{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Awareness & Training","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TRAIN-01","description":"Provide security and privacy awareness training to all personnel as part of onboarding, at least annually thereafter, and when threats, policies, or systems change materially. Include practical exercises reflecting current threats, such as phishing simulations and social-engineering awareness, and update content based on lessons learned and emerging risks. Require timely completion as a condition of continued system access.","details":{"control_category":"administrative","control_type":"preventive","domain":"Awareness & Training","guidance":[],"members":[{"control_id":"AT-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AT-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.6.3","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"500.14","coverage":"partial","delta":"authorized-user activity monitoring and email/web filtering prongs not covered","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"Provide security and privacy awareness training to all personnel as part of onboarding, at least annually thereafter, and when threats, policies, or systems change materially. Include practical exercises reflecting current threats, such as phishing simulations and social-engineering awareness, and update content based on lessons learned and emerging risks. Require timely completion as a condition of continued system access.","title":"Deliver security awareness training to all personnel","unified_id":"UC-TRAIN-01"},"id":"uc:UC-TRAIN-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TRAIN-01","sourceIds":["iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"UC-TRAIN-01 — Deliver security awareness training to all personnel","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04a6d208fc62e199456b186b546a117766f45f54a64aeed4d2363ae94b8f1298","properties":{"rationale":"Control explicitly runs phishing simulations and social-engineering awareness, directly lowering susceptibility to deception/credential theft.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06caba359dc2d65a4c9d56804c34395ff5e555522dff95ca64b630e97981f249","properties":{"rationale":"Training on safe use of email/messaging gives the guidance that reduces inadvertent disclosure via insecure channels even absent a formal AUP.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-no-acceptable-use-policy-e874ca5c.json","targetId":"risk:aware-no-acceptable-use-policy","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:358b69c65fd3738651f16989f96b72debda0886e39521e36e7e4bf3064c3773b","properties":{"rationale":"Delivering security & privacy awareness training to all personnel is the direct first-order defense against the inadequate-awareness gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-insufficient-training-7cb09d2f.json","targetId":"risk:aware-insufficient-training","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:463bec64bc01df31b9a94cd1c057161fd031347bb01b81ca0978059a8d63346f","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","targetId":"uc:UC-TRAIN-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:556521b6603b104e9322fef7747b936a908990cf20d979a76fb761243d625383","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","targetId":"uc:UC-TRAIN-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:605827928cae6a01b48a3831a7516c4e9bd00231941030ed7ed7c482be457bb6","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","targetId":"uc:UC-TRAIN-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a7f08161288ce029a9ff09ceca2f15d66a7c1432464faeba040324abce84b91","properties":{"rationale":"General awareness cuts inadvertent sensitive-info mishandling, but the operative defense against the named operational errors (misconfiguration, privilege settings) is role-based training; general training only contributes.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8886e83192ee0838e39880eeaf15689ae3ff8afb5e964a790e21a83f31442c13","properties":{"control_id":"PR.AT-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-at-01-e5f1fe35.json","targetId":"ctrl:nist-csf-2:PR.AT-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ff93d7e4e334d9453ecbad99b8cd3527f3de070de51c8adc3daad60b069d2b6","properties":{"control_id":"A.6.3","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-3-b9bb8fbd.json","targetId":"ctrl:iso-27001:A.6.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad5c470d3acd9952e494e7d4cb2470c44d8347b0648827887adf264d04a114b7","properties":{},"sourceDetailPath":"/data/v1/records/wf-c15-3675020d.json","sourceId":"wf:C15","targetDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","targetId":"uc:UC-TRAIN-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:af38eec7a8f928c5a9042ad4d5ea80f3bef11e25dd5ac3a101697e71f9b73a75","properties":{"rationale":"Annual all-personnel refresh supplies the ongoing-awareness component of the gap; the role-specific core is delivered by UC-TRAIN-02.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-role-based-training-gap-3e2ca2c3.json","targetId":"risk:aware-role-based-training-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cc42ae43a07e6751affbd567aa46907a8bcb7af8d8d84616257c0cbb2fcbc6a1","properties":{"control_id":"500.14","coverage":"partial","delta":"authorized-user activity monitoring and email/web filtering prongs not covered","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-14-d15e0ff2.json","targetId":"ctrl:nydfs-500:500.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db5763c540f39e6a6769a92931c66561b81ada24ceb1a3aa1ceb13d1f24ac749","properties":{"control_id":"AT-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-at-2-8a8c6b57.json","targetId":"ctrl:nist-800-53:AT-2","type":"maps_to"}],"schemaVersion":1}
