Agencies should make sure their information security awareness and training covers: (1) why the training or awareness programme exists; (2) mandates and requirements arising from legislation or regulation; (3) mandates and requirements from national or agency policy; (4) the agency's security appointments and contact points; (5) legitimate use of classified information, software and system accounts; (6) account security, shared passwords included; (7) what authorisation is required for applications, databases and data; (8) the security risks of systems not owned by the agency, the Internet in particular; (9) reporting of any suspected compromise or anomaly; (10) what must be reported, and how, for information security incidents, suspected compromises or anomalies; (11) the classification, marking, control, storage and sanitisation of media; (12) guarding workstations against unauthorised access; (13) telling the support section once a person no longer needs access to a system; (14) observing the rules and regulations that govern authorised use and secure operation of systems; and (15) supporting documents such as SOPs and user guides.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.