← Controls / AT

AT-03 Role-based Training

Awareness and Training

Low Moderate High Privacy

Description

a. Provide role-based security and privacy training to personnel with the following roles and responsibilities: [Assignment: organization-defined roles and responsibilities]: 1. Before authorizing access to the system, information, or performing assigned duties, and [Assignment: organization-defined frequency] thereafter; and 2. When required by system changes; b. Update role-based training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and c. Incorporate lessons learned from internal or external security incidents or breaches into role-based training.

Supplemental Guidance

Organizations determine the content of training based on the assigned roles and responsibilities of individuals as well as the security and privacy requirements of organizations and the systems to which personnel have authorized access, including technical training specifically tailored for assigned duties. Roles that may require role-based training include senior leaders or management officials (e.g., head of agency/chief executive officer, chief information officer, senior accountable official for risk management, senior agency information security officer, senior agency official for privacy), system owners; authorizing officials; system security officers; privacy officers; acquisition and procurement officials; enterprise architects; systems engineers; software developers; systems security engineers; privacy engineers; system, network, and database administrators; auditors; personnel conducting configuration management activities; personnel performing verification and validation activities; personnel with access to system-level software; control assessors; personnel with contingency planning and incident response duties; personnel with privacy management responsibilities; and personnel with access to personally identifiable information. Comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls. Role-based training also includes policies, procedures, tools, methods, and artifacts for the security and privacy roles defined. Organizations provide the training necessary for individuals to fulfill their responsibilities related to operations and supply chain risk management within the context of organizational security and privacy programs. Role-based training also applies to contractors who provide services to federal agencies. Types of training include web-based and computer-based training, classroom-style training, and hands-on training (including micro-training). Updating role-based training on a regular basis helps to ensure that the content remains relevant and effective. Events that may precipitate an update to role-based training content include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Changes from Rev 4

Title changed from 'Role-Based Security Training' Adds privacy to control text, to imply training includes privacy, as well as security; adds text to incorporate lessons learned from internal or external security or privacy incidents into training Adds parameter requiring role-based security and privacy training for personnel with specific roles and responsibilities Adds new control text with a parameter to update role-based training at a specific frequency Discussion adds examples of personnel to be trained as well as events that may precipitate an update to role-based training Incorporates role-based training elements of withdrawn App J control AR-05

Enhancements (4)

What NIST adds to this control. Select one to read its statement.

AT-03(01) Environmental Controls

Provide [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of environmental controls.

AT-03(02) Physical Security Controls

Provide [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of physical security controls.

AT-03(03) Practical Exercises

Provide practical exercises in security and privacy training that reinforce training objectives.

AT-03(05) Processing Personally Identifiable Information Privacy

Provide [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of personally identifiable information processing and transparency controls.

Withdrawn by NIST:

  • AT-03(04) Suspicious Communications and Anomalous System Behavior, now in AT-02(04)

Compliance Mappings

ISO 27001:2022

7.2A.6.3

ISO 27002:2022

6.3

COBIT 2019

APO07BAI08

CIS Controls v8

CIS 14CIS 14.3CIS 14.4CIS 14.5CIS 14.7CIS 14.8CIS 14.9CIS 16.9

NIST CSF 2.0

GV.RR-04PR.AT-01PR.AT-02

PCI DSS v4.0.1

6.2.112.6

CSA CCM v4

DCS-11HRS-11HRS-12

CSA AICM v1

DCS-11HRS-11HRS-12HRS-14

ISO 42001:2023

A.4.6

NIS2 Directive

Art. 21(2)(g)

PRA Operational Resilience

SS2/21-17.1

APRA CPS 234

Para 19-20

BSI IT-Grundschutz

ORP.2ORP.3

ANSSI

Hygiene.4SecNumCloud.8.3

FINMA Circular 2023/1

IV.B.a(48)IV.B.a(49)IV.B.b(50)

OSFI B-13

B-13.1.1

EU GDPR

Art.29Art.32(4)Art.47(2)(n)

EU DORA

Art.5(4)Art.13(6)

BIO2

6.3

RBI CSF

Annex1.23

FISC Security Guidelines

FISC.O8

LGPD + BCB 4893

BCB.Art.4LGPD.Art.47

MLPS 2.0

8.1.8.2

DNB Good Practice

DNB.8.2DNB.9.2

SWIFT CSCF

SWIFT.7.2

SAMA CSF

1.6

NCA ECC

1-10

UAE IA

T5

CBB TM

TM-3

Qatar NIA

HR

CBUAE

CR-11

CBE CSF

GOV-4

SA JS2

JS2-8.6

CBN CSF

Part1.2Part8

BoG CISD

CISD-XCISD-XV

BoM CTRM

3.8

IOSCO Cyber Resilience

PROT-4

CPMI-IOSCO PFMI

CG.GOVCG.LE

FFIEC IS

I.AI.CII.C.7II.C.7(e)IV.A.1

NYDFS 500

500.10500.14

HIPAA Security Rule

§164.308(a)(5)(i)

ECB CROE

CROE.2.1.2CROE.2.3.2CROE.2.8.2

EBA ICT Guidelines

3.4.7

SEBI CSCRF

CAPACITYPR.AT

BOT Cyber Resilience

Ch7.1

CMMC 2.0

AT

NERC CIP

CIP-004-7

10 CFR 73.54

RG5.71-C-AT

TSA Pipeline SD

SD-2 Sec H

DOE C2M2 v2.1

WORKFORCE

API 1164

Sec 13

AWIA

AWWA Sec 8

IAEA NSS 17-T

Sec 9

Solvency II

DR.266

Lloyd's Minimum Standards

CRM.1MS8.13

NAIC Insurance Data Security

4-training4B

PRA SS1/23

P2.3P3.6

FCA SYSC 13

SYSC 13.5.1SYSC 13.6.1

HITRUST CSF v11

02.b

FDA 21 CFR Part 11

§11.10(i)

ISO 27799

7.2

NHS DSPT

NDG-1.3NDG-2.2NDG-2.3NDG-3.1NDG-3.2

CCSS v9.0

1.04.4

Basel SCO60

SCO60.60SCO60.74

BSSC Standards

GSP-03

SEC Custody (Digital Assets)

SEC-CD-19

ISO 17799 (legacy)

8.2.210.3.211.7.113.1.114.1.4

COBIT 4.1 (legacy)

PO7.4DS7.2