Skip to main content

πŸ’Ό PR.AT-02: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

  • Contextual name: πŸ’Ό PR.AT-02: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • ID: /frameworks/nist-csf-v2.0/pr-at/02
  • Located in: πŸ’Ό Awareness and Training (PR.AT)

Description​

  1. Identify the specialized roles within the organization that require additional cybersecurity training, such as physical and cybersecurity personnel, finance personnel, senior leadership, and anyone with access to business-critical data
  2. Provide role-based cybersecurity awareness and training to all those in specialized roles, including contractors, partners, suppliers, and other third parties
  3. Periodically assess or test users on their understanding of cybersecurity practices for their specialized roles
  4. Require annual refreshers to reinforce existing practices and introduce new practices

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-at/02
    • /frameworks/nist-csf-v1.1/pr-at/03
    • /frameworks/nist-csf-v1.1/pr-at/04
    • /frameworks/nist-csf-v1.1/pr-at/05
    • /frameworks/nist-sp-800-53-r5/at/03

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-2: Privileged users understand their roles and responsibilities
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-4: Senior executives understand their roles and responsibilities
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AT-5: Physical and cybersecurity personnel understand their roles and responsibilities
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AT-3 Role-based Training5

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags