Skip to main content

💼 PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

  • ID: /frameworks/nist-csf-v2.0/pr-at/01

Description

  1. Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources
  2. Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials)
  3. Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole
  4. Periodically assess or test users on their understanding of basic cybersecurity practices
  5. Require annual refreshers to reinforce existing practices and introduce new practices

Similar

  • Sections
    • /frameworks/nist-csf-v1.1/pr-at/01
    • /frameworks/nist-csf-v1.1/pr-at/03
    • /frameworks/nist-csf-v1.1/rs-co/01
    • /frameworks/nist-sp-800-53-r5/at/02
    • /frameworks/nist-sp-800-53-r5/at/03

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 PR.AT-1: All users are informed and trained77no data
💼 NIST CSF v1.1 → 💼 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilitiesno data
💼 NIST CSF v1.1 → 💼 RS.CO-1: Personnel know their roles and order of operations when a response is needed1no data
💼 NIST SP 800-53 Revision 5 → 💼 AT-2 Literacy Training and Awareness6no data
💼 NIST SP 800-53 Revision 5 → 💼 AT-3 Role-based Training5no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (8)

PolicyLogic CountFlagsCompliance
🛡️ Azure Subscription Microsoft Defender For (Managed Instance) Azure SQL Databases is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For App Services is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Containers is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Key Vault is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Servers is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For SQL Servers On Machines is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Storage is not set to On🟢1🟢 x6no data
🛡️ Google Organization Essential Contacts is not configured🟢1🟢 x6no data