Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.AT-01 What else in your programme already covers this This control maps to 126 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-14.1 Establish and Maintain a Security Awareness Program CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks CIS-14.3 Train Workforce Members on Authentication Best Practices CIS-14.4 Train Workforce on Data Handling Best Practices CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training CIS-16.9 Train Developers in Application Security Concepts and Secure Coding CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents AT-2 Literacy Training and Awareness AT-2(2) Insider Threat AT-2(3) Social Engineering and Mining AT-3 Role-Based Training AT-4 Training Records CP-3 Contingency Training IR-9(2) Information Spillage Response | Training (IR-9(2)) PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1)) PS-7 External Personnel Security SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1)) AT-2 Literacy Training and Awareness AT-2(2) Insider Threat AT-2(3) Social Engineering and Mining AT-3 Role-Based Training AT-4 Training Records CP-3 Contingency Training IR-9(2) Information Spillage Response | Training (IR-9(2)) PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1)) PS-7 External Personnel Security SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1)) 12.10.4 12.10.4 Periodic training for incident response personnel 12.6.2 12.6.2 Awareness program reviewed annually and updated 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies 5.4.1 5.4.1 Mechanisms detect and protect against phishing 6.2.2 6.2.2 Annual secure software training for developers 9.5.1.3 9.5.1.3 Training for personnel in POI environments 5.5.2 Competence 5.5.3 Awareness 6.4 Human resource security 6.4.2 During employment 6.6.3 User responsibilities 6.9.1 Operational procedures and responsibilities CCM-HRS-02 Acceptable Use of Technology Policy and Procedures CCM-HRS-11 Security Awareness Training CCM-HRS-12 Personal and Sensitive Data Awareness and Training CCM-HRS-13 Compliance User Responsibility 7.2 Competence 7.3 Awareness A.4.6 Human resources A.9.2 Processes for responsible use of AI systems ISM-0252 Annual cyber security awareness training content ISM-0735 Oversight of awareness training program ISM-2022 Cyber security awareness training register PR.AT-1 PR.AT-1: All users are informed and trained PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand roles & responsibilities RS.CO-1 RS.CO-1: Personnel know their roles and order of operations when a response is needed PR.AT-1 PR.AT-1: All users are informed and trained PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities RS.CO-1 RS.CO-1: Personnel know their roles and order of operations when a response is needed SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4) SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) ANSSI-HYG-01 Train Operational Teams in Information System Security ANSSI-HYG-02 Raise User Awareness of Basic Security Practice 6.3 Information security awareness, education and training 8.7 Protection against malware 6.3 Information security awareness, education and training 6.7 Remote working Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis Art.21.2.g Basic cyber hygiene practices and cybersecurity training AWWA-1.3 Security Awareness and Training AUCDR-IS-6 Information security training and awareness program AESCSF-WM-2 Training and awareness AEO-10 Education, Training and Awareness BMA-17 Staff Cyber Risk Awareness Training WORKFORCE-2 Develop Cybersecurity Workforce and Awareness C5-HR-03 Security training and awareness programme ITSG33-AT Awareness and Training (AT) 03.02.01 Literacy Training and Awareness 3.2.1e Provide Awareness Training on Advanced Persistent Threat CE-SC.7 Educate Users on Strong Passwords Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AT-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 126 it maps to, and the evidence behind each claim, over MCP and REST.