Under active development Content is continuously updated and improved

CM0041CM0041

>Control Description

Train users to be aware of access or manipulation attempts by a threat actor to reduce the risk of successful spear phishing, social engineering, and other techniques that involve user interaction. Ensure that role-based security-related training is provided to personnel with assigned security roles and responsibilities: (i) before authorizing access to the information system or performing assigned duties; (ii) when required by information system changes; and (iii) at least annually if not otherwise defined.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.