[フレーム]
You are viewing this page in an unauthorized frame window.

This is a potential security issue, you are being redirected to https://csrc.nist.gov.

You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    Publications

NIST SP 1288

Federal Cybersecurity Role-Based Training Approaches, Successes, and Challenges

Documentation Topics

Date Published: January 2023

Author(s)

Julie Haney (NIST), Jody Jacobs (NIST), Susanne Furman (NIST)

Abstract

Most United States federal government organizations are required to conduct cybersecurity role-based training for federal government personnel and supporting contractors who are assigned roles having security and privacy responsibilities. Despite the training mandate, there has been little prior effort to look broadly across federal organizations to see how they are implementing these training activities and what issues they are experiencing. This lack of understanding may be hindering the development of improvements and resources for training activities. To address this gap, the Usable Cybersecurity team at the National Institute of Standards and Technology conducted a research study consisting of focus groups and a survey to gain insights into the approaches of and challenges faced by federal organizations when implementing role-based training activities. This paper reports the results of the study and suggests actions that organizations can take to improve federal role-based training activities.

Most United States federal government organizations are required to conduct cybersecurity role-based training for federal government personnel and supporting contractors who are assigned roles having security and privacy responsibilities. Despite the training mandate, there has been little prior... See full abstract

Most United States federal government organizations are required to conduct cybersecurity role-based training for federal government personnel and supporting contractors who are assigned roles having security and privacy responsibilities. Despite the training mandate, there has been little prior effort to look broadly across federal organizations to see how they are implementing these training activities and what issues they are experiencing. This lack of understanding may be hindering the development of improvements and resources for training activities. To address this gap, the Usable Cybersecurity team at the National Institute of Standards and Technology conducted a research study consisting of focus groups and a survey to gain insights into the approaches of and challenges faced by federal organizations when implementing role-based training activities. This paper reports the results of the study and suggests actions that organizations can take to improve federal role-based training activities.


Hide full abstract

Keywords

role-based training; cybersecurity awareness programs
Control Families

Awareness and Training

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.1288
Download URL

Supplemental Material:
None available

Document History:
01/11/23: SP 1288 (Final)

AltStyle によって変換されたページ (->オリジナル) /