Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CDM330 is a CISA course on High Value Asset (HVA) program basics and using the CDM Agency Dashboard to manage HVAs. It is intended for federal cybersecurity staff and supporting contractors who monitor, manage, or oversee information-system controls. CISA describes its CDM training as instructor-led, hands-on instruction with simulated labs in a cyber virtual learning environment.

What CDM330 covers

CISA’s published description says CDM330 covers the basics of the HVA program and demonstrates managing HVAs in the CDM Agency Dashboard. The public description establishes the course’s purpose, but not a detailed lesson sequence or click-by-click dashboard procedure. It is therefore best understood as practical HVA and dashboard training, rather than as a published operating manual.

CISA’s January–February 2025 training bulletin listed the course as a four-hour session. That is a historical offering detail, not a guarantee that every future session will use the same duration or format. CISA Cyber Training Bulletin: January–February 2025

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who should take the course

The intended audience is Federal Civilian Executive Branch (FCEB) agency employees and supporting contractors whose work includes monitoring, managing, or overseeing information-system controls. Relevant roles named by CISA include:

  • Information system security officers (ISSOs)
  • CDM points of contact
  • Information system security managers (ISSMs)
  • Personnel responsible for reporting metrics

The course is most relevant when your responsibilities touch HVA oversight or CDM dashboard reporting; it is not described as a general cybersecurity-awareness course.

What an HVA means in the CDM program

CISA places HVA protection under CDM’s Data Protection Management capability. Its fact sheet describes HVAs as networks essential to agency functions, networks designated essential to maintaining the security and resiliency of the federal civilian .gov enterprise, or both. This is a program-level scope: an HVA is not simply any computer system someone considers sensitive. CISA CDM Program Data Protection Management Fact Sheet, September 3, 2020

CDM provides visibility through agency and federal dashboards. CISA’s asset-management fact sheet says asset information is reported to both levels of dashboard, while Binding Operational Directive 23-01 identifies outcomes such as maintaining an up-to-date network-asset inventory, identifying vulnerabilities, and providing asset and vulnerability information to the CDM Federal Dashboard. These are wider program objectives; the public CDM330 description does not establish that the course teaches every BOD 23-01 task.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the training and dashboard context fit together

CISA characterizes CDM dashboard training as instructor-led and hands-on, using a cyber virtual learning environment (CVLE) with simulated labs. The simulation provides a training context for dashboard work; it should not be mistaken for access to an agency’s operational dashboard or evidence that every agency uses the same deployed version. CISA Cyber Training Bulletin: September–October 2026

In that September–October 2026 bulletin, CISA identified Enterprise Services (ES) 6.8 as the version used in the training environment and listed HVA reporting among current training content. This identifies the bulletin’s training setup, not the version necessarily deployed by each agency. The bulletin listed a CDM330 session for September 24, 2026; that date has passed, so it is a past scheduled offering rather than an upcoming registration date. CISA’s earlier 2026 bulletins also listed CDM330, showing repeated offerings, but future dates and availability require checking current CISA listings.

How CDM330 relates to other dashboard training

CISA’s course catalog covers other CDM dashboard activities. These areas help distinguish HVA management from adjacent work, but the catalog does not establish that they are all part of CDM330:

Operational area What the related training addresses Relationship to CDM330
Asset management Hardware and software queries, reports, and risk-based decisions Supports asset visibility across the program; not identified as CDM330’s full curriculum.
Vulnerability management Identifying risk and prioritizing mitigation Adjacent to HVA protection, but not specified as a CDM330 module.
Identity management PRIV, CRED, TRUST, and BEHAVE areas A separate dashboard learning area.
Configuration management Security settings, STIGs, and the contribution of configuration scoring to risk scoring A separate dashboard learning area.
HVA data protection and reporting HVA program basics and managing HVAs in the CDM Agency Dashboard The published focus of CDM330.

CISA also describes analyst training focused on routine queries, discrepancies, continuous monitoring, and reporting. For course selection, start with the operational task you need to perform—inventory visibility, vulnerability prioritization, identity and access, secure configuration, or HVA protection and reporting—rather than treating the courses as interchangeable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Related CISA resources: CDM Dashboard Courses, CDM Asset Management Fact Sheet, May 26, 2021, and BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks, January 26, 2023.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What public course information does not establish

CISA’s public descriptions establish CDM330’s topic, intended audience, hands-on training context, and selected scheduled offerings. They do not publish a complete lesson plan, exact dashboard navigation steps, or a definitive list of exercises. For those specifics, use the course materials supplied to enrolled participants or ask the relevant CISA training contact; do not assume that a general CDM dashboard guide reproduces the CDM330 lab.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.