|
controlAT-2

Literacy Training and Awareness (AT-2)

Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): Employ the following techniques to increase the security and privacy awareness of system users [organization-defined]; Update literacy training and awareness content [organization-defined] and following [organization-defined] ; and Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.

Security Baselines

LOWMODERATEHIGH
awarenesstrainingworkforce

Why These Connect

Maps To4

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports25

These related controls work together — a change to one may affect the others.

Mitigates3

This control helps defend against or reduce the risk of the linked threat technique.

Enhances6

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(4)

PR.AT-01PR.AT-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AT-01PR.AT-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(7)

Assignmentorganization-defined frequency
Assignmentorganization-defined frequency
Assignmentorganization-defined events
Assignmentorganization-defined events
Assignmentorganization-defined awareness techniques
Assignmentorganization-defined frequency
Assignmentorganization-defined events

Control Enhancements(6)