The rules this course is built on
We teach to the published text. Read it yourself — every link below goes to the issuing agency or legislature, not to a summary.
Issuing authority: National Institute of Standards and Technology (NIST) and CISA
- NIST SP 800-50r1 — Building a Cybersecurity and Privacy Learning Program
The federal reference for how a security awareness programme should be built, run and measured. This course is structured against it.
Read the official text — NIST Computer Security Resource Center → - NIST Cybersecurity Framework
The framework most US security programmes are organised around. Awareness training sits under its Protect function.
Read the official text — National Institute of Standards and Technology → - CISA — Cybersecurity Best Practices
The US government’s own guidance for the behaviours this course trains: phishing recognition, passwords and multi-factor authentication, safe handling of data and devices.
Read the official text — Cybersecurity and Infrastructure Security Agency →
Provided so you can verify what we teach against the source. This is reference material, not legal advice, and reading it does not by itself discharge an employer obligation.