NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 126 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 11 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

NIST SP 800-53 Rev 5 · 11 controls

FedRAMP High · 10 controls

  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • PS-7 External Personnel Security
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))

FedRAMP Moderate · 10 controls

  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • PS-7 External Personnel Security
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))

PCI DSS 4.0 · 8 controls

  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.6.2 12.6.2 Awareness program reviewed annually and updated
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering
  • 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.2.2 6.2.2 Annual secure software training for developers
  • 9.5.1.3 9.5.1.3 Training for personnel in POI environments

ISO 27701:2019 · 6 controls

  • 5.5.2 Competence
  • 5.5.3 Awareness
  • 6.4 Human resource security
  • 6.4.2 During employment
  • 6.6.3 User responsibilities
  • 6.9.1 Operational procedures and responsibilities

HIPAA Security Rule · 5 controls

CMMC 2.0 · 4 controls

  • CCM-HRS-02 Acceptable Use of Technology Policy and Procedures
  • CCM-HRS-11 Security Awareness Training
  • CCM-HRS-12 Personal and Sensitive Data Awareness and Training
  • CCM-HRS-13 Compliance User Responsibility

ISO/IEC 42001:2023 · 4 controls

  • 7.2 Competence
  • 7.3 Awareness
  • A.4.6 Human resources
  • A.9.2 Processes for responsible use of AI systems
  • ISM-0252 Annual cyber security awareness training content
  • ISM-0735 Oversight of awareness training program
  • ISM-2022 Cyber security awareness training register
  • PR.AT-1 PR.AT-1: All users are informed and trained
  • PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand roles & responsibilities
  • RS.CO-1 RS.CO-1: Personnel know their roles and order of operations when a response is needed
  • PR.AT-1 PR.AT-1: All users are informed and trained
  • PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
  • RS.CO-1 RS.CO-1: Personnel know their roles and order of operations when a response is needed

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice

ISO 22301:2019 · 2 controls

ISO 27001:2022 · 2 controls

  • 6.3 Information security awareness, education and training
  • 8.7 Protection against malware

ISO 27002:2022 · 2 controls

  • 6.3 Information security awareness, education and training
  • 6.7 Remote working

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-181 · 2 controls

APPI · 1 control

APRA CPS 234 · 1 control

  • AUCDR-IS-6 Information security training and awareness program
  • AESCSF-WM-2 Training and awareness
  • AEO-10 Education, Training and Awareness

C2M2 · 1 control

  • WORKFORCE-2 Develop Cybersecurity Workforce and Awareness

C5 (Germany) · 1 control

  • C5-HR-03 Security training and awareness programme
  • ITSG33-AT Awareness and Training (AT)

DORA · 1 control

  • 03.02.01 Literacy Training and Awareness

NIST SP 800-172 · 1 control

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat

UK Cyber Essentials · 1 control

  • CE-SC.7 Educate Users on Strong Passwords

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AT-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 126 it maps to, and the evidence behind each claim, over MCP and REST.