03.02.01EActive
An effective way to detect APTs, address the cyber threat environment, and preclude successful attacks is to provide specific literacy training for individuals. Threat literacy training includes educating individuals on the various ways that APTs can infiltrate the organization (e.g., through websites, emails, pop-ups, articles, and social engineering) and describes techniques for recognizing suspicious emails, the u
03.02.02EActive
Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking malicious web links via spear phishing attacks. This requirement enhances SP 800-171 requirement 03.02.01.
03.02.03EActive
Training feedback includes literacy and role-based training results, which can indicate a potentially serious problem, especially the failures of personnel in critical roles. Managers should be made aware of such situations so that they can respond accordingly. Training feedback supports the evaluation and update of organizational training content and methodology. This requirement does not enhance a specific requirem
03.02.04EActive
System components include hardware, software, and firmware components as well as the documentation for those components. This requirement is sourced to a control tailored out of the SP 800-53B .13 moderate baseline in SP 800-171.