Security awareness training is foundational
Security awareness training is mandatory for all companies under any compliance framework. It doesn’t matter what standard or framework your company adheres to; security awareness training is required. You can see this in Table 7.1 which maps security standards and frameworks to the sections that cover security awareness training:
Standard/Framework |
Section |
NIST CSF |
PR.AT-1 |
NIST 800-53 |
AT-2, PM-13 |
CIS |
14 |
PCI |
12.6 |
HIPAA |
164.308(a)(5)(i) |
CMMC |
AT.L2-3.2.3 AT.L2-3.2.1 |
ISO 27001 |
... |