Training Records AT-4
Awareness and Training · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds AT-4 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Awareness and Training family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
AT-4 (Training Records) is about keeping proof that the training actually happened. You document and monitor both the general awareness training and the role-based training that people receive, and you retain each person’s training records for a defined length of time. It is an Awareness and Training control in the Low baseline — the one that makes the other AT controls auditable.
What good looks like
- Document each training event — who was trained, on what, and when — for both awareness and role-based training.
- Monitor that the training is being completed, so gaps surface before an auditor finds them.
- Retain individual training records for a defined period — choose the length and write it down.
- Keep records tied to a named person, matching the administrators who actually hold access to this server.
- Store the records somewhere durable and dated so they can be produced on request.
Framework mapping
How to move it toward Implemented
- Create a simple training log (a dated spreadsheet or file) listing each administrator, the training they completed, and the date.
- Decide and record a retention period (for example, three years) and note it at the top of the log.
- Do a periodic check that everyone with access to this server has a current record, and save that check as a dated file.
- Attach the training log as hardening evidence on the asset, naming
AT-4in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.