Skip to content
PlanetISO
CMMC and NIST SP 800-171AwarenessFoundation

Insider Threat Awareness

Recognize and report the indicators that protect your colleagues, your company and controlled information

Duration
1.5 hours
Modules
4
Final exam
70% to pass
Certificate
No expiry
$59
  • Lifetime access to the course and your certificate
  • Verifiable Certificate of Completion. Certificate does not expire.
  • 3 exam attempts
  • Progress saved to your account on every slide
Buying for a team? Volume pricing from 5 seats
1 to 4 seatsList price
5 to 10 seats15% off
11 to 20 seats25% off
21 or more seats35% off

$250.75

5 × $50.15 · save $44.25

Each seat is a single-use code. Send one to each learner; they sign in with their own account and earn their own certificate. Track progress on your Team page.

About this course

The person who causes the most damage to a defense supplier is often already inside: an employee, a contractor or a trusted partner with a badge and a login. Sometimes they mean harm. More often they are careless, pressured or tricked. This course teaches you what an insider threat is, what the early signs look like, why the controls you live with every day exist, and how to report a concern in a way that protects everyone, including the person you are worried about.

You will learn the difference between malicious, negligent and compromised insiders, why controlled unclassified information and export-controlled data make defense suppliers a target for foreign intelligence and competitors, and what NIST SP 800-171 Rev 2 requirement 3.2.3 and the CMMC Awareness and Training domain expect of you. The indicators module covers behavioural and technical warning signs and the equally important caution against profiling or acting on a single sign.

The controls module explains least privilege, separation of duties, access reviews, onboarding and offboarding, removable media rules, monitoring and acceptable use, so that you understand them as protection rather than friction. The reporting module tells you whom to tell, what to include, how confidentiality and non-retaliation work, and walks through realistic scenarios with a decision in each.

This is awareness-level training for every employee of a company that handles federal contract information or CUI. It does not replace the insider threat training that cleared facilities must provide under the NISPOM, and it is not legal advice; follow your company's procedures and your security officer. The course closes with a 10-question examination drawn from a bank of 20. On passing you receive a PlanetISO Certificate of Completion with lifetime access. The certificate does not expire.

What you will be able to do

  • Define insider threat and distinguish malicious, negligent and compromised insiders with examples from a defense supplier.
  • Explain why CUI and export-controlled data make insiders valuable to foreign intelligence services and competitors.
  • State what NIST SP 800-171 Rev 2 requirement 3.2.3 and the CMMC Awareness and Training domain require.
  • Recognise behavioural and technical indicators of potential insider threat and explain why no single sign is proof.
  • Describe the purpose of least privilege, separation of duties, access reviews, offboarding, removable media rules and monitoring.
  • Report a concern through the correct path with the right facts, and explain how confidentiality and non-retaliation apply.

Course outline

  1. 1

    What an insider threat is

    Malicious, negligent and compromised insiders; why CUI and export-controlled data make them valuable; and the requirement in NIST SP 800-171 Rev 2 3.2.3 and CMMC.

    About 20 minutes, then a module quiz

  2. 2

    Indicators: what to notice

    Behavioural and technical indicators of potential insider threat, how they combine, and the caution against profiling or acting on a single sign.

    About 20 minutes, then a module quiz

  3. 3

    The controls you live with and why

    Least privilege, separation of duties, access reviews, onboarding and offboarding, removable media rules, monitoring and acceptable use, explained as protection rather than friction.

    About 20 minutes, then a module quiz

  4. 4

    Reporting a concern

    Whom to tell, what to include, how confidentiality and non-retaliation work, how reporting links to the company's DoD obligations, and scenarios with a decision in each.

    About 25 minutes, then a module quiz

  5. Final examination and certificate

    10 questions drawn from the course bank. Score 70% or higher to receive your Certificate of Completion.

  • CMMC and NIST SP 800-171Short course

    CMMC Level 2 and NIST SP 800-171 Overview

    What a Level 2 assessment expects, how the 110 requirements are organized and how to build a program that passes

    Duration
    3 hours
    Level
    Foundation
    $99
    View course
  • CMMC and NIST SP 800-171Awareness

    Phishing and Email Security

    Spot the message that is trying to trick you, and know exactly what to do next

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    Social Engineering Prevention

    Recognize manipulation in person, on the phone and online, and verify before you act

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    CUI Handling and Marking

    Recognize controlled unclassified information, mark it correctly and handle it safely

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    CMMC Level 1 Overview

    The 15 basic safeguards for federal contract information and how the annual self-assessment works

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course