πΌ AT-2 Literacy Training and Awareness
- Contextual name: πΌ AT-2 Literacy Training and Awareness
- ID:
/frameworks/nist-sp-800-53-r5/at/02
- Located in: πΌ AT Awareness And Training
Descriptionβ
a. Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):
- As part of initial training for new users and [Assignment: organization-defined frequency] thereafter; and
- When required by system changes or following [Assignment: organization-defined events]; b. Employ the following techniques to increase the security and privacy awareness of system users [Assignment: organization-defined awareness techniques]; c. Update literacy training and awareness content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and d. Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
Similarβ
- Internal
- ID:
dec-c-71d48d29
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ AT-2 Literacy Training and Awareness (L)(M)(H) | 2 | |||
πΌ FedRAMP Low Security Controls β πΌ AT-2 Literacy Training and Awareness (L)(M)(H) | 1 | |||
πΌ NIST CSF v2.0 β πΌ PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind | 7 |