Skip to main content

πŸ’Ό PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

  • Contextual name: πŸ’Ό PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • ID: /frameworks/nist-csf-v2.0/pr-at/01
  • Located in: πŸ’Ό Awareness and Training (PR.AT)

Description​

  1. Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources
  2. Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials)
  3. Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole
  4. Periodically assess or test users on their understanding of basic cybersecurity practices
  5. Require annual refreshers to reinforce existing practices and introduce new practices

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-at/01
    • /frameworks/nist-csf-v1.1/pr-at/03
    • /frameworks/nist-csf-v1.1/rs-co/01
    • /frameworks/nist-sp-800-53-r5/at/02
    • /frameworks/nist-sp-800-53-r5/at/03

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-1: All users are informed and trained77
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.CO-1: Personnel know their roles and order of operations when a response is needed
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AT-2 Literacy Training and Awareness6
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AT-3 Role-based Training5

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (7)​

PolicyLogic CountFlags
πŸ“ Azure Subscription Microsoft Defender For (Managed Instance) Azure SQL Databases is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For App Services is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Containers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Key Vault is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Servers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For SQL Servers On Machines is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Storage is not set to On 🟒1🟒 x6