PR.AT-04

Have senior executives been formally trained on and demonstrated understanding of their specific cybersecurity roles and responsibilities?

Explanation

Executive accountability is the focus: reviewers want senior leaders formally trained on their specific cybersecurity roles and able to demonstrate they understand them. Senior executives must comprehend their decision-making authority, oversight responsibilities, and accountability for security incidents that may impact the organization.

Evidence of fulfillment could include: documented role descriptions for executives that outline security responsibilities; signed acknowledgments from executives confirming their understanding; meeting minutes showing executive participation in security governance discussions; completion certificates from executive-level security awareness training; or performance objectives that include security governance metrics.

Context

Function
PR: PROTECT
Category
PR.AT: Awareness and Training
Sub-Category
Senior executives understand their roles and responsibilities

Related questions