Control statement
a. Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-based security and privacy training; and
b. Retain individual training records for {{ insert: param, at-04_odp }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-CED-01 | General Training _Persistently_ review the effectiveness of training given to all employees on policies, procedures, and security-related topics. | Cybersecurity Education |