of competence
What observable behaviour supports readiness.
A readiness claim for this role must trace back to these artifacts. Evidence freshness is tracked separately from current competence, so an expired record never silently counts as a current one.
How readiness is calculated- Lab completion with checkpoint results
- Practical task evidence
- Demonstrated safe tool use
- Written reflection on the approach taken
- Readiness for the next capability level
Collaboration
Upstream and downstream handoffs.
No role operates alone. These are the relationships that make this pathway useful to the wider mission.
Feeds progressive readiness into every other role pathway
Instructors release hints and review practical evidence
Prerequisites gate entry into higher-risk exercises
Metrics
Operational and learning measures.
What the platform can measure for this role. Targets are baselined with each organization rather than claimed in advance.
- Median time-to-competency for foundational roles
- Pre and post assessment improvement
- Practical task success rate
Map your roles to CLIP.
We will work from your approved role definitions and competency framework, not from ours.