The rules this course is built on
We teach to the published text. Read it yourself — every link below goes to the issuing agency or legislature, not to a summary.
Issuing authority: PCI Security Standards Council (industry standard body, not a government regulator), with US federal guidance from NIST and CISA
- NIST SP 800-50r1 — Building a Cybersecurity and Privacy Learning Program
PCI DSS Requirement 12.6 obliges a formal security awareness programme but does not prescribe how to build one. NIST SP 800-50r1 is the reference this course follows for programme structure and measurement.
Read the official text — NIST Computer Security Resource Center → - CISA — Cybersecurity Best Practices
The US government’s own guidance for the behaviours this course trains: phishing recognition, passwords and multi-factor authentication, safe handling of data and devices.
Read the official text — Cybersecurity and Infrastructure Security Agency →
Provided so you can verify what we teach against the source. This is reference material, not legal advice, and reading it does not by itself discharge an employer obligation.