Literacy Training and Awareness AT-2
Awareness and Training · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AT-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Awareness and Training family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AT-2 (Literacy Training and Awareness) requires giving everyone who uses the system basic security-awareness and literacy training — spotting phishing, insider threat, and safe data handling — at onboarding, on a refresh schedule, and after major changes. It is an organization-wide personnel control, not a host setting.
What good looks like
- Provide security-awareness training to all system users before they are granted access.
- Refresh the training on a defined schedule and after major system or threat-landscape changes.
- Cover practical topics — phishing, social engineering, insider threat, and safe handling of data.
- Track completion so you can show who has been trained and when.
Framework mapping
- NIST CSF 2.0 — PR.AT-01 — Personnel are provided with awareness and training so they perform their duties securely
- CIS Controls v8 — Control 14 — Security Awareness and Skills Training
How to move it toward Implemented
- This is correctly marked not applicable at the host level: awareness training is delivered to people across an organization, and a single lab virtual machine (VM) offers no mechanism to implement it — the runbook has no training step.
- Tailor it as an inherited common control: record in the System Security Plan (SSP) that AT-2 is satisfied by the organization's awareness program rather than by anything configured on PROD-WEB-01.
- It WOULD apply directly the moment real human operators or users administer this system under an organization — each of them must complete awareness training at onboarding and on the refresh cycle, with completion tracked as the evidence.