
NIST Cybersecurity Professional®
(NCSP®) 800-115 Awareness Certificate
Build Awareness of NIST SP 800‑115: Information Security Testing & Assessment

NIST Cybersecurity Professional®
(NCSP®) 800-115 Awareness Certificate
Course Description
NIST Special Publication 800‑115, Technical Guide to Information Security Testing and Assessment, provides a structured methodology for planning, executing, and reporting on security testing activities, including vulnerability assessments, penetration testing, and security audits. It helps organisations evaluate the effectiveness of security controls and identify weaknesses before they can be exploited.
The NIST Cybersecurity Professional® (NCSP®) 800‑115 Awareness Certificate is a half‑day, instructor‑led course offering a concise introduction to the purpose, structure, and strategic value of NIST SP 800‑115. Designed for executives, managers, system owners, and stakeholders, this course explains how security testing supports risk management, compliance, and continuous improvement, without requiring hands‑on technical testing skills.
Participants gain a high‑level understanding of testing methodologies, assessment types, organisational responsibilities, and how 800‑115 integrates with CSF 2.0, RMF (800‑37), 800‑53, and broader cybersecurity assurance frameworks.
What You Will Learn
Participants gain essential awareness‑level knowledge of NIST SP 800‑115. You will learn:
-
The purpose, scope, and structure of the NIST Technical Guide to Information Security Testing.
-
The major types of security assessments, including testing, examination, and interviewing.
-
The phases of the NIST testing methodology: planning, execution, and post‑testing activities.
-
How vulnerability assessments and penetration tests support risk‑based decision‑making.
-
Organisational roles and responsibilities in security testing and assurance.
-
How 800‑115 aligns with CSF 2.0, RMF, 800‑53, and continuous monitoring programmes.
Course Agenda
Module 1: Introduction to NIST SP 800‑115 & Security Testing Fundamentals
Module 2: Security Assessment Types & Testing Methodologies
Module 3: Roles, Responsibilities & Governance for Security Testing
Module 4: Applying NIST 800‑115 in Practice - Alignment, Use Cases & Continuous Improvement
Learning Outcomes
Participants will be able to:
-
Describe the purpose and structure of NIST SP 800‑115.
-
Explain the major types of security assessments.
-
Understand the phases of the NIST testing methodology.
-
Recognise key roles and responsibilities in security testing governance.
-
Identify how 800‑115 aligns with CSF 2.0, RMF, 800‑53, and assurance frameworks.
-
Communicate the strategic value of security testing to stakeholders and teams.
Who Should Attend?
This course is designed for professionals who need a foundational understanding of security testing and assessment, including:
-
Executives & Senior Leaders
-
Business & System Owners
-
Governance, Risk & Compliance (GRC) Stakeholders
-
Programme & Project Managers
-
Security & Privacy Managers
-
Anyone seeking an introduction to security testing principles
Prerequisites
There are no prerequisites for this Awareness‑level course. No technical testing background is required.
Participants are provided with:
-
NIST Cybersecurity Professional® (NCSP®) 800-115 Awareness Certificate courseware including links to further reading and resources.
-
NIST Cybersecurity Professional® (NCSP®) 800-115 Awareness Certificate, Certificate of Completion.
-
NIST Cybersecurity Professional® (NCSP®) 800-115 Awareness Certificate digital badge.
Enrol Today
This NIST Cybersecurity Professional® (NCSP®) 800‑115 Awareness course provides students with a high‑level understanding of NIST security testing and assessment methods.

Further Reading
NIST 800-115 - Technical Guide to Information Security Testing and Assessment
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf