The Awareness and Training (AT) objective is based around the policies and procedures in place at a 3pao to properly inform employees of security risks and provide the appropriate training to identify and mitigate the common issues that put organizations at risk. Additionally, the controls assist in providing sufficient audit evidence and also being able to hold employees accountable for their actions.
- Security Awareness and Training Policy and Procedures
- Security Awareness
- Security Training
- Security Training Records
← FedRAMP FAQ