The Law That Made People the Perimeter
- DMS

- Jul 7
- 3 min read
A standard with a paper trail
The National Institute of Standards and Technology (NIST) published the original SP 800-50, "Building an Information Technology Security Awareness and Training Program," in October 2003. Its abstract states plainly that it supports requirements in the Federal Information Security Management Act (FISMA) of 2002 and OMB Circular A-130, Appendix III. Its focus is on the human element of cyber threats.
FISMA was enacted as Title III of the E-Government Act of 2002, Public Law 107-347, signed December 17, 2002. It assigns NIST the job of developing federal information-security standards and requires every agency program to include security awareness training for personnel and contractors. NIST's earlier statutory mandate to issue computer-security guidance derives from the Computer Security Act of 1987. Congress, not a sitting president, put workforce training on the books.
Executive Orders 13800 and 14028 are landscape, not legal basis. The authority is the statute.
Why the 2024 rewrite happened in the open
On September 12, 2024, NIST replaced the 2003 document with SP 800-50 Revision 1, "Building a Cybersecurity and Privacy Learning Program." It also withdrew the 1998 SP 800-16 and stopped developing that companion's third public draft, folding role-based training into a single guide.
NIST did not write this behind closed doors. It released an initial public draft on August 28, 2023, took comments through October 27, 2023, then adjudicated them and published the final on September 12, 2024. That open cycle is why the guidance carries weight. It survived scrutiny before it became authoritative.
What Revision 1 actually asks for
Revision 1 integrates privacy with cybersecurity and treats training as a managed life-cycle program rather than an annual click-through. It defines four phases: Plan and Strategy, Analysis and Design, Development and Implementation, and Assessment and Improvement. The goal is behavior change measured by suggested metrics, not a completion checkbox.
It also abandons the old awareness, training, and education ladder. In its place, Revision 1 segments people by audience: all users, privileged access account holders, and those with significant cybersecurity or privacy responsibilities. The SP 800-53 AT control family supplies the auditable hooks. AT-2 covers literacy training for everyone, AT-3 covers role-based training for defined roles, and AT-4 covers the training records that prove it happened.
Why this is now an underwriting question
The threat data explains the urgency. Verizon's 2024 DBIR found that 68 percent of breaches involved a non-malicious human element across 10,626 confirmed breaches. The 2025 edition put that share near 60 percent, with about 22 percent of breaches beginning in credential abuse and about 16 percent in phishing.
Those attacks are expensive and slow to contain. IBM's 2024 report pegged the average breach at 4.88 million dollars, with stolen credentials the most common initial vector at 16 percent and the slowest to identify and contain, nearly 292 days. Insurers feel it firsthand. Coalition's 2024 report found that more than half of cyber claims originate in the email inbox, and its 2025 report tied roughly 60 percent of claims to business email compromise and funds-transfer fraud combined.
How DMS turns the standard into evidence
DMS is built directly on SP 800-50 Revision 1 and the AT control family. It runs quarterly training cycles, monthly phishing simulations, and role-based tracks. That means an all-staff core plus finance, executive, HR, and developer paths, and a privileged or IT access path that matches Revision 1's privileged-account audience.
Every employee earns a named certificate, and the platform keeps a rolling 12-month proof packet shaped for what carriers ask to see. The law made people the perimeter in 2002. The 2024 revision turned that requirement into a modern learning program built around roles, behavior change, privacy, metrics, and continuous improvement. DMS gives you the program that defends it, the records that prove you did, and training that keeps pace as new threats emerge where awareness is the first line of mitigation.
Sources: NIST CSRC (SP 800-50, SP 800-50 Rev. 1, SP 800-53) | Congress.gov and govinfo.gov (FISMA, Pub. L. 107-347) | Verizon 2024 and 2025 DBIR | IBM Cost of a Data Breach 2024 | Coalition Cyber Claims Report 2024 and 2025

Comments