Skip to content

Awareness & Training

Awareness & Training is the people layer. Technical controls fail when people don’t know the policies, don’t recognize threats, or don’t understand their responsibilities.

Everyone (3.2.1) — All staff get security awareness training covering CUI risks and your specific policies. Documented, tracked, annual refresher.

Security Roles (3.2.2) — Admins, security staff, and incident responders get additional training specific to their duties. A sysadmin who hardens servers needs different training than the receptionist.

Insider Threat (3.2.3) — All staff are trained to recognize insider threat indicators and have a confidential reporting path.


RefShort NameWhat It Covers
3.2.1Train EveryoneSecurity awareness for all CUI users
3.2.2Role-Specific TrainingTraining matched to security responsibilities
3.2.3Spot the Insider ThreatRecognize and report insider threat indicators