AT-2 Literacy training and awareness
Requires security and privacy literacy training for all system users including managers, executives and contractors, given at induction and repeated on a defined frequency and after defined system changes or events, with
4
artefacts
2
held by a system
1
at each review
easy
to go live
HR system / LMS
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Training completion report covering all user categories including executives and contractors · HR system / LMS
- Change log showing content updated after incidents or system changes · SIEM / log platform
periodic reviewEvidence produced at each review
- Record of awareness techniques used such as simulated phishing or targeted campaigns · HR system / LMS
governing documentDocuments that govern the control
- Course content showing the security and privacy topics delivered · HR system / LMS
First move
Automate the pull from your HR system / LMS. Joiner, mover, leaver and training-completion records exported from the HR system and LMS.
Common gaps auditors find
- Completion tracked for employees while contractors and vendors are omitted
- Content unchanged year to year, so it does not reflect the threats actually seen
- Incidents produce a post mortem but never reach the awareness material
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAT-1 Policy and procedures for awareness and training · AT-3 Role-based training