1Overview
AT.L2-3.2.3 closes the Awareness and Training family and narrows awareness to a specific and sensitive subject: the insider threat. It requires security awareness training on recognizing and reporting the potential indicators of insider threat, so that the workforce can notice and raise concerns about risks that originate from within. Unlike the two five-point controls before it, this is a one-point requirement and may be deferred on a plan of action.
The insider threat is different from the external one because it comes from people who already have legitimate access. It need not be malicious; a well-meaning employee mishandling CUI, a disgruntled one considering taking data, a person under pressure making poor choices, all fall within it. The control recognizes that the people best positioned to notice early indicators are coworkers, and it asks the organization to identify those indicators and train managers and employees to recognize and report them. The emphasis is as much on reporting as on recognizing, because an indicator noticed but never raised does no good, and the reporting path has to feel safe to use.
Provide security awareness training on recognizing and reporting potential indicators of insider threat.
The requirement pairs recognizing with reporting. To recognize is to know what the potential indicators of insider threat are, from unusual data access to attempts to bypass controls to behavioral signs. To report is to have a path by which a concern can be raised, ideally one that is clear and non-punitive, so that an observation becomes a report rather than a private worry. The training is directed at managers and employees together, since both are positioned to observe and both need to know how to respond.
2The Assessment Objectives
NIST SP 800-171A frames 3.2.3 around two objectives: identify the indicators, and provide the training on recognizing and reporting them.
Potential indicators associated with insider threat are identified. The organization has articulated what the signs of insider threat look like, so the training can convey them.
Security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. The workforce is trained both to recognize the indicators and to report them.
The two objectives are identification of the indicators and training on both recognizing and reporting them. The common gap is at objective [b] on the reporting half, where training describes what to watch for but never gives a clear, safe path to raise a concern, leaving observations unreported. The assessor looks for training that reaches managers and employees and covers reporting as well as recognition.
3Failure Patterns
The failures are about skipping the topic, covering recognition without reporting, and a reporting path that no one trusts.
The topic left out entirely
Because insider threat is uncomfortable, some awareness programs omit it, covering external threats and handling but never the internal risk. That leaves objective [b] unmet outright, and the workforce unprepared to notice the risks that come from within.
Recognizing without reporting
Training that lists the indicators but never explains how or where to report a concern covers half the requirement. The control pairs recognizing with reporting deliberately, and an indicator that a coworker notices but has no clear way to raise is an indicator that does no good.
A reporting path no one trusts
Where reporting feels like informing on a colleague and carries the risk of blame, people will not use it even if it exists. The training and the surrounding culture have to make reporting feel like a normal, non-punitive act, or the reporting objective is met on paper while going unused in practice.
No record of the training
Insider-threat awareness delivered without any record of who received it cannot be demonstrated. As with the rest of the family, the objective is shown through evidence that managers and employees were trained, so completion records and dated content carry the requirement.
4Ownership
This control is owned by the security program alongside human resources, since the reporting path and the non-punitive culture around it are as much an HR matter as a security one.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Identifies the insider-threat indicators and delivers the awareness training on recognizing and reporting them. Owns the training records. |
| Human resources | Helps define a reporting path that is clear and non-punitive, since the willingness to report depends on how concerns are received and handled. |
| Managers | Receive the training as a named audience, model the reporting behavior, and are often the first point a concern is raised to. |
| All employees | Receive the training and understand both what to watch for and how to report it. |
5Tooling
The control is delivered through insider-threat awareness content and a defined reporting mechanism, with records to show it reached managers and employees.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Identified insider-threat indicators | The organization-relevant signs the training conveys, from unusual access to behavioral cues. |
| [b] delivery | Insider-threat awareness module for managers and employees | Training on recognizing the indicators and on how to report a concern, delivered to both audiences. |
| [b] reporting | A defined, non-punitive reporting channel | A clear and safe path by which an observed concern can be raised. |
| Evidence | Training completion records | The dated records showing managers and employees received the training. |
The caveat is that the reporting channel is as important as the content and harder to get right. A module can teach the indicators, but the requirement's reporting half depends on a channel people will actually use, which rests on the culture around it more than on any tool. The assessor examines the training content and completion records, and the reporting path it describes, so both the recognition content and a usable reporting mechanism have to be present.
6Evidence
The satisfied version of 3.2.3 shows the identified indicators, training for both audiences, and a reporting path.
| Evidence | What it demonstrates |
|---|---|
| Identified indicators | Objective [a]. The insider-threat indicators the training conveys. |
| Insider-threat training content | Objective [b]. Material covering recognition and reporting, aimed at managers and employees. |
| Reporting mechanism | Objective [b]. The defined, non-punitive path for raising a concern. |
| Completion records | Objective [b]. Dated evidence that managers and employees received the training. |
The evidence should show both halves of the requirement, recognition and reporting, delivered to managers and employees, with a reporting path the training points to. Training content that covers the indicators and a usable reporting channel, paired with completion records, is the clearest demonstration of the control.
Recognizing is half of it; reporting is the other half
Insider-threat awareness is straightforward to teach and easy to get half right, covering the warning signs while leaving people no trusted way to report. Building content that reaches managers and employees and pairing it with a clear, non-punitive reporting path is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.3[a] and 3.2.3[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov