AT-2—Literacy Training and Awareness
>Control Description
a
Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):
1.
As part of initial training for new users and ⚙organization-defined frequency thereafter; and
2.
When required by system changes or following ⚙organization-defined events;
b
Employ the following techniques to increase the security and privacy awareness of system users ⚙organization-defined awareness techniques;
c
Update literacy training and awareness content ⚙organization-defined frequency and following ⚙organization-defined events; and
d
Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
>Related Controls
Ask AI
Configure your API key to use AI features.