Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

AT-2 — Literacy Training and Awareness

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

6Enhancements
9Parameters
4Baseline memberships
3Assessment methods

AT — Awareness and Training · NIST SP 800-53 Release 5.2.0

LowModerateHighPrivacy
Official NIST control content

Control statement

  1. a.Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):
    1. 1.As part of initial training for new users and [Organization-defined: organization-defined frequency] thereafter; and
    2. 2.When required by system changes or following [Organization-defined: organization-defined events];
  2. b.Employ the following techniques to increase the security and privacy awareness of system users [Organization-defined: awareness techniques];
  3. c.Update literacy training and awareness content [Organization-defined: frequency] and following [Organization-defined: events] ; and
  4. d.Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
Official NIST discussion

Discussion

Organizations provide basic and advanced levels of literacy training to system users, including measures to test the knowledge level of users. Organizations determine the content of literacy training and awareness based on specific organizational requirements, the systems to which personnel have authorized access, and work environments (e.g., telework). The content includes an understanding of the need for security and privacy as well as actions by users to maintain security and personal privacy and to respond to suspected incidents. The content addresses the need for operations security and the handling of personally identifiable information. Awareness techniques include displaying posters, offering supplies inscribed with security and privacy reminders, displaying logon screen messages, generating email advisories or notices from organizational officials, and conducting awareness events. Literacy training after the initial training described in [AT-2a.1](#at-2_smt.a.1) is conducted at a minimum frequency consistent with applicable laws, directives, regulations, and policies. Subsequent literacy training may be satisfied by one or more short ad hoc sessions and include topical information on recent attack schemes, changes to organizational security and privacy policies, revised security and privacy expectations, or a subset of topics from the initial training. Updating literacy training and awareness content on a regular basis helps to ensure that the content remains relevant. Events that may precipitate an update to literacy training and awareness content include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined frequency
organization-defined events
frequencythe frequency at which to provide security literacy training to system users (including managers, senior executives, and contractors) after initial training is defined;
frequencythe frequency at which to provide privacy literacy training to system users (including managers, senior executives, and contractors) after initial training is defined;
eventsevents that require security literacy training for system users are defined;
eventsevents that require privacy literacy training for system users are defined;
awareness techniquestechniques to be employed to increase the security and privacy awareness of system users are defined;
frequencythe frequency at which to update literacy training and awareness content is defined;
eventsevents that would require literacy training and awareness content to be updated are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Literacy Training and Awareness as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to role-based knowledge, behavior, awareness, and measurable workforce readiness.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • training plans and role assignments
  • completion and attendance records
  • exercise results and lessons learned
  • training-content approval records

Common failure patterns

  • generic annual training with no role context
  • completion treated as proof of competence
  • contractors or privileged users omitted
  • training content not updated after incidents

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AT-02a.
    1. AT-02a.01
      1. AT-02a.01[01]security literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
      2. AT-02a.01[02]privacy literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
      3. AT-02a.01[03]security literacy training is provided to system users (including managers, senior executives, and contractors) [Organization-defined: frequency] thereafter;
      4. AT-02a.01[04]privacy literacy training is provided to system users (including managers, senior executives, and contractors) [Organization-defined: frequency] thereafter;
    2. AT-02a.02
      1. AT-02a.02[01]security literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following [Organization-defined: events];
      2. AT-02a.02[02]privacy literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following [Organization-defined: events];
  2. AT-02b.[Organization-defined: awareness techniques] are employed to increase the security and privacy awareness of system users;
  3. AT-02c.
    1. AT-02c.[01]literacy training and awareness content is updated [Organization-defined: frequency];
    2. AT-02c.[02]literacy training and awareness content is updated following [Organization-defined: events];
  4. AT-02d.lessons learned from internal or external security incidents or breaches are incorporated into literacy training and awareness techniques.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness implementation
  • appropriate codes of federal regulations
  • security and privacy literacy training curriculum
  • security and privacy literacy training materials
  • training records
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel comprising the general system user community

Test

  • Mechanisms managing information security and privacy literacy training
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

AT-2(1) — Practical Exercises

Provide practical exercises in literacy training that simulate events and incidents.

Official discussion

Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking, via spear phishing attacks, malicious web links.

Assessment objectives and methods

practical exercises in literacy training that simulate events and incidents are provided.

Examine

  • System security plan
  • privacy plan
  • security awareness and training policy
  • procedures addressing security awareness training implementation
  • security awareness training curriculum
  • security awareness training materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for security awareness training
  • organizational personnel with information security responsibilities

Test

  • Mechanisms implementing cyber-attack simulations in practical exercises
Related controls
Official NIST control enhancement

AT-2(2) — Insider Threat

LowModerateHigh

Provide literacy training on recognizing and reporting potential indicators of insider threat.

Official discussion

Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information not required for job performance; unexplained access to financial resources; bullying or harassment of fellow employees; workplace violence; and other serious violations of policies, procedures, directives, regulations, rules, or practices. Literacy training includes how to communicate the concerns of employees and management regarding potential indicators of insider threat through channels established by the organization and in accordance with established policies and procedures. Organizations may consider tailoring insider threat awareness topics to the role. For example, training for managers may be focused on changes in the behavior of team members, while training for employees may be focused on more general observations.

Assessment objectives and methods
  1. AT-02(02)[01]literacy training on recognizing potential indicators of insider threat is provided;
  2. AT-02(02)[02]literacy training on reporting potential indicators of insider threat is provided.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness implementation
  • literacy training and awareness curriculum
  • literacy training and awareness materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
Related controls
Official NIST control enhancement

AT-2(3) — Social Engineering and Mining

ModerateHigh

Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.

Official discussion

Social engineering is an attempt to trick an individual into revealing information or taking an action that can be used to breach, compromise, or otherwise adversely impact a system. Social engineering includes phishing, pretexting, impersonation, baiting, quid pro quo, thread-jacking, social media exploitation, and tailgating. Social mining is an attempt to gather information about the organization that may be used to support future attacks. Literacy training includes information on how to communicate the concerns of employees and management regarding potential and actual instances of social engineering and data mining through organizational channels based on established policies and procedures.

Assessment objectives and methods
  1. AT-02(03)[01]literacy training on recognizing potential and actual instances of social engineering is provided;
  2. AT-02(03)[02]literacy training on reporting potential and actual instances of social engineering is provided;
  3. AT-02(03)[03]literacy training on recognizing potential and actual instances of social mining is provided;
  4. AT-02(03)[04]literacy training on reporting potential and actual instances of social mining is provided.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness implementation
  • literacy training and awareness curriculum
  • literacy training and awareness materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
Official NIST control enhancement

AT-2(4) — Suspicious Communications and Anomalous System Behavior

Provide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [Organization-defined: indicators of malicious code].

Official discussion

A well-trained workforce provides another organizational control that can be employed as part of a defense-in-depth strategy to protect against malicious code coming into organizations via email or the web applications. Personnel are trained to look for indications of potentially suspicious email (e.g., receiving an unexpected email, receiving an email containing strange or poor grammar, or receiving an email from an unfamiliar sender that appears to be from a known sponsor or contractor). Personnel are also trained on how to respond to suspicious email or web communications. For this process to work effectively, personnel are trained and made aware of what constitutes suspicious communications. Training personnel on how to recognize anomalous behaviors in systems can provide organizations with early warning for the presence of malicious code. Recognition of anomalous behavior by organizational personnel can supplement malicious code detection and protection tools and systems employed by organizations.

Organization-defined parameters (1)
indicators of malicious codeindicators of malicious code are defined;
Assessment objectives and methods

literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [Organization-defined: indicators of malicious code] is provided.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness implementation
  • literacy training and awareness curriculum
  • literacy training and awareness materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for basic literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
Official NIST control enhancement

AT-2(5) — Advanced Persistent Threat

Provide literacy training on the advanced persistent threat.

Official discussion

An effective way to detect advanced persistent threats (APT) and to preclude successful attacks is to provide specific literacy training for individuals. Threat literacy training includes educating individuals on the various ways that APTs can infiltrate the organization (e.g., through websites, emails, advertisement pop-ups, articles, and social engineering). Effective training includes techniques for recognizing suspicious emails, use of removable systems in non-secure settings, and the potential targeting of individuals at home.

Assessment objectives and methods

literacy training on the advanced persistent threat is provided.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness implementation
  • literacy training and awareness curriculum
  • literacy training and awareness materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for basic literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
Official NIST control enhancement

AT-2(6) — Cyber Threat Environment

  1. (a)Provide literacy training on the cyber threat environment; and
  2. (b)Reflect current cyber threat information in system operations.
Official discussion

Since threats continue to change over time, threat literacy training by the organization is dynamic. Moreover, threat literacy training is not performed in isolation from the system operations that support organizational mission and business functions.

Assessment objectives and methods
  1. AT-02(06)(a)literacy training on the cyber threat environment is provided;
  2. AT-02(06)(b)system operations reflects current cyber threat information.

Examine

  • System security plan
  • privacy plan
  • literacy training and awareness policy
  • procedures addressing literacy training and awareness training implementation
  • literacy training and awareness curriculum
  • literacy training and awareness materials
  • other relevant documents or records

Interview

  • Organizational personnel who receive literacy training and awareness
  • organizational personnel with responsibilities for basic literacy training and awareness
  • organizational personnel with information security and privacy responsibilities
Related controls
Source record

Authoritative sources