Skip to content

AT-2: Literacy Training and Awareness

An OSCAL Control

Statement

    • a.

      Provide security and privacy literacy training to system users (including managers, senior executives, and contractors):

      • 1.

        As part of initial training for new users and thereafter; and

      • 2.

        When required by system changes or following ;

    • b.

      Employ the following techniques to increase the security and privacy awareness of system users ;

    • c.

      Update literacy training and awareness content and following ; and

    • d.

      Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.