Awareness and Training (PR.AT)
The employees at your company are your eyes and ears when it comes to cybersecurity. They are your first line of defense. The employees will often see new threats against your facility before you do. Security awareness and training are not meant just for the cybersecurity professional; it is meant for everyone in the company.
PR.AT-01
There is a difference between security awareness and training. Security awareness is meant to provide generalized cybersecurity awareness within the facility. This can mean posting flyers or posters throughout the organization promoting cybersecurity topics. This is meant primarily for those outside of IT.
Security training, on the other hand, is more targeted or focused on cybersecurity topics that provide in-depth knowledge of a particular area. For example,...