Awareness and Training (AT)¶
Domain: Awareness and Training (AT)
Requirements in this domain: 3
Assessment Objectives in this domain: 9
AT.L2-3.2.1¶
AT.L2-3.2.1[a]¶
Assessment Objective
security risks associated with organizational activities involving CUI are identified.
Collection Approach: Document
Potential Evidence Examples
Security Awareness Training curriculum/briefing slides that explicitly call out the security risks tied to CUI-handling activities (e.g., phishing, improper CUI transmission, unlocked workstations) relevant to the organization's operations.
AT.L2-3.2.1[b]¶
Assessment Objective
policies, standards, and procedures related to the security of the system are identified.
Collection Approach: Document
Potential Evidence Examples
Acceptable Use Policy and the specific security policies/standards/procedures referenced in the training materials, showing the link between what the training teaches and the actual governing documents.
AT.L2-3.2.1[c]¶
Assessment Objective
managers, systems administrators, and users of the system are made aware of the security risks associated with their activities.
Collection Approach: Artifact
Potential Evidence Examples
Training completion records (LMS report, sign-in sheet, or completion certificates) showing all managers, system administrators, and users completed initial and annual/refresher security awareness training, dated and mapped to individuals.
Assessment Guide – Further Discussion
Do all users, managers, and system administrators receive initial and refresher training commensurate with their roles and responsibilities [c,d]?
AT.L2-3.2.1[d]¶
Assessment Objective
managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.
Collection Approach: Artifact
Potential Evidence Examples
Training completion records paired with the training content itself, demonstrating the material covers the organization's actual security policies/standards/procedures (not generic content) and that all applicable personnel completed it.
Assessment Guide – Further Discussion
- Do all users, managers, and system administrators receive initial and refresher training commensurate with their roles and responsibilities [c,d]?
- Do training materials identify the organizationally defined security requirements that must be met by users while interacting with the system as described in written policies, standards, and procedures [d]?
AT.L2-3.2.2¶
AT.L2-3.2.2[a]¶
Assessment Objective
information security-related duties, roles, and responsibilities are defined.
Collection Approach: Document
Potential Evidence Examples
Job/Position Description library or Roles & Responsibilities matrix that documents which roles carry information-security duties (e.g., ISSM, ISSO, system administrator, incident handler) and what each role is responsible for.
Assessment Guide – Further Discussion
Are the duties, roles, and responsibilities that impact, directly or indirectly, the information security of the company or its systems defined and documented [a]?
AT.L2-3.2.2[b]¶
Assessment Objective
information security-related duties, roles, and responsibilities are assigned to designated personnel.
Collection Approach: Artifact
Potential Evidence Examples
Screen share or org chart showing security-related roles are assigned to specific named individuals (e.g., AD group membership tied to the ISSO role, a signed role-assignment/appointment letter).
Assessment Guide – Further Discussion
Do information security-related tasks have accountable owners, and is a strictly limited group of individuals assigned to perform them [b]?
AT.L2-3.2.2[c]¶
Assessment Objective
personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities.
Collection Approach: Artifact
Potential Evidence Examples
Training records or certification evidence (e.g., Security+, CISSP, vendor-specific admin training) showing personnel assigned security duties received training specific to those duties, beyond general security-awareness training.
Assessment Guide – Further Discussion
Are personnel who are assigned information security-related duties, roles, and responsibilities trained on those responsibilities, including the security requirements unique or inherent to their roles or responsibilities [c]?
AT.L2-3.2.3¶
AT.L2-3.2.3[a]¶
Assessment Objective
potential indicators associated with insider threats are identified.
Collection Approach: Document
Potential Evidence Examples
Insider Threat training content/briefing that lists specific behavioral and technical indicators of insider threat (e.g., repeated access violations, unusual after-hours activity, large/unexplained data transfers, disgruntlement) rather than generic awareness language.
Assessment Guide – Further Discussion
Do training materials include potential indicators associated with insider threats (e.g., repeated security violations, unusual work hours, unexpected significant transfers of data, suspicious contacts, concerning behaviors outside the workplace) [a,b]?
AT.L2-3.2.3[b]¶
Assessment Objective
security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.
Collection Approach: Artifact
Potential Evidence Examples
Training completion records showing all managers and employees completed insider-threat-specific training, and training content confirming it includes how/where to report a suspected insider-threat indicator (e.g., hotline, ISSO, HR).
Assessment Guide – Further Discussion
- Do training materials include potential indicators associated with insider threats (e.g., repeated security violations, unusual work hours, unexpected significant transfers of data, suspicious contacts, concerning behaviors outside the workplace) [a,b]?
- Do training materials include methods of reporting potential indicators of insider threats to management or responsible security personnel [b]?