STIGhub
STIGs
RMF Controls
Compare
← All Controls
AT-1
Awareness and Training
Rev 5
Policy and Procedures
CCI Identifiers (15)
CCI-000100
Develop and document an organization level, mission/business process-level, or system-level awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000101
Disseminate an organization level, mission/business process-level, or system-level awareness and training policy to organization-defined personnel or roles.
CCI-000102
Review and update the current security awareness and training policy in accordance with organization-defined frequency.
CCI-000103
Develop and document procedures to facilitate the implementation of the awareness and training policy and associated awareness and training controls.
CCI-000104
Disseminate organization-level; mission/business process-level; or system-level awareness and training procedures to organization-defined personnel or roles.
CCI-000105
Review and update the current security awareness and training procedures in accordance with an organization-defined frequency.
CCI-001564
Defines the frequency of security awareness and training policy reviews and updates.
CCI-001565
Defines the frequency of security awareness and training procedure reviews and updates.
CCI-002048
Defines the personnel or roles to whom the awareness and training policy is disseminated.
CCI-002049
Defines the personnel or roles to whom the organization-level; mission/business process-level; system-level awareness and training procedures are disseminated.
CCI-003761
Develop and document an organization level, mission/business process-level, or system-level awareness and training policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
CCI-003762
Designate an organization-defined official to manage the development and documentation of the awareness and training policy.
CCI-003763
Designate an organization-defined official to manage the dissemination of the awareness and training policy.
CCI-003764
Designate an organization-defined official to manage the development and documentation of the awareness and training procedures.
CCI-003765
Designate an organization-defined official to manage the dissemination of the awareness and training procedures.
Linked STIG Checks (1)
Across 1 STIGs. Click to expand.
▶
Microsoft Windows PAW Security Technical Implementation Guide
1 check