Awareness and Training (PR.AT) – NIST Cybersecurity Framework 1.1
NIST Cybersecurity Framework 1.1 PR.AT-3: PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities. PROTECT (PR) Function, Awareness and Training (PR.AT) Category. Outcome in the Framework Core of Version 1.1; withdrawn in CSF 2.0 (incorporated into PR.AT-01, PR.AT-02).
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind