DKDavid Koran& Associates
Home The CMMC Guide Part III · Awareness and Training AT.L2-3.2.3
The CMMC Guide · Awareness and Training Family

AT.L2-3.2.3  Insider Threat Awareness

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Family
Awareness and TrainingAT, 3 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

AT.L2-3.2.3 closes the Awareness and Training family and narrows awareness to a specific and sensitive subject: the insider threat. It requires security awareness training on recognizing and reporting the potential indicators of insider threat, so that the workforce can notice and raise concerns about risks that originate from within. Unlike the two five-point controls before it, this is a one-point requirement and may be deferred on a plan of action.

The insider threat is different from the external one because it comes from people who already have legitimate access. It need not be malicious; a well-meaning employee mishandling CUI, a disgruntled one considering taking data, a person under pressure making poor choices, all fall within it. The control recognizes that the people best positioned to notice early indicators are coworkers, and it asks the organization to identify those indicators and train managers and employees to recognize and report them. The emphasis is as much on reporting as on recognizing, because an indicator noticed but never raised does no good, and the reporting path has to feel safe to use.

The requirement · NIST SP 800-171 Rev 2, 3.2.3

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

The requirement pairs recognizing with reporting. To recognize is to know what the potential indicators of insider threat are, from unusual data access to attempts to bypass controls to behavioral signs. To report is to have a path by which a concern can be raised, ideally one that is clear and non-punitive, so that an observation becomes a report rather than a private worry. The training is directed at managers and employees together, since both are positioned to observe and both need to know how to respond.

2The Assessment Objectives

NIST SP 800-171A frames 3.2.3 around two objectives: identify the indicators, and provide the training on recognizing and reporting them.

[a]

Potential indicators associated with insider threat are identified. The organization has articulated what the signs of insider threat look like, so the training can convey them.

MeetsThe organization has identified the indicators relevant to its environment: unusual access to CUI, attempts to circumvent controls, and behavioral signs.
FailsNo indicators are identified, so training on recognizing them has no definite content.
[b]

Security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. The workforce is trained both to recognize the indicators and to report them.

MeetsManagers and employees receive training covering the indicators and a clear, non-punitive way to report concerns, with the training recorded.
FailsInsider-threat awareness is skipped, or covers recognizing without ever explaining how or where to report.

The two objectives are identification of the indicators and training on both recognizing and reporting them. The common gap is at objective [b] on the reporting half, where training describes what to watch for but never gives a clear, safe path to raise a concern, leaving observations unreported. The assessor looks for training that reaches managers and employees and covers reporting as well as recognition.

3Failure Patterns

The failures are about skipping the topic, covering recognition without reporting, and a reporting path that no one trusts.

The topic left out entirely

Because insider threat is uncomfortable, some awareness programs omit it, covering external threats and handling but never the internal risk. That leaves objective [b] unmet outright, and the workforce unprepared to notice the risks that come from within.

Recognizing without reporting

Training that lists the indicators but never explains how or where to report a concern covers half the requirement. The control pairs recognizing with reporting deliberately, and an indicator that a coworker notices but has no clear way to raise is an indicator that does no good.

A reporting path no one trusts

Where reporting feels like informing on a colleague and carries the risk of blame, people will not use it even if it exists. The training and the surrounding culture have to make reporting feel like a normal, non-punitive act, or the reporting objective is met on paper while going unused in practice.

No record of the training

Insider-threat awareness delivered without any record of who received it cannot be demonstrated. As with the rest of the family, the objective is shown through evidence that managers and employees were trained, so completion records and dated content carry the requirement.

The common root
This control fails on the reporting half more than the recognizing half. It is easier to list warning signs than to build a reporting path people trust, and awareness that teaches recognition without a safe way to report leaves the concern sitting silently with the person who noticed it.

4Ownership

This control is owned by the security program alongside human resources, since the reporting path and the non-punitive culture around it are as much an HR matter as a security one.

RoleResponsibility for this control
Security or compliance leadIdentifies the insider-threat indicators and delivers the awareness training on recognizing and reporting them. Owns the training records.
Human resourcesHelps define a reporting path that is clear and non-punitive, since the willingness to report depends on how concerns are received and handled.
ManagersReceive the training as a named audience, model the reporting behavior, and are often the first point a concern is raised to.
All employeesReceive the training and understand both what to watch for and how to report it.
See also: This control completes the Awareness and Training family with AT.L2-3.2.1 and AT.L2-3.2.2, and connects to the audit and monitoring controls that can surface the technical indicators a person is trained to recognize.

5Tooling

The control is delivered through insider-threat awareness content and a defined reporting mechanism, with records to show it reached managers and employees.

ObjectivesToolingWhat it provides
[a]Identified insider-threat indicatorsThe organization-relevant signs the training conveys, from unusual access to behavioral cues.
[b] deliveryInsider-threat awareness module for managers and employeesTraining on recognizing the indicators and on how to report a concern, delivered to both audiences.
[b] reportingA defined, non-punitive reporting channelA clear and safe path by which an observed concern can be raised.
EvidenceTraining completion recordsThe dated records showing managers and employees received the training.

The caveat is that the reporting channel is as important as the content and harder to get right. A module can teach the indicators, but the requirement's reporting half depends on a channel people will actually use, which rests on the culture around it more than on any tool. The assessor examines the training content and completion records, and the reporting path it describes, so both the recognition content and a usable reporting mechanism have to be present.

6Evidence

The satisfied version of 3.2.3 shows the identified indicators, training for both audiences, and a reporting path.

EvidenceWhat it demonstrates
Identified indicatorsObjective [a]. The insider-threat indicators the training conveys.
Insider-threat training contentObjective [b]. Material covering recognition and reporting, aimed at managers and employees.
Reporting mechanismObjective [b]. The defined, non-punitive path for raising a concern.
Completion recordsObjective [b]. Dated evidence that managers and employees received the training.

The evidence should show both halves of the requirement, recognition and reporting, delivered to managers and employees, with a reporting path the training points to. Training content that covers the indicators and a usable reporting channel, paired with completion records, is the clearest demonstration of the control.

Recognizing is half of it; reporting is the other half

Insider-threat awareness is straightforward to teach and easy to get half right, covering the warning signs while leaving people no trusted way to report. Building content that reaches managers and employees and pairing it with a clear, non-punitive reporting path is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.3[a] and 3.2.3[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Awareness and Training
AT.L2-3.2.2 · Role-Based Training
Next: Audit and Accountability →
AU.L2-3.3.1 · System Audit Logging
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AT.L2-3.2.3 · Edition 2026.1 · Last reviewed July 12, 2026