Awareness and Training (PR.AT)

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

Subcategories

PR.AT-01

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

PR.AT-02

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

PR.AT-03

Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities

[Withdrawn: Incorporated into PR.AT-01, PR.AT-02]

PR.AT-04

Senior executives understand their roles and responsibilities

[Withdrawn: Incorporated into PR.AT-02]

PR.AT-05

Physical and cybersecurity personnel understand their roles and responsibilities

[Withdrawn: Incorporated into PR.AT-02]