Insider Threat Awareness
Recognize and report the indicators that protect your colleagues, your company and controlled information
- Duration
- 1.5 hours
- Modules
- 4
- Final exam
- 70% to pass
- Certificate
- No expiry
- Lifetime access to the course and your certificate
- Verifiable Certificate of Completion. Certificate does not expire.
- 3 exam attempts
- Progress saved to your account on every slide
Buying for a team? Volume pricing from 5 seats
| 1 to 4 seats | List price |
| 5 to 10 seats | 15% off |
| 11 to 20 seats | 25% off |
| 21 or more seats | 35% off |
$250.75
5 × $50.15 · save $44.25
Each seat is a single-use code. Send one to each learner; they sign in with their own account and earn their own certificate. Track progress on your Team page.
About this course
The person who causes the most damage to a defense supplier is often already inside: an employee, a contractor or a trusted partner with a badge and a login. Sometimes they mean harm. More often they are careless, pressured or tricked. This course teaches you what an insider threat is, what the early signs look like, why the controls you live with every day exist, and how to report a concern in a way that protects everyone, including the person you are worried about.
You will learn the difference between malicious, negligent and compromised insiders, why controlled unclassified information and export-controlled data make defense suppliers a target for foreign intelligence and competitors, and what NIST SP 800-171 Rev 2 requirement 3.2.3 and the CMMC Awareness and Training domain expect of you. The indicators module covers behavioural and technical warning signs and the equally important caution against profiling or acting on a single sign.
The controls module explains least privilege, separation of duties, access reviews, onboarding and offboarding, removable media rules, monitoring and acceptable use, so that you understand them as protection rather than friction. The reporting module tells you whom to tell, what to include, how confidentiality and non-retaliation work, and walks through realistic scenarios with a decision in each.
This is awareness-level training for every employee of a company that handles federal contract information or CUI. It does not replace the insider threat training that cleared facilities must provide under the NISPOM, and it is not legal advice; follow your company's procedures and your security officer. The course closes with a 10-question examination drawn from a bank of 20. On passing you receive a PlanetISO Certificate of Completion with lifetime access. The certificate does not expire.
What you will be able to do
- Define insider threat and distinguish malicious, negligent and compromised insiders with examples from a defense supplier.
- Explain why CUI and export-controlled data make insiders valuable to foreign intelligence services and competitors.
- State what NIST SP 800-171 Rev 2 requirement 3.2.3 and the CMMC Awareness and Training domain require.
- Recognise behavioural and technical indicators of potential insider threat and explain why no single sign is proof.
- Describe the purpose of least privilege, separation of duties, access reviews, offboarding, removable media rules and monitoring.
- Report a concern through the correct path with the right facts, and explain how confidentiality and non-retaliation apply.
Course outline
- 1
What an insider threat is
Malicious, negligent and compromised insiders; why CUI and export-controlled data make them valuable; and the requirement in NIST SP 800-171 Rev 2 3.2.3 and CMMC.
About 20 minutes, then a module quiz
- 2
Indicators: what to notice
Behavioural and technical indicators of potential insider threat, how they combine, and the caution against profiling or acting on a single sign.
About 20 minutes, then a module quiz
- 3
The controls you live with and why
Least privilege, separation of duties, access reviews, onboarding and offboarding, removable media rules, monitoring and acceptable use, explained as protection rather than friction.
About 20 minutes, then a module quiz
- 4
Reporting a concern
Whom to tell, what to include, how confidentiality and non-retaliation work, how reporting links to the company's DoD obligations, and scenarios with a decision in each.
About 25 minutes, then a module quiz
Final examination and certificate
10 questions drawn from the course bank. Score 70% or higher to receive your Certificate of Completion.
More CMMC and NIST SP 800-171 training
- CMMC and NIST SP 800-171Short course
CMMC Level 2 and NIST SP 800-171 Overview
What a Level 2 assessment expects, how the 110 requirements are organized and how to build a program that passes
- Duration
- 3 hours
- Level
- Foundation
$99View course - CMMC and NIST SP 800-171Awareness
Phishing and Email Security
Spot the message that is trying to trick you, and know exactly what to do next
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
Social Engineering Prevention
Recognize manipulation in person, on the phone and online, and verify before you act
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CUI Handling and Marking
Recognize controlled unclassified information, mark it correctly and handle it safely
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CMMC Level 1 Overview
The 15 basic safeguards for federal contract information and how the annual self-assessment works
- Duration
- 1.5 hours
- Level
- Foundation
$59View course