Literacy Training and Awareness
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
- 1.As part of initial training for new users and [organization-defined frequency] thereafter; and
- 2.When required by system changes or following [organization-defined events];
Requirement Context
This element is part of AT-2 — Literacy Training and Awareness. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AT-2 — Literacy Training and Awareness. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AT-2 — Literacy Training and Awareness. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AT-2 — Literacy Training and Awareness. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Organizations provide basic and advanced levels of literacy training to system users, including measures to test the knowledge level of users. Organizations determine the content of literacy training and awareness based on specific organizational requirements, the systems to which personnel have authorized access, and work environments (e.g., telework). The content includes an understanding of the need for security and privacy as well as actions by users to maintain security and personal privacy and to respond to suspected incidents. The content addresses the need for operations security and the handling of personally identifiable information. Awareness techniques include displaying posters, offering supplies inscribed with security and privacy reminders, displaying logon screen messages, generating email advisories or notices from organizational officials, and conducting awareness events. Literacy training after the initial training described in AT-2a.1 is conducted at a minimum frequency consistent with applicable laws, directives, regulations, and policies. Subsequent literacy training may be satisfied by one or more short ad hoc sessions and include topical information on recent attack schemes, changes to organizational security and privacy policies, revised security and privacy expectations, or a subset of topics from the initial training. Updating literacy training and awareness content on a regular basis helps to ensure that the content remains relevant. Events that may precipitate an update to literacy training and awareness content include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Enhancements NIST SOURCE
AT-2(1) Practical Exercises LOW MODERATE HIGH
Provide practical exercises in literacy training that simulate events and incidents.
Discussion
Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking, via spear phishing attacks, malicious web links.
AT-2(2) Insider Threat ✓ LOW ✓ MODERATE ✓ HIGH
Provide literacy training on recognizing and reporting potential indicators of insider threat.
Discussion
Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information not required for job performance; unexplained access to financial resources; bullying or harassment of fellow employees; workplace violence; and other serious violations of policies, procedures, directives, regulations, rules, or practices. Literacy training includes how to communicate the concerns of employees and management regarding potential indicators of insider threat through channels established by the organization and in accordance with established policies and procedures. Organizations may consider tailoring insider threat awareness topics to the role. For example, training for managers may be focused on changes in the behavior of team members, while training for employees may be focused on more general observations.
AT-2(3) Social Engineering and Mining LOW ✓ MODERATE ✓ HIGH
Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.
Discussion
Social engineering is an attempt to trick an individual into revealing information or taking an action that can be used to breach, compromise, or otherwise adversely impact a system. Social engineering includes phishing, pretexting, impersonation, baiting, quid pro quo, thread-jacking, social media exploitation, and tailgating. Social mining is an attempt to gather information about the organization that may be used to support future attacks. Literacy training includes information on how to communicate the concerns of employees and management regarding potential and actual instances of social engineering and data mining through organizational channels based on established policies and procedures.
AT-2(4) Suspicious Communications and Anomalous System Behavior LOW MODERATE HIGH
Provide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [indicators of malicious code].
Discussion
A well-trained workforce provides another organizational control that can be employed as part of a defense-in-depth strategy to protect against malicious code coming into organizations via email or the web applications. Personnel are trained to look for indications of potentially suspicious email (e.g., receiving an unexpected email, receiving an email containing strange or poor grammar, or receiving an email from an unfamiliar sender that appears to be from a known sponsor or contractor). Personnel are also trained on how to respond to suspicious email or web communications. For this process to work effectively, personnel are trained and made aware of what constitutes suspicious communications. Training personnel on how to recognize anomalous behaviors in systems can provide organizations with early warning for the presence of malicious code. Recognition of anomalous behavior by organizational personnel can supplement malicious code detection and protection tools and systems employed by organizations.
AT-2(5) Advanced Persistent Threat LOW MODERATE HIGH
Provide literacy training on the advanced persistent threat.
Discussion
An effective way to detect advanced persistent threats (APT) and to preclude successful attacks is to provide specific literacy training for individuals. Threat literacy training includes educating individuals on the various ways that APTs can infiltrate the organization (e.g., through websites, emails, advertisement pop-ups, articles, and social engineering). Effective training includes techniques for recognizing suspicious emails, use of removable systems in non-secure settings, and the potential targeting of individuals at home.
AT-2(6) Cyber Threat Environment LOW MODERATE HIGH
- (a) Provide literacy training on the cyber threat environment; and
- (b) Reflect current cyber threat information in system operations.
Discussion
Since threats continue to change over time, threat literacy training by the organization is dynamic. Moreover, threat literacy training is not performed in isolation from the system operations that support organizational mission and business functions.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AT-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency at which to provide security literacy training to system users (including managers, senior executives, and contractors) after initial training is defined;
- the frequency at which to provide privacy literacy training to system users (including managers, senior executives, and contractors) after initial training is defined;
- events that require security literacy training for system users are defined;
- events that require privacy literacy training for system users are defined;
- techniques to be employed to increase the security and privacy awareness of system users are defined;
- the frequency at which to update literacy training and awareness content is defined;
- events that would require literacy training and awareness content to be updated are defined;
- security literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
- privacy literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
- security literacy training is provided to system users (including managers, senior executives, and contractors) <AT-02_ODP[01] frequency> thereafter;
- privacy literacy training is provided to system users (including managers, senior executives, and contractors) <AT-02_ODP[02] frequency> thereafter;
- security literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following <AT-02_ODP[03] events>;
- privacy literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following <AT-02_ODP[04] events>;
- <AT-02_ODP[05] awareness techniques> are employed to increase the security and privacy awareness of system users;
- literacy training and awareness content is updated <AT-02_ODP[06] frequency>;
- literacy training and awareness content is updated following <AT-02_ODP[07] events>;
- lessons learned from internal or external security incidents or breaches are incorporated into literacy training and awareness techniques.
Examine
[SELECT FROM: System security plan; privacy plan; literacy training and awareness policy; procedures addressing literacy training and awareness implementation; appropriate codes of federal regulations; security and privacy literacy training curriculum; security and privacy literacy training materials; training records; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with responsibilities for literacy training and awareness; organizational personnel with information security and privacy responsibilities; organizational personnel comprising the general system user community].
Test
[SELECT FROM: Mechanisms managing information security and privacy literacy training].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AT-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System security plan
- privacy plan
- literacy training and awareness policy
Testing
- Mechanisms managing information security and privacy literacy training
Other Records
- procedures addressing literacy training and awareness implementation
- appropriate codes of federal regulations
- security and privacy literacy training curriculum
- security and privacy literacy training materials
- training records
- other relevant documents or records