AT-3—Role-based Training
>Control Description
a
Provide role-based security and privacy training to personnel with the following roles and responsibilities: ⚙organization-defined roles and responsibilities:
1.
Before authorizing access to the system, information, or performing assigned duties, and ⚙organization-defined frequency thereafter; and
2.
When required by system changes;
b
Update role-based training content ⚙organization-defined frequency and following ⚙organization-defined events; and
c
Incorporate lessons learned from internal or external security incidents or breaches into role-based training.
>Related Controls
Ask AI
Configure your API key to use AI features.