Skip to content

AT-3: Role-based Training

An OSCAL Control

Statement

    • a.

      Provide role-based security and privacy training to personnel with the following roles and responsibilities: :

      • 1.

        Before authorizing access to the system, information, or performing assigned duties, and thereafter; and

      • 2.

        When required by system changes;

    • b.

      Update role-based training content and following ; and

    • c.

      Incorporate lessons learned from internal or external security incidents or breaches into role-based training.