to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Awareness and Training

Ensure that managers, system administrators, and users are aware of security risks.

Three requirements about people rather than machines: everyone knows the risks, the people with security duties are trained for them, and staff can recognise an insider threat. Small family, but two of the three are five-point requirements, and an assessor will ask to see the records.

  1. 3.2.1 Make sure people know the risks AT Level 2 5 pt
  2. 3.2.2 Train people for the security duties they hold AT Level 2 5 pt
  3. 3.2.3 Cover insider threat AT Level 2 1 pt