ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-01: Train Operational Teams in Information System Security

Train the teams that operate the information system in security, covering security integration for project managers, secure development for developers and security frameworks for security officers, and require equivalent training of external providers by contract.

What else in your programme already covers this

This control maps to 45 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding
  • CCM-AIS-04 Secure Application Design and Development
  • CCM-HRS-11 Security Awareness Training
  • CCM-HRS-12 Personal and Sensitive Data Awareness and Training
  • CCM-STA-12 Supply Chain Service Agreement Compliance

ISO 27001:2022 · 4 controls

  • 5.20 Addressing information security within supplier agreements
  • 6.3 Information security awareness, education and training
  • 8.25 Secure development life cycle
  • 8.28 Secure coding
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

ISO 27002:2022 · 3 controls

  • 5.20 Addressing information security within supplier agreements
  • 6.3 Information security awareness, education and training
  • 8.25 Secure development life cycle

NIST SP 800-161 Rev 1 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.10.4 Incident responder training
  • 12.6.3 Security awareness training delivered
  • 6.2.2 Software development personnel working on bespoke and custom software are trained at least once every 12 months as follows: • On software security relevant to their job function and development languages. • Including secure

C5 (Germany) · 2 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-03 Security training and awareness programme

CMMC 2.0 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

APRA CPS 234 · 1 control

  • ASBv3-GS-10 Define and implement DevOps security strategy

FedRAMP High · 1 control

  • AT-3 Role-Based Training

FedRAMP Moderate · 1 control

  • AT-3 Role-Based Training

HIPAA Security Rule · 1 control

ISO/IEC 42001:2023 · 1 control

  • AT-3 Role-Based Training
  • AT-3 Role-Based Training
  • AT-3 Role-Based Training

SOC 2 · 1 control

  • SOC2-CC1.4 COSO principle 4: Demonstrates commitment to attract and retain competent individuals

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)

You are reading one control. How much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have you already done?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) your existing evidence covers. Hold FedRAMP Moderate and 35 of 42 ANSSI Guide d'hygiene informatique (42 mesures, v2.0) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.