# AT-06 Training Feedback

NIST SP 800-53 control. Family: AT Awareness and Training. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Provide feedback on organizational training results to the following personnel [Assignment: organization-defined frequency]: [Assignment: organization-defined personnel].
Guidance: Training feedback includes awareness training results and role-based training results. Training results, especially failures of personnel in critical roles, can be indicative of a potentially serious problem. Therefore, it is important that senior managers are made aware of such situations so that they can take appropriate response actions. Training feedback supports the evaluation and update of organizational training described in AT-02b and AT-03b.

## Clauses by framework (48 frameworks)
- iso_27001_2022: 7.2, A.6.3. OSA's own, not in NIST's crosswalk: 7.2, A.6.3
- iso_27002_2022: 6.3
- cobit_2019: APO07, BAI08
- nist_csf_2: ID.IM-03, PR.AT-01, PR.AT-02. OSA's own, not in NIST's crosswalk: ID.IM-03, PR.AT-01, PR.AT-02
- cis_controls_v8: CIS 14, CIS 14.6, CIS 14.9
- soc2_tsc: CC1.4, CC1.4-POF2
- iso_42001_2023: A.4.6
- nis2: Art. 21(2)(g)
- apra_cps_234: Para 19-20
- pra_op_resilience: SS1/21-6.2
- bsi_grundschutz: ORP.3
- anssi: Hygiene.1, RGS.1.2, SecNumCloud.8.3
- osfi_b13: B-13.1.1
- finma_circular: IV.B.a(47), IV.B.a(48), IV.B.a(49), IV.B.b(50), IV.B.b(51), IV.E(92), IV.E(93), IV.F(97)
- gdpr: Art.39(1)(b), Art.47(2)(n)
- dora: Art.5(4), Art.13(6)
- bio2: 6.3
- rbi_csf: Annex1.23
- fisc: FISC.O8
- lgpd_bcb: BCB.Art.4, LGPD.Art.50
- dnb_good_practice: DNB.9.1, DNB.9.3
- cbb_tm: TM-3
- cbuae: CR-11
- nca_ecc: 1-10
- qatar_nia: HR
- sama_csf: 1.6
- uae_ia: T5
- bog_cisd: CISD-XV
- bom_ctrm: 3.8
- cbe_csf: GOV-4
- cbn_csf: Part8
- sa_js2: JS2-8.6
- bot_cyber: Ch7.1
- cpmi_pfmi: CG.GOV, CG.LE
- eba_ict: 3.4.7
- ecb_croe: CROE.2.1.2, CROE.2.3.2, CROE.2.8.1
- ffiec_is: I.A, II.C.7(e)
- hipaa_sr: §164.308(a)(5)(i), §164.308(a)(5)(ii)(A)
- iosco_cyber: PROT-4
- sebi_cscrf: CAPACITY, PR.AT
- cmmc_2: AT
- cbest: CBEST.10
- fca_sysc_13: SYSC 13.5.1, SYSC 13.6.1
- hitrust_csf: 02.b
- iso_27799: 7.2
- lloyds_ms: MS8.13
- naic_ds: 4-training
- nhs_dspt: NDG-2.2, NDG-3.1, NDG-6.4
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AT-06
- Clauses only: /api/v1/controls/AT-06?fields=mappings
- Page for people: /controls/at-06/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
