AT-2—Literacy Training and Awareness
>Control Description
Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):
As part of initial training for new users prior to accessing CJI and annually thereafter; and
When required by system changes or within 30 days of any security event for individuals involved in the event;
Employ one or more of the following techniques to increase the security and privacy awareness of system users:
Displaying posters
Offering supplies inscribed with security and privacy reminders
Displaying logon screen messages
Generating email advisories or notices from organizational officials
Conducting awareness events
Update literacy training and awareness content annually and following changes in the information system operating environment, when security incidents occur, or when changes are made in the CJIS Security Policy; and
Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.