Control statement
- a.Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):
- 1.As part of initial training for new users and [Organization-defined: organization-defined frequency] thereafter; and
- 2.When required by system changes or following [Organization-defined: organization-defined events];
- b.Employ the following techniques to increase the security and privacy awareness of system users [Organization-defined: awareness techniques];
- c.Update literacy training and awareness content [Organization-defined: frequency] and following [Organization-defined: events] ; and
- d.Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
Discussion
Organizations provide basic and advanced levels of literacy training to system users, including measures to test the knowledge level of users. Organizations determine the content of literacy training and awareness based on specific organizational requirements, the systems to which personnel have authorized access, and work environments (e.g., telework). The content includes an understanding of the need for security and privacy as well as actions by users to maintain security and personal privacy and to respond to suspected incidents. The content addresses the need for operations security and the handling of personally identifiable information. Awareness techniques include displaying posters, offering supplies inscribed with security and privacy reminders, displaying logon screen messages, generating email advisories or notices from organizational officials, and conducting awareness events. Literacy training after the initial training described in [AT-2a.1](#at-2_smt.a.1) is conducted at a minimum frequency consistent with applicable laws, directives, regulations, and policies. Subsequent literacy training may be satisfied by one or more short ad hoc sessions and include topical information on recent attack schemes, changes to organizational security and privacy policies, revised security and privacy expectations, or a subset of topics from the initial training. Updating literacy training and awareness content on a regular basis helps to ensure that the content remains relevant. Events that may precipitate an update to literacy training and awareness content include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Literacy Training and Awareness as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to role-based knowledge, behavior, awareness, and measurable workforce readiness.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- training plans and role assignments
- completion and attendance records
- exercise results and lessons learned
- training-content approval records
Common failure patterns
- generic annual training with no role context
- completion treated as proof of competence
- contractors or privileged users omitted
- training content not updated after incidents
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- AT-02a.
- AT-02a.01
- AT-02a.01[01]security literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
- AT-02a.01[02]privacy literacy training is provided to system users (including managers, senior executives, and contractors) as part of initial training for new users;
- AT-02a.01[03]security literacy training is provided to system users (including managers, senior executives, and contractors) [Organization-defined: frequency] thereafter;
- AT-02a.01[04]privacy literacy training is provided to system users (including managers, senior executives, and contractors) [Organization-defined: frequency] thereafter;
- AT-02a.02
- AT-02a.02[01]security literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following [Organization-defined: events];
- AT-02a.02[02]privacy literacy training is provided to system users (including managers, senior executives, and contractors) when required by system changes or following [Organization-defined: events];
- AT-02a.01
- AT-02b.[Organization-defined: awareness techniques] are employed to increase the security and privacy awareness of system users;
- AT-02c.
- AT-02c.[01]literacy training and awareness content is updated [Organization-defined: frequency];
- AT-02c.[02]literacy training and awareness content is updated following [Organization-defined: events];
- AT-02d.lessons learned from internal or external security incidents or breaches are incorporated into literacy training and awareness techniques.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness implementation
- appropriate codes of federal regulations
- security and privacy literacy training curriculum
- security and privacy literacy training materials
- training records
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for literacy training and awareness
- organizational personnel with information security and privacy responsibilities
- organizational personnel comprising the general system user community
Test
- Mechanisms managing information security and privacy literacy training
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
AT-2(1) — Practical Exercises
Provide practical exercises in literacy training that simulate events and incidents.
Official discussion
Practical exercises include no-notice social engineering attempts to collect information, gain unauthorized access, or simulate the adverse impact of opening malicious email attachments or invoking, via spear phishing attacks, malicious web links.
Assessment objectives and methods
practical exercises in literacy training that simulate events and incidents are provided.
Examine
- System security plan
- privacy plan
- security awareness and training policy
- procedures addressing security awareness training implementation
- security awareness training curriculum
- security awareness training materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for security awareness training
- organizational personnel with information security responsibilities
Test
- Mechanisms implementing cyber-attack simulations in practical exercises
Related controls
AT-2(2) — Insider Threat
Provide literacy training on recognizing and reporting potential indicators of insider threat.
Official discussion
Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information not required for job performance; unexplained access to financial resources; bullying or harassment of fellow employees; workplace violence; and other serious violations of policies, procedures, directives, regulations, rules, or practices. Literacy training includes how to communicate the concerns of employees and management regarding potential indicators of insider threat through channels established by the organization and in accordance with established policies and procedures. Organizations may consider tailoring insider threat awareness topics to the role. For example, training for managers may be focused on changes in the behavior of team members, while training for employees may be focused on more general observations.
Assessment objectives and methods
- AT-02(02)[01]literacy training on recognizing potential indicators of insider threat is provided;
- AT-02(02)[02]literacy training on reporting potential indicators of insider threat is provided.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness implementation
- literacy training and awareness curriculum
- literacy training and awareness materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for literacy training and awareness
- organizational personnel with information security and privacy responsibilities
Related controls
AT-2(3) — Social Engineering and Mining
Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.
Official discussion
Social engineering is an attempt to trick an individual into revealing information or taking an action that can be used to breach, compromise, or otherwise adversely impact a system. Social engineering includes phishing, pretexting, impersonation, baiting, quid pro quo, thread-jacking, social media exploitation, and tailgating. Social mining is an attempt to gather information about the organization that may be used to support future attacks. Literacy training includes information on how to communicate the concerns of employees and management regarding potential and actual instances of social engineering and data mining through organizational channels based on established policies and procedures.
Assessment objectives and methods
- AT-02(03)[01]literacy training on recognizing potential and actual instances of social engineering is provided;
- AT-02(03)[02]literacy training on reporting potential and actual instances of social engineering is provided;
- AT-02(03)[03]literacy training on recognizing potential and actual instances of social mining is provided;
- AT-02(03)[04]literacy training on reporting potential and actual instances of social mining is provided.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness implementation
- literacy training and awareness curriculum
- literacy training and awareness materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for literacy training and awareness
- organizational personnel with information security and privacy responsibilities
AT-2(4) — Suspicious Communications and Anomalous System Behavior
Provide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [Organization-defined: indicators of malicious code].
Official discussion
A well-trained workforce provides another organizational control that can be employed as part of a defense-in-depth strategy to protect against malicious code coming into organizations via email or the web applications. Personnel are trained to look for indications of potentially suspicious email (e.g., receiving an unexpected email, receiving an email containing strange or poor grammar, or receiving an email from an unfamiliar sender that appears to be from a known sponsor or contractor). Personnel are also trained on how to respond to suspicious email or web communications. For this process to work effectively, personnel are trained and made aware of what constitutes suspicious communications. Training personnel on how to recognize anomalous behaviors in systems can provide organizations with early warning for the presence of malicious code. Recognition of anomalous behavior by organizational personnel can supplement malicious code detection and protection tools and systems employed by organizations.
Organization-defined parameters (1)
Assessment objectives and methods
literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [Organization-defined: indicators of malicious code] is provided.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness implementation
- literacy training and awareness curriculum
- literacy training and awareness materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for basic literacy training and awareness
- organizational personnel with information security and privacy responsibilities
AT-2(5) — Advanced Persistent Threat
Provide literacy training on the advanced persistent threat.
Official discussion
An effective way to detect advanced persistent threats (APT) and to preclude successful attacks is to provide specific literacy training for individuals. Threat literacy training includes educating individuals on the various ways that APTs can infiltrate the organization (e.g., through websites, emails, advertisement pop-ups, articles, and social engineering). Effective training includes techniques for recognizing suspicious emails, use of removable systems in non-secure settings, and the potential targeting of individuals at home.
Assessment objectives and methods
literacy training on the advanced persistent threat is provided.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness implementation
- literacy training and awareness curriculum
- literacy training and awareness materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for basic literacy training and awareness
- organizational personnel with information security and privacy responsibilities
AT-2(6) — Cyber Threat Environment
- (a)Provide literacy training on the cyber threat environment; and
- (b)Reflect current cyber threat information in system operations.
Official discussion
Since threats continue to change over time, threat literacy training by the organization is dynamic. Moreover, threat literacy training is not performed in isolation from the system operations that support organizational mission and business functions.
Assessment objectives and methods
- AT-02(06)(a)literacy training on the cyber threat environment is provided;
- AT-02(06)(b)system operations reflects current cyber threat information.
Examine
- System security plan
- privacy plan
- literacy training and awareness policy
- procedures addressing literacy training and awareness training implementation
- literacy training and awareness curriculum
- literacy training and awareness materials
- other relevant documents or records
Interview
- Organizational personnel who receive literacy training and awareness
- organizational personnel with responsibilities for basic literacy training and awareness
- organizational personnel with information security and privacy responsibilities
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.