Role-based Training AT-3
Awareness and Training · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AT-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Awareness and Training family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AT-3 (Role-based Training) is about training people for the specific job they do, not just general awareness. Anyone with a security-relevant role — here, the administrators of this Linux lab server — gets training tied to that role before they are granted access, again on a set schedule, and whenever the system changes enough to matter. Lessons learned from real incidents feed back into it. It is an Awareness and Training control in the Low baseline.
What good looks like
- Identify the roles that touch this server (for example, system administrator or backup operator) and what each one needs to know to work safely.
- Train before access — deliver role-based training before you hand over the credentials for that role, then repeat it on a set frequency.
- Refresh the training when the system changes — a new service, a new hardening standard, or a new tool can each trigger an update.
- Fold in lessons learned from real incidents or breaches so the training reflects what actually goes wrong.
- Cover the practical skills the role uses on this box — for a Linux administrator, that includes
sudouse, patching, and reading the audit logs.
Framework mapping
- NIST CSF 2.0 — PR.AT-02 — Individuals in specialized roles are provided with awareness and training
- CIS Controls v8 — Control 14 — Security Awareness and Skills Training
How to move it toward Implemented
- List each security-relevant role on this server and write a short training outline for it — the topics an administrator must understand before receiving
sudoaccess. - Deliver the training and capture the date and who attended; do this before granting access and then on a yearly cadence.
- After any incident or major change to the server, update the outline and note what you added and why.
- Attach the training outline and the completion record as hardening evidence on the asset, naming
AT-3in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.