Skip to content

Awareness and Training (AT)

AT.L2-3.2.1 – Role-Based Risk Awareness

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

Assessment Objectives

Source: NIST SP 800-171A, p. 19.

Determine if:

  • [a] security risks associated with organizational activities involving CUI are identified;
  • [b] policies, standards, and procedures related to the security of the system are identified;
  • [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities; and
  • [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 19.

Examine: [SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; relevant codes of federal regulations; security awareness training curriculum; security awareness training materials; system security plan; training records; other relevant documents or records].

Interview: [SELECT FROM: Personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel composing the general system user community; personnel with responsibilities for role-based awareness training].

Test: [SELECT FROM: Mechanisms managing security awareness training; mechanisms managing role-based security training].

Discussion

Source: NIST SP 800-171 Rev. 2, pp. 16-17.

Organizations determine the content and frequency of security awareness training and security awareness techniques based on the specific organizational requirements and the systems to which personnel have authorized access. The content includes a basic understanding of the need for information security and user actions to maintain security and to respond to suspected security incidents. The content also addresses awareness of the need for operations security. Security awareness techniques include: formal training; offering supplies inscribed with security reminders; generating email advisories or notices from organizational officials; displaying logon screen messages; displaying security awareness posters; and conducting information security awareness events. NIST SP 800-50 provides guidance on security awareness and training programs.

Further Discussion

Awareness training focuses user attention on security. Several techniques can be used, such as:

  • synchronous or asynchronous training;
  • simulations (e.g., simulated phishing emails);
  • security awareness campaigns (posters, reminders, group discussions); and
  • communicating regular email advisories and notices to employees.

Awareness training and role-based training are different. This requirement, AT.L2-3.2.1, covers awareness training, which provides general security training to influence user behavior. This training can apply broadly or be tailored to a specific role. Role-based training focuses on the knowledge, skills, and abilities needed to complete a specific job and is covered by AT.L2-3.2.2.

Examples

  • Your organization holds a DoD contract which requires the use of CUI. You want to provide information to employees so they can identify phishing emails. To do this, you prepare a presentation that highlights basic traits, including:

  • suspicious-looking email address or domain name;

  • a message that contains an attachment or URL; and
  • a message that is poorly written and often contains obvious misspelled words.

You encourage everyone to not click on attachments or links in a suspicious email [c]. You tell employees to forward such a message immediately to IT security [d]. You download free security awareness posters to hang in the office [c,d]. You send regular emails and tips to all employees to ensure your message is not forgotten over time [c,d].

Potential Assessment Considerations

  • Do all users, managers, and system administrators receive initial and refresher training commensurate with their roles and responsibilities [c,d]?
  • Do training materials identify the organization-defined security requirements that must be met by users while interacting with the system as described in written policies, standards, and procedures [d]?

Key References

  • NIST SP 800-171 Rev. 2 3.2.1

AT.L2-3.2.2 – Role-Based Training

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

Assessment Objectives

Source: NIST SP 800-171A, pp. 19-20.

Determine if:

  • [a] information security-related duties, roles, and responsibilities are defined;
  • [b] information security-related duties, roles, and responsibilities are assigned to designated personnel; and
  • [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, pp. 19-20.

Examine: [SELECT FROM: Security awareness and training policy; procedures addressing security training implementation; codes of federal regulations; security training curriculum; security training materials; system security plan; training records; other relevant documents or records].

Interview: [SELECT FROM: Personnel with responsibilities for role-based security training; personnel with assigned system security roles and responsibilities; personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel representing the general system user community].

Test: [SELECT FROM: Mechanisms managing role-based security training; mechanisms managing security awareness training].

Discussion

Source: NIST SP 800-171 Rev. 2, p. 17.

Organizations determine the content and frequency of security training based on the assigned duties, roles, and responsibilities of individuals and the security requirements of organizations and the systems to which personnel have authorized access. In addition, organizations provide system developers, enterprise architects, security architects, acquisition/procurement officials, software developers, system developers, systems integrators, system/network administrators, personnel conducting configuration management and auditing activities, personnel performing independent verification and validation, security assessors, and other personnel having access to system-level software, security-related technical training specifically tailored for their assigned duties. Comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls. Such training can include policies, procedures, tools, and artifacts for the security roles defined. Organizations also provide the training necessary for individuals to carry out their responsibilities related to operations and supply chain security within the context of organizational information security programs. NIST SP 800-181 provides guidance on role-based information security training in the workplace. SP 800-161 provides guidance on supply chain risk management.

Further Discussion

Training imparts skills and knowledge to enable staff to perform a specific job function. Training should be available to all employees for all organizational roles to accommodate role changes without being constrained by the training schedule. Awareness training and role-based training are different. Awareness training provides general security training to influence user behavior and is covered by AT.L2-3.2.1. This requirement, AT.L2-3.2.2, covers role-based training that focuses on the knowledge, skills, and abilities needed to complete a specific job. Role-based training may include awareness topics specific to individual roles such as ensuring systems administrators understand the risk associated with using an administrative account.

Examples

  • Your company upgraded the firewall to a newer, more advanced system to protect the CUI it stores. You have been identified as an employee who needs training on the new device [a,b,c]. This will enable you to use the firewall effectively and efficiently. Your company considered training resources when it planned for the upgrade and ensured that training funds were available as part of the upgrade project [c].

Potential Assessment Considerations

  • Are the duties, roles, and responsibilities that impact, directly or indirectly, the information security of the company or its systems defined and documented [a]?
  • Do information security-related tasks have accountable owners, and is a strictly limited group of individuals assigned to perform them [b]?
  • Are personnel who are assigned information security-related duties, roles, and responsibilities trained on those responsibilities, including the security requirements unique or inherent to their roles or responsibilities [c]?

Key References

  • NIST SP 800-171 Rev. 2 3.2.2

AT.L2-3.2.3 – Insider Threat Awareness

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Assessment Objectives

Source: NIST SP 800-171A, p. 20.

Determine if:

  • [a] potential indicators associated with insider threats are identified; and
  • [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 20.

Examine: [SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; security awareness training curriculum; security awareness training materials; insider threat policy and procedures; system security plan; other relevant documents or records].

Interview: [SELECT FROM: Personnel that participate in security awareness training; personnel with responsibilities for basic security awareness training; personnel with information security responsibilities].

Test: [SELECT FROM: Mechanisms managing insider threat training].

Discussion

Source: NIST SP 800-171 Rev. 2, p. 17.

Potential indicators and possible precursors of insider threat include behaviors such as: inordinate, long-term job dissatisfaction; attempts to gain access to information that is not required for job performance; unexplained access to financial resources; bullying or sexual harassment of fellow employees; workplace violence; and other serious violations of the policies, procedures, directives, rules, or practices of organizations. Security awareness training includes how to communicate employee and management concerns regarding potential indicators of insider threat through appropriate organizational channels in accordance with established organizational policies and procedures. Organizations may consider tailoring insider threat awareness topics to the role (e.g., training for managers may be focused on specific changes in behavior of team members, while training for employees may be focused on more general observations).

Further Discussion

An insider threat is the threat that an insider will use their authorized access, wittingly or unwittingly, to do harm. Insider threat security awareness training focuses on recognizing employee behaviors and characteristics that might be indicators of an insider threat and the guidelines and procedures to handle and report it. Training for managers will provide guidance on observing team members to identify all potential threat indicators, while training for general employees will provide guidance for focusing on a smaller number of indicators. Employee behaviors will vary depending on roles, team membership, and associated information needs. The person responsible for specifying insider threat indicators must be cognizant of these factors. Because of this, organizations may choose to tailor the training for specific roles. This requirement does not require separate training regarding insider threat. Organizations may choose to integrate these topics into their standard security awareness training programs.

Examples

  • You are responsible for training all employees on the awareness of high-risk behaviors that can indicate a potential insider threat [b]. You educate yourself on the latest research on insider threat indicators by reviewing a number of law enforcement bulletins [a]. You then add the following example to the training package: A baseline of normal behavior for work schedules has been created. One employee’s normal work schedule is 8:00 AM–5:00 PM, but another employee noticed that the employee has been working until 9:00 PM every day even though no projects requiring additional hours have been assigned [b]. The observing employee reports the abnormal work schedule using the established reporting guidelines.

Potential Assessment Considerations

  • Do training materials include potential indicators associated with insider threats (e.g., repeated security violations, unusual work hours, unexpected significant transfers of data, suspicious contacts, concerning behaviors outside the workplace) [a,b]?
  • Do training materials include methods of reporting potential indicators of insider threats to management or responsible security personnel [b]?

Key References

  • NIST SP 800-171 Rev. 2 3.2.3