PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AT-2 — Literacy Training and Awareness

Framework: NIST SP 800-53 Rev.5 AT-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Does a current, management-approved security and privacy literacy training and awareness program (policy/plan) exist that defines the mandatory audiences (new users, managers, senior executives, and contractors), the trigger events for training, and the recurring refresher frequency (e.g., annually) as required by AT-2a? (CIS Control 14.1)
Examine Do Learning Management System / training completion records show that a sample of new users (including contractors) completed initial literacy training before, or within the organization-defined window after, receiving system access?
Examine Do completion records demonstrate that the current workforce - including privileged users and senior executives - met the organization-defined periodic refresher within the required frequency, with non-completions tracked to remediation or escalation?
Test Are practical awareness exercises such as simulated phishing / social-engineering campaigns actually conducted, and do the campaign results (click rates, report rates, and repeat-offender follow-up) evidence AT-2(1)/AT-2(3)? (CIS Control 14.2)
Examine Does version history or a content review log show that training and awareness material is refreshed at the defined frequency and following significant events, and that lessons learned from internal or external security incidents were incorporated (AT-2c/AT-2d)?
Examine Does the training curriculum explicitly cover the required threat topics - social engineering (AT-2(3)), insider-threat indicators (AT-2(2)), and recognizing and reporting suspicious communications or anomalous system behavior (AT-2(4))? (CIS Controls 14.4/14.6)
Interview Can a sample of staff describe what constitutes a reportable security event and identify the correct channel or point of contact for reporting suspected phishing or incidents, demonstrating the awareness program is effective rather than merely delivered?