Framework Category

Awareness and Training

Awareness and Training equips all personnel—including specialized roles, executives, and third-party stakeholders—with the knowledge and skills needed to recognize and manage cybersecurity risks relevant to their responsibilities.

It promotes a shared understanding of security roles across the organization.

Implementation Questions

PR.AT-01

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

NIST CSF Awareness and Training (PR.AT-01) — Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind: implementation questions and what each one covers
QuestionWhat it covers
Does your organization provide cybersecurity awareness and training to all users with access to non-public resources?Cybersecurity awareness training helps users recognize and respond appropriately to security threats like phishing, social engineering, and data handling requirements. This training should be provided to all individuals with access to sensitive information, including employees, contractors, partners, and suppliers, as they all represent potential security vulnerabilities if not properly educated.
Does your organization provide comprehensive security awareness training that covers social engineering recognition, attack reporting procedures, acceptable use policies, and basic cyber hygiene practices?Security awareness training is essential for creating a human firewall against common attacks like phishing, vishing, and pretexting. Employees should be trained to identify suspicious emails, messages, or calls, know how to report security incidents, understand acceptable use of company resources, and perform basic security practices such as using strong passwords, enabling multi-factor authentication, and keeping software updated.
Does your organization clearly communicate the consequences of cybersecurity policy violations to all employees and stakeholders?Consequences for policy breaches are the subject: reviewers want assurance that the penalties for violating cybersecurity policies are clearly communicated to employees and stakeholders.
Does your organization regularly assess employees' cybersecurity awareness through testing or evaluation?Regular assessment of employee cybersecurity knowledge helps identify gaps in understanding and ensures staff can recognize and respond appropriately to security threats like phishing, social engineering, and data handling requirements. These assessments establish accountability and reinforce the importance of security practices in daily operations.
Does your organization require annual refresher training for all employees to reinforce existing security practices and introduce new ones?Regular refresher training helps maintain security awareness and ensures employees stay updated on evolving threats and organizational security practices. Annual refreshers can address common security mistakes observed throughout the year, introduce new security tools or procedures, and reinforce critical security behaviors that may have weakened over time.

PR.AT-02

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

NIST CSF Awareness and Training (PR.AT-02) — Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind: implementation questions and what each one covers
QuestionWhat it covers
Has the organization identified specialized roles that require additional cybersecurity training beyond the baseline security awareness program?Different roles within an organization face different security risks and responsibilities.
Does your organization provide specialized cybersecurity training for employees and third parties (contractors, partners, suppliers) who perform roles with elevated security responsibilities?Role-based cybersecurity training ensures that individuals with specialized responsibilities receive targeted education beyond basic awareness training. For example, developers should receive secure coding training, system administrators should learn about secure configuration, and procurement staff should understand third-party risk management.
Does your organization conduct regular assessments or tests to evaluate employees' understanding of role-specific cybersecurity practices?Role-specific cybersecurity assessments help ensure that employees understand the security requirements unique to their job functions, which can significantly reduce the risk of security incidents caused by human error.
Does your organization require annual refresher training for all employees to reinforce existing security practices and introduce new ones?Regular security refresher training ensures employees maintain awareness of security policies, procedures, and best practices while also introducing them to emerging threats and countermeasures. Annual refreshers help combat the natural decay of security knowledge over time and ensure staff are updated on new security requirements or organizational changes.

PR.AT-03

Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities

NIST CSF Awareness and Training (PR.AT-03) — Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities: implementation questions and what each one covers
QuestionWhat it covers
Have you established a formal program to ensure third-party stakeholders (suppliers, customers, partners) understand their cybersecurity roles and responsibilities?Educating external parties on their security duties is the focus here: whether you run a formal program ensuring suppliers, customers, and partners understand their cybersecurity roles and responsibilities. Effective third-party security awareness helps prevent incidents caused by external stakeholders who may not be familiar with your security requirements or who might inadvertently introduce risks.

PR.AT-04

Senior executives understand their roles and responsibilities

NIST CSF Awareness and Training (PR.AT-04) — Senior executives understand their roles and responsibilities: implementation questions and what each one covers
QuestionWhat it covers
Have senior executives been formally trained on and demonstrated understanding of their specific cybersecurity roles and responsibilities?Executive accountability is the focus: reviewers want senior leaders formally trained on their specific cybersecurity roles and able to demonstrate they understand them. Senior executives must comprehend their decision-making authority, oversight responsibilities, and accountability for security incidents that may impact the organization.

PR.AT-05

Physical and cybersecurity personnel understand their roles and responsibilities

NIST CSF Awareness and Training (PR.AT-05) — Physical and cybersecurity personnel understand their roles and responsibilities: implementation questions and what each one covers
QuestionWhat it covers
Have all physical and cybersecurity personnel been trained on and demonstrated understanding of their specific roles and responsibilities?Role clarity for security staff is what's being verified: whether physical and cybersecurity personnel have been trained on, and can demonstrate, their specific responsibilities. Without clear role definition and proper training, security personnel may respond inconsistently to incidents, miss critical security tasks, or create gaps in your security posture due to confusion about who handles what responsibilities.

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron