Security Awareness
Security awareness helps you recognize common cybersecurity and privacy risks, choose safer actions, and report suspicious activity. It also helps organizations build learning programs that turn policies into repeatable behavior.
itCybersecurity fundamentals and governance | OpenSkills.info
Intro
Security Awareness
Security awareness is your ability to notice cybersecurity and privacy risks, avoid unsafe behavior, and act cautiously. Awareness training gives everyone a shared foundation for protecting information, systems, and privacy-related assets.
This is not a promise that people can stop every attack. Secure systems still need technical controls, clear processes, and capable security teams. Awareness helps you make better decisions at the points where your work meets those controls.
Why it matters
Daily work creates security decisions. You receive messages, sign in to accounts, handle information, approve requests, install updates, and report problems. An attacker may exploit urgency, authority, curiosity, fear, or routine to push one of those decisions in an unsafe direction.
A useful awareness program connects those moments to organizational risk. It tells you:
- which information and systems you must protect;
- which actions are expected;
- how common attacks reach you;
- where to ask for help;
- how to report a mistake or suspicious event quickly.
The goal is usable behavior, not perfect recall. NIST describes awareness training as foundational learning for all personnel. People with specialized duties need additional role-based training.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Sources
- https://csrc.nist.gov/pubs/sp/800/50/r1/final
Supports
- Definitions of awareness, awareness content, and awareness training
- Foundational and role-based learning for personnel
- Cybersecurity and privacy learning program scope and life cycle
- Behavior goals, security culture, measurement, evaluation, and improvement
- Limits of completion counts and the use of multiple assessment methods
- Quiz answers about program purpose, learning layers, and measurement
- https://csrc.nist.gov/projects/cybersecurity-framework/filters
Supports
- Awareness and Training category and general-task outcome PR.AT-01
- Recognition and reporting of social engineering and suspicious activity
- Basic cyber hygiene, assessment, and refresher examples
- Role-based awareness and training outcome PR.AT-02
- https://csrc.nist.gov/glossary/term/awareness_training
Supports
- Awareness training as foundational learning for all personnel
- Protection of information, cybersecurity, and privacy-related assets
- Acceptable use and organizational system risk orientation
- https://www.cisa.gov/secure-our-world
Supports
- Recognizing and reporting phishing
- Strong unique passwords and password-manager use
- Enabling multifactor authentication
- Installing software updates
- https://www.cisa.gov/more-password
Supports
- Multifactor authentication concepts and factor categories
- Account protection beyond passwords
- Differences in MFA strength
- FIDO and WebAuthn as widely available phishing-resistant authentication
- Quiz answers about unexpected authentication prompts and MFA limits
- https://github.com/sindresorhus/awesome
Supports
- Discovery of the Awesome Security and Awesome Security Card Games lists
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Gophish as an open-source phishing framework
- https://github.com/Karneades/awesome-security-card-games
Supports
- Discovery of Security Cards and Backdoors and Breaches
- Security card games as training and discussion resources
- https://getgophish.com/
Supports
- Authorized phishing campaign templates, scheduling, result tracking, and REST API
- Gophish Awesome Links rationale
- https://securitycards.cs.washington.edu/
Supports
- Threat brainstorming across human impact, motivations, resources, and methods
- Educational and industry activities
- Security Cards Awesome Links rationale
- https://www.blackhillsinfosec.com/tools/backdoorsandbreaches/
Supports
- Cooperative incident-response tabletop exercises
- Attack paths, detections, procedures, and debrief-driven improvements
- Backdoors and Breaches Awesome Links rationale
