NIST Special Publication 800-53 (Rev. 4)

Security and Privacy Controls for Federal Information Systems and Organizations

AT-4 SECURITY TRAINING RECORDS

Family:
Awareness and Training
Class:
Priority:
P3 - Implement P3 security controls after implementation of P1 and P2 controls.
Baseline Allocation:
Low Moderate High
AT-4
AT-4
AT-4

Control Description

The organization:

a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and

b. Retains individual training records for [Assignment: organization-defined time period].

Supplemental Guidance

Documentation for specialized training may be maintained by individual supervisors at the option of the organization.

Related to: AT-2AT-3PM-14

Control Enhancements

None.

References

None.