AT-3 Role-based training
Requires role-based security and privacy training for personnel holding organization-defined roles, delivered before access or duties begin and repeated on a defined frequency and on system change, with content refreshed
4
artefacts
1
held by a system
1
at each review
moderate
to go live
HR system / LMS
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Completion records showing training preceded the grant of access or duties · HR system / LMS
periodic reviewEvidence produced at each review
- Refresher completion evidence against the defined frequency · HR system / LMS
governing documentDocuments that govern the control
- Defined list of roles requiring role-based training and the syllabus for each · Policy repository / GRC workspace
- Content revision history reflecting system changes and incident lessons · HR system / LMS
First move
Start with the 1 of 4 artefacts that already live in a system (HR system / LMS); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Privileged administrators receive only the general awareness course
- Training delivered after access was already granted rather than before
- Developer and incident responder roles identified but no distinct syllabus exists for them
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAT-2 Literacy training and awareness · AT-4 Training records