Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: AT-FAMILY: AWARENESS AND TRAINING

AT-2 SECURITY AWARENESS TRAINING

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

AT-2

SECURITY AWARENESS TRAINING

 

assessment objective:

Determine if the organization:

at-2(a)

provides basic security awareness training to information system users (including managers, senior executives, and contractors) as part of initial training for new users;

at-2(b)

provides basic security awareness training to information system users (including managers, senior executives, and contractors) when required by information system changes; and

at-2(c)

at-2(c)[1]

defines the frequency to provide refresher security awareness training thereafter to information system users (including managers, senior executives, and contractors); and

at-2(c)[2]

provides refresher security awareness training to information users (including managers, senior executives, and contractors) with the organization-defined frequency.

potential assessment methods and objects:

Examine: [select from: Security awareness and training policy; procedures addressing security awareness training implementation; appropriate codes of federal regulations; security awareness training curriculum; security awareness training materials; security plan; training records; other relevant documents or records].

Interview: [select from: Organizational personnel with responsibilities for security awareness training; organizational personnel with information security responsibilities; organizational personnel comprising the general information system user community].

Test: [select from: Automated mechanisms managing security awareness training].

 

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056