Skip to content

AT-1: Policy and Procedures

An OSCAL Control

Statement

    • a.

      Develop, document, and disseminate to :

      • 1.

        awareness and training policy that:

        • (a)

          Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

        • (b)

          Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and

      • 2.

        Procedures to facilitate the implementation of the awareness and training policy and the associated awareness and training controls;

    • b.

      Designate an to manage the development, documentation, and dissemination of the awareness and training policy and procedures; and

    • c.

      Review and update the current awareness and training:

      • 1.

        Policy and following ; and

      • 2.

        Procedures and following .