Training catalogue
Eleven courses, each citing named controls from the framework it covers. Coverage is selective, not framework-wide.
Scenario Lab
Put every course into practice in real-life situations
Sixty-one hands-on scenarios — one for every module of every course — so students can touch and feel the relevance of what they learn. Every scenario carries an AI governance angle, and each course closes with a governed response in the ai.heart canon: eight layers, a verdict, Node 9 and an append-only audit trail.
BY-BX1
PractitionerGoverning AI: Duties of Boards
What the system refuses, what it permits, and how it behaves in between
The only course here that cites its own framework rather than someone else’s. It sets out the doctrine the ai.heart floor is built from — one life is infinity, strive then trust, and the three verdict states — and maps every clause to a named construct in the running system so a reviewer can check it rather than take it on faith.
BY-G1
FoundationPSPF 2026 Fundamentals
Recognise contacts, risks and incident reporting pathways
Build foundation awareness of PSPF Release 2026 security responsibilities, including contacts, foreign interference and incident response. The course supports personnel to notice, report and escalate concerns through agency processes.
BY-G3
FoundationProtective Markings
Apply protective markings with consistent judgement
Build practical understanding of how protective markings are chosen, recorded and applied across documents, systems and email. The course is mapped to PSPF Section 09 and the Email Protective Marking Standard.
BY-GX3
FoundationEmail Protective Marking
Apply email protective markings correctly
Build foundation capability in applying Australian Government email protective marking syntax to email subjects, bodies, attachments and metadata. Learn how to choose values, resolve system differences, and understand tool limits.
BY-G7
FoundationFraud Prevention
Apply layered fraud prevention and measurement
Build foundation capability in layered fraud prevention using IPSFF measurement-scoped concepts. Learn how FRA, FLM, conduct, data and AI support better control decisions.
BY-G2
PractitionerISM 2026
Apply ISM governance controls in practice
This 60-minute practitioner course builds capability in ISM accountability, training, policy and reporting controls. It also covers selected June 2026 changes and secure building practices for information security roles.
BY-G4
PractitionerPersonnel Security
Make sound personnel security access decisions
Build practitioner capability to apply personnel security concepts across suitability, clearances, need-to-know and ongoing assurance. The course is mapped to PSPF personnel security requirements and the Personnel Security Adjudicative Standard 2026.
BY-G5
PractitionerAI Governance in Government Systems
Govern AI systems with accountable human oversight
Build practical capability to govern AI use in government systems. The course is mapped to the ISM AI control set, GOV-08 and the PSPF recommended approach to AI training.
BY-GX1
PractitionerGateway Security
Govern gateway controls with evidence and risk ownership
Build capability to govern gateway security across domains. Learn how requirements, risk ownership, evidence and assurance support gateways aligned to the PSPF Gateway Security Standard.
BY-GX2
PractitionerHosting Certification
Apply hosting certification decisions before procurement
Learn to apply hosting certification requirements before procurement. Build capability to assess workloads, assurance, certification level, ongoing change, and contract boundaries.
BY-G6
AdvancedCyber Resilience & Critical Infrastructure
Authorise resilient technology and cryptography decisions
Build advanced capability to authorise technology, manage shared risk information, and plan post-quantum transition activities. The course is mapped to PSPF Sec 13-15 TECH domain expectations and ISM cryptography guidance.
How training works
Choose modules, assign learners and track completion through straightforward reporting for internal oversight.
Choose by topic
Pick the courses covering the topics your people need. Each course lists the specific controls it cites; none covers a framework end to end.
Complete governed modules
Staff complete short modules, knowledge checkpoints and a governed tutorial scenario to build capability and support consistent judgement.
Keep the record
Receive completion records and the list of controls each course cited. This is a training record, not assurance evidence and not an assessment.
Content assurance
Materials are reviewed for currency and mapped to relevant legislation, standards and organisational policy settings.
What these courses do
Each course is written against named source documents and cites specific control or requirement identifiers. Every citation is listed on the course page so a reviewer can check it against the source.
Courses build capability: they help staff recognise obligations, apply the right handling, and escalate correctly.
What these courses do not do
They do not discharge a legal or policy obligation, and they are not accredited, endorsed or approved by any Commonwealth entity. BestYou·AI is a private provider.
Where a framework is only partly covered, the course says so on its page rather than implying full coverage.
