Policy and Procedures AT-1
Awareness and Training · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AT-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Awareness and Training family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AT-1 (Policy and Procedures) is about putting your Awareness and Training (AT) program in writing so it does not live only in memory. You document a policy that states why training matters and who it applies to, write the procedures that carry the policy out, name an official who owns it, and set a schedule to review and update both. It is a foundational Awareness and Training control that sits in the Low baseline.
What good looks like
- Write an awareness and training policy that states its purpose, scope, roles, responsibilities, and management commitment — and say whether it applies at the organization, mission, or system level.
- Back the policy with procedures — the concrete steps that carry it out for this lab server and the people who administer it.
- Name an official who owns the policy and procedures — one person responsible for keeping them current.
- Keep the policy consistent with applicable laws, directives, and standards so it does not contradict rules you already follow.
- Review and update the policy and procedures on a set schedule, and after a triggering event such as an audit finding or a major system change.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established, communicated, and enforced
- CIS Controls v8 — Control 14 — Security Awareness and Skills Training
How to move it toward Implemented
- Draft a one-page awareness and training policy covering purpose, scope, roles, the named owner, and a review cadence (for example, yearly).
- Write short procedures beneath it: how a new administrator of this server gets trained, what they must know, and how completion is recorded.
- Set the next review date and note the last-reviewed date on the document itself, so the schedule is visible at a glance.
- Attach the signed policy and procedures as hardening evidence on the asset, naming
AT-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.