HomeControl Library › 3.2.2
3.2 Awareness & Training5 pts

3.2.2 — Train people for their security duties

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

People with security responsibilities are trained to perform them.

What it actually means

Beyond general awareness, anyone with a specific security role (admins, the person who reviews logs, whoever handles incidents) needs role-specific training to actually do that job. General awareness covers everyone; this covers the people with duties.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library