“Cybersecurity Computer-Based Training and Technical Communication Design”
by Lysandwr McNary | Xchanges 9.2
Background
Per the United States Government Office of Management and Budget (OMB), which ensures that all agency reports and rules are consistent with Administration policies, FISMA requires all employees of federal agencies and affiliated civilian entities to have information awareness training. The OMB further defines information systems as “a discrete set of information resources organized for the collection, process, maintenance, transmission, and dissemination of information, in accordance with defined procedures, whether automated or manual” (OMB Memo 12.20.2012). This training must initially occur prior to employee access to federal agency information systems, and then annually with additional training provided should duties change or increase (OMB Memo 07-16). Significantly, the OMB Memorandum language specifically notes that “both initial and refresher training must include acceptable rules of behavior and the consequences when the rules are not followed.”
FISMA requires that all federal entities develop and implement “an agency-wide information security program that includes security awareness training to inform personnel, including contractors and other users of information systems that support the operations and assets of the agency, of: (a) information security risks associated with their activities; and (b) their responsibilities in complying with agency policies and procedures designed to reduce these risks” (Department of Homeland Security, 2012). The primary entity tasked with providing guidance on cybersecurity training requirements, including that of information assurance/awareness, is the National Institute of Standards and Technology (NIST, Computer Security Division, 2012).
Cybersecurity information assurance training is defined by NIST as belonging to either Tier 1 (General Security Awareness) — the information assurance/awareness “basics and literacy” required for all employees with access to federal information systems — or Tier 2, required for employees with higher level involvement in implementing cybersecurity (NIST, Computer Security Division, 2012).
In order to standardize this training and ensure that products maintain the skills and competencies required, four Information Systems Security Line of Business Security and Awareness Training Shared Service Centers have been recognized to provide sources of approved training products that meet FISMA/NIST requirements and guidelines for both Tier 1 and Tier 2. Each of these four Security Awareness Training Shared Service Centers has a sponsoring agency: the Department of State, the Department of Defense (DoD), the United States Office of Personnel Management, and the Department of Veterans Affairs.

In determining what metrics to apply in this examination, the annual FISMA compliance reporting requirements mandated by the OMB and DHS were reviewed. Federal agencies and other interacting entities such as civilian contractors must presently report whether or not their information assurance/awareness training addresses phishing, remote access, Web 2.0 technologies, and Peer-to-Peer technologies. DHS notes that the desired results of successful completion of “cybersecurity awareness training” are that users will understand and avoid risky or negative behavior, will always maintain safe practices in the information environment, and will — to best of their abilities — take steps to increase the security of their information environments during normal work day situations.
NIST Special Publication (SP) 800-16, on Information Security Training Requirements, expands on Tier 1 “awareness training.” The Security Basics and Literacy level for Tier 1 objectives includes ensuring users understand core information security concepts, promoting personal responsibility and positive behavioral change, and offering an information security awareness training curriculum framework to promote consistency across government.

Technical Communication (TC) Best Practices
The following design principles and best practices were drawn from research studies as well as curricula and syllabi of Technical Communication degree and certificate programs across the United States (Appendix A). Special attention was paid to New Mexico Institute of Mining and Technology, University of Texas at San Antonio, and Missouri University of Science and Technology — all three are designated National Centers of Academic Excellence in Information Assurance Education by the NSA and DHS.
- Audience Awareness — Who will be taking the course and how will they apply it to their jobs? How well does the course maintain credibility and value to the trainee? Does the learner feel included or overlooked (Paretti, 2006)?
- User Centered Design — How will users access the information and how much control over the format and pathway do they have? What tasks will they perform in the course of the module, to what desired outcome? How interactive is the training (Fisher, 2000)?
- Navigation — How does the framework (the information architecture and linear/non-linear construction aspects) affect the users in their choices? Are the desired learning outcomes supported?
- Visual Design / Rhetoric — Eye tracking, color use, white/negative space and grouping, font selection (Williams, 2000; Russell, 2005; Anderson, 278-282; Chaparro et al., 2004, 2005).
- Audio-Visual — Is the user effectively included, without causing overload to information processing capabilities and in such a way as to increase information retention (Anderson, 250-265)?
- Game Theory / Virtual World — Are competition (with self), rewards, and “entertainment value” used to add credibility and increase effectiveness of behavioral change (Araki, 2008)?
- Accessibility — Has usability on common systems been addressed, and is the module Americans with Disabilities Act compliant (508 ADA)?
