3.2 Awareness & Training5 pts

3.2.1 — Make everyone security-aware

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

Managers, admins, and users know the risks and the rules.

What it actually means

Security awareness training for everyone who touches the environment — not a one-time slideshow, but ongoing awareness of the risks in their day-to-day work and the policies they're expected to follow. It's a 5-pointer because people are the most-exploited part of any system.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Awareness & Training (3.2)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.