# Security Awareness Learning Program Development and Management Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/security-awareness-program-development-course-self-paced>

## Overview

Federal agencies must run a security awareness and training program, but most training is written for the employee taking it, not the person running it. This self-paced course is built for the ISSO, training officer, or IT security specialist who owns the program.

Learners cover FISMA and NIST requirements, needs assessments, audience segmentation, delivery channels, and ethical phishing simulations. The course closes with metrics that show behavior change and reports that leadership can act on.

## What you'll learn

- Explain the federal statutory and regulatory basis for security awareness and training programs, including FISMA and the NIST SP 800-53 Awareness and Training control family.
- Identify the roles and responsibilities for building and running an agency's awareness program.
- Conduct a training needs assessment for a federal workforce.
- Segment a workforce into general, privileged, and specialized training audiences.
- Write measurable learning objectives tied to organizational risk.
- Evaluate build, buy, and blend options for sourcing training content.
- Select delivery channels appropriate to workforce size, location, and technology constraints.
- Design a phishing simulation program within ethical and policy limits.
- Build a communication plan that reinforces training and sustains a security-aware culture.
- Establish an escalation process for employees who do not complete required training.
- Define metrics that measure behavior change rather than completion alone.
- Correlate awareness program metrics with incident data to target follow-up training.
- Report program health to agency leadership and oversight bodies.
- Apply a program maturity model to plan year-over-year improvement.

## Curriculum

#### Module 1: Federal Mandates and the Awareness and Training Program Foundation

- Lessons: 
  - Why Federal Agencies Are Required to Train
  - The NIST SP 800-53 Awareness and Training (AT) Control Family
  - Building the Program: NIST SP 800-50 Roles and Structure
  - Who Owns the Program: ISSO, CISO, and Training Officer Roles

- Applied activity: Given a mock agency's mission and workforce profile, identify which FISMA and NIST SP 800-53 AT requirements apply and name the roles responsible for meeting each one.

#### Module 2: Assessing Needs and Designing the Curriculum

- Lessons: 
  - Conducting a Training Needs Assessment
  - Segmenting Audiences: General Workforce, Privileged Users, and Specialized Roles
  - Writing Learning Objectives and Mapping Curriculum to Risk
  - Sourcing Content: Build, Buy, or Blend

- Applied activity: Draft a training needs assessment and audience segmentation plan for a mock agency with a general workforce, privileged system administrators, and specialized technical staff.

#### Module 3: Delivering, Communicating, and Sustaining the Program

- Lessons: 
  - Choosing Delivery Channels and Cadence
  - Running Phishing Simulations Responsibly
  - Communication Campaigns and Building a Security Aware Culture
  - Handling Non-Completion and Repeat Offenders

- Applied activity: Build a delivery and communication plan for a 12-month awareness cycle, including one simulated phishing campaign and one escalation path for repeat non-completion.

#### Module 4: Measuring Effectiveness and Reporting to Leadership

- Lessons: 
  - Metrics That Matter: Beyond Completion Rates
  - Correlating Awareness Metrics with Incident Data
  - Reporting Program Health to Leadership and Oversight
  - Program Maturity and Continuous Improvement

- Applied activity: Build a one-page dashboard reporting program metrics, including completion, phishing click rate, and incident correlation, for agency leadership.

## Pricing

**Tuition:** $799
