NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AT-02: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 70 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

  • PR.AT-2 PR.AT-2: Privileged users understand roles & responsibilities
  • PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand roles & responsibilities
  • PR.AT-4 PR.AT-4: Senior executives understand roles & responsibilities
  • PR.AT-5 PR.AT-5: Physical and information security personnel understand roles & responsibilities
  • PR.AT-2 PR.AT-2: Privileged users understand their roles and responsibilities
  • PR.AT-3 PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
  • PR.AT-4 PR.AT-4: Senior executives understand their roles and responsibilities
  • PR.AT-5 PR.AT-5: Physical and cybersecurity personnel understand their roles and responsibilities

PCI DSS 4.0 · 4 controls

  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 6.2.2 6.2.2 Annual secure software training for developers
  • 9.5.1.3 9.5.1.3 Training for personnel in POI environments
  • ISM-0612 Formal training for gateway administrators
  • ISM-1565 Annual tailored privileged user training
  • ISM-2037 Secure development training for developers

FedRAMP High · 3 controls

FedRAMP Moderate · 3 controls

NIST SP 800-181 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • SEC11-BP01 Train for application security
  • SEC11-BP08 Build a program that embeds security ownership in workload teams

CIS Controls v8 · 2 controls

  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding

CMMC 2.0 · 2 controls

ISO 27001:2022 · 2 controls

  • 6.3 Information security awareness, education and training
  • 8.28 Secure coding

ISO 27701:2019 · 2 controls

ISO/IEC 42001:2023 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ASD37-37 Personnel management (Very Good)
  • AUCDR-IS-6 Information security training and awareness program

C5 (Germany) · 1 control

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • CFTC-SS-5 Systems Development and Quality Assurance Category

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

ISO 27002:2022 · 1 control

  • 6.3 Information security awareness, education and training

NIS2 Directive · 1 control

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis

NIST SP 800-172 · 1 control

  • 3.2.2e Practical Exercises in Awareness Training

NIST SP 800-218 · 1 control

  • PR.AT-02 PR.AT-02 Role-based training includes incident-related responsibilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AT-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 70 it maps to, and the evidence behind each claim, over MCP and REST.