Why: A workforce readiness program that trains people on a rhythm and updates content as the threat picture changes is the operating engine this requirement's literacy training runs on — the cadence, the triggers, and the records are shared machinery.
What this does not claim: The requirement names its content: recognizing and reporting insider-threat indicators, social engineering, and social mining, delivered to all system users. The practice centers on technical-staff readiness; unless the general-user curriculum actually carries those named topics, the relationship is partial rather than direct. Coverage of every user population — not just the technical team — must also be demonstrable.
- Extend the readiness rhythm to all-user literacy training, not only technical roles
- Add insider-threat, social-engineering, and social-mining recognition to the curriculum and date the update
- Track completion for every system user
- Curriculum showing the required topics with an update history
- All-user completion records on the defined cadence
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06