# AT-04 Training Records

NIST SP 800-53 control. Family: AT Awareness and Training. Function: preventative. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-based security and privacy training; and b. Retain individual training records for [Assignment: organization-defined time period].
Guidance: Documentation for specialized training may be maintained by individual supervisors at the discretion of the organization. The National Archives and Records Administration provides guidance on records retention for federal agencies.

## Patterns that use it (5)
- Important (1): SP-014 Awareness and Training Pattern
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern

## Clauses by framework (49 frameworks)
- iso_27001_2022: A.6.3. OSA's own, not in NIST's crosswalk: A.6.3
- iso_27002_2022: 6.3
- pci_dss_v4: 12.6
- nist_csf_2: GV.RR-04. OSA's own, not in NIST's crosswalk: GV.RR-04
- cis_controls_v8: CIS 14
- iso_42001_2023: A.4.6
- bsi_grundschutz: ORP.2, ORP.3
- anssi: Hygiene.3, Hygiene.4, SecNumCloud.8.3
- osfi_b13: B-13.1.1
- finma_circular: IV.B.a(48), IV.B.a(49)
- gdpr: Art.5(2), Art.24(1)
- dora: Art.13(6)
- bio2: 6.3
- rbi_csf: Annex1.21, Annex1.23
- fisc: FISC.O8
- mlps_2: 8.1.8.2
- dnb_good_practice: DNB.9.2
- cbuae: CR-11
- nca_ecc: 1-10
- qatar_nia: HR
- sama_csf: 1.6
- uae_ia: T5
- bog_cisd: CISD-XV
- bom_ctrm: 3.8
- cbe_csf: GOV-4
- cbn_csf: Part8
- sa_js2: JS2-8.6
- bot_cyber: Ch7.1
- eba_ict: 3.4.7
- ecb_croe: CROE.2.3.2
- ffiec_is: I.A, II.C.7(e)
- hipaa_sr: §164.308(a)(5)(i)
- iosco_cyber: PROT-4
- nydfs_500: 500.14
- sebi_cscrf: CAPACITY, PR.AT
- cmmc_2: AT
- nerc_cip: CIP-004-7
- nrc_73_54: RG5.71-C-AT
- tsa_psd: SD-2 Sec H
- doe_c2m2: WORKFORCE
- iaea_nss: Sec 9
- fca_sysc_13: SYSC 13.6.1
- fda_21_cfr_11: §11.10(i)
- hitrust_csf: 02.b
- iso_27799: 7.2
- lloyds_ms: MS8.13
- naic_ds: 4-training
- nhs_dspt: NDG-2.1, NDG-2.2, NDG-3.1
- bssc: GSP-03
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AT-04
- Clauses only: /api/v1/controls/AT-04?fields=mappings
- Page for people: /controls/at-04/
