{
  "node_id": "nist-sp-800-50r1-learning-program",
  "title": "Building a Cybersecurity and Privacy Learning Program",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2024-08-09",
  "bluf": "This publication provides guidance for federal agencies and organizations to develop and manage a life cycle approach to building a Cybersecurity and Privacy Learning Program (CPLP). The program is intended to address the needs of large and small organizations and includes cybersecurity and privacy awareness campaigns, role-based training, and other workforce education programs. The CPLP is designed to be part of a larger organizational effort to reduce cybersecurity and privacy risks, supporting federal requirements such as the Federal Information Security Management Act (FISMA) and incorporating industry-recognized best practices for risk management.\n\nThe core obligation is for an organization to create a strategic program plan that ensures appropriate resources are available to meet learning goals for all personnel, including employees and contractors. The overarching goal of a CPLP is to provide opportunities for learning at all levels, encourage behavior change as part of risk management, and lead to developing a privacy and security culture in the organization. The guidance provides steps to build an effective CPLP, identify personnel who require advanced training, create a methodology for program evaluation, and engage in ongoing improvement to minimize privacy and security risks to the organization.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-200-minimum-security-requirements",
    "nist-sp-800-181r1-nice-framework",
    "nist-sp-800-39-managing-information-security-risk",
    "nist-sp-800-53-r5"
  ],
  "primary_citations_count": 8
}