1Overview
AT.L2-3.2.2 is the second five-point requirement in the Awareness and Training family, and it moves from general awareness to specific competence. Where 3.2.1 makes everyone aware of risks and rules, this control requires that people with assigned security duties be trained to actually carry them out. It too cannot be deferred on a plan of action.
General awareness and role-based training answer different questions. Awareness asks whether the workforce understands the risks; this control asks whether the people who hold security responsibilities can perform them. The administrator who manages accounts and permissions, the person who reviews audit logs, the one who handles incident response, each has duties that generic awareness does not prepare them for. The control asks the organization to define those security-related duties, assign them to specific people, and train those people to carry them out, so that the responsibilities the program depends on are held by people equipped to fulfill them rather than assigned in name only.
Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
The phrase "assigned information security-related duties and responsibilities" is the pivot. The control assumes those duties have been defined and assigned, and it requires training suited to them. That training is role-specific: an administrator needs training in the secure administration of the systems they run, an incident responder in the response process, a reviewer in what the logs should show. The five-point weight reflects that a security program is only as strong as the competence of the people running its moving parts.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.2.2 into three objectives: define the duties, assign them, and train the assigned personnel.
Information security-related duties, roles, and responsibilities are defined. The organization has articulated the security duties that people are expected to carry out.
Information security-related duties, roles, and responsibilities are assigned to designated personnel. Those defined duties are given to specific, named people.
Personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. The people who hold the duties are trained to perform them.
The three objectives move from defining duties to assigning them to training the assigned people. The common gap is at objective [c], where duties are assigned but the training is only the same general awareness everyone gets, which does not prepare a person for the specific security work they hold. The assessor looks for training matched to the assigned duties, not generic awareness standing in for it.
3Failure Patterns
The failures are about duties that are unassigned or untrained, and about role-based training collapsed into general awareness.
The accidental administrator
A small shop often has one person who became the system administrator by availability rather than training, holding powerful duties they were never prepared for. The person learns account management, permissions, and hardening by trial on production systems, which fails objective [c] and puts the security of the environment in untrained hands. Training suited to the administration duties is what the control requires.
General awareness standing in for role training
Where the only training anyone receives is the general awareness of 3.2.1, the people with specific security duties get nothing tailored to those duties. The two controls are distinct: awareness for everyone, role-based training for those with assigned responsibilities, and using one to satisfy the other leaves objective [c] unmet.
Duties assigned to no one
Security duties that are written down but assigned to no specific person fail objective [b], and untrained-because-unassigned work tends to fall through entirely. Log review that is nobody's job does not happen, and the control's chain from defined to assigned to trained breaks at the first missing link.
No record of the training
Role-based training that happened informally, with no record of who was trained on what, cannot be demonstrated. The objective is met through evidence that the assigned personnel were trained for their duties, so records tying training to the specific roles are what carry the requirement.
4Ownership
This control is owned by whoever manages the security program and the people in it, since defining and assigning duties is a management act and training follows from it.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines the security-related duties, ensures they are assigned, and arranges training suited to each. Owns the training records. |
| Executive sponsor | Backs the assignment of duties and the investment in training, since role-based training for administrators and responders often means external courses or certifications that need support. |
| IT and system administrators | Receive training matched to their administration duties, the role whose untrained exposure is the most common failure of this control. |
| Anyone holding a security duty | Incident responders, log reviewers, and others receive training for the specific responsibilities they hold. |
5Tooling
The control is delivered through role-appropriate training and the records that tie it to assigned duties. The tooling is largely the training itself, which for technical roles is often external.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Role definitions and a responsibility assignment | The defined security duties and the named people who hold them, the basis for targeted training. |
| [c] administration | Vendor and platform administration training, security configuration courses | Training the administrator in the secure operation of the systems they run. |
| [c] specialized | Incident response, log analysis, and related role training or certifications | Training for the specific security duties beyond administration, matched to each assigned role. |
| Evidence | Training completion records tied to roles | The dated records linking training to the assigned duties, which demonstrate the objective. |
The caveat is that the training must match the duty, not merely exist. A general course does not satisfy the requirement for a specialized duty, and the objective is met when the person holding a role is trained for that role, which for a small shop often means budgeting for external training the accidental administrator never had. The assessor examines the assigned duties and the training records together, looking for a match between the responsibility and the preparation.
6Evidence
The satisfied version of 3.2.2 shows defined and assigned duties and training records that match them.
| Evidence | What it demonstrates |
|---|---|
| Defined security duties | Objective [a]. The articulated security-related roles and responsibilities. |
| Responsibility assignment | Objective [b]. The named individuals holding each defined duty. |
| Role-based training records | Objective [c]. Dated evidence that assigned personnel were trained for their specific duties. |
| Certifications or course completions | Objective [c]. Where used, external training demonstrating competence for technical roles. |
The evidence should tie training to assigned duties, showing that the people holding security responsibilities were prepared for them rather than only exposed to general awareness. Records matching role-specific training to the named holders of each duty are the clearest demonstration, and because this control cannot sit on a plan of action, the training has to be in place at the time of assessment.
The accidental administrator needs real training
In many shops the person running the systems grew into the role without training for it, which is exactly the gap this five-point control targets. Defining the security duties, assigning them, and getting the people who hold them, the administrator especially, trained to carry them out is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.2[a] through 3.2.2[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing AT.L2-3.2.2 among the five-point basic security requirements. ecfr.gov