Recognizing digital threats and building the habits that protect personal and organizational information.
Cybersecurity Awareness is the competency of understanding digital risks and applying protective practices in daily life and work. It spans password hygiene and phishing recognition through organizational security policies, incident response, and security program design. The focus is not on becoming a security engineer, but on developing the judgment and habits needed to minimize risk, respond to threats appropriately, and foster a security-conscious culture at every level of an organization.
Defines six core cybersecurity functions (Govern, Identify, Protect, Detect, Respond, Recover) with four implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive), providing structure for Level 3-6 organizational security maturity checklist progression.
A 5-level maturity model (Non-Existent β Compliance-Focused β Promoting Awareness β Long-Term Sustainment β Metrics Framework) providing evidence-based behavioral benchmarks and measurement criteria for checklist item design at each level.
Defines 12 cybersecurity professional role profiles with competency requirements as an EU-endorsed standard, providing authoritative grounding for Level 4-7 organizational and strategic security awareness competencies.
Defines cybersecurity workforce Work Roles, Competency Areas, and Tasks as a U.S. government-endorsed standard, providing government-level authority for establishing boundaries across the 7-level progression from security awareness to security strategy.