{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Awareness & Training","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TRAIN-02","description":"Identify roles with significant security, privacy, or elevated-risk responsibilities (e.g., administrators, developers, incident responders, senior leaders) and provide role-based training before access or duties are granted, when systems or duties change, and at least annually. Maintain a qualified security and privacy workforce through defined competencies, development plans, and recruitment and retention practices for security staff.","details":{"control_category":"administrative","control_type":"preventive","domain":"Awareness & Training","guidance":[],"members":[{"control_id":"AT-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AT-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"PM-13","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Identify roles with significant security, privacy, or elevated-risk responsibilities (e.g., administrators, developers, incident responders, senior leaders) and provide role-based training before access or duties are granted, when systems or duties change, and at least annually. Maintain a qualified security and privacy workforce through defined competencies, development plans, and recruitment and retention practices for security staff.","title":"Train personnel with specialized security roles and duties","unified_id":"UC-TRAIN-02"},"id":"uc:UC-TRAIN-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TRAIN-02","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TRAIN-02 — Train personnel with specialized security roles and duties","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3cffa2621074794e1d73b5bdbfe8e397637d8e0dff11b847f99710a4ba66bd87","properties":{"rationale":"Delivering role-based training to admins/devs/IR/leaders before access and on change is the direct closure of the role-based training gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-aware-role-based-training-gap-3e2ca2c3.json","targetId":"risk:aware-role-based-training-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:498a99a138d433d039c4eb556882f39f1edc7a5c54a67791a8dce0a0f79141b3","properties":{"rationale":"Role-based training of privacy-responsible staff who design notices/consent flows reduces inadequate-notice and dark-pattern design.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-data-transparency-notice-dark-patterns-9326fdf0.json","targetId":"risk:data-transparency-notice-dark-patterns","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64c73a32b10bf3e12c583ecf05ca62d03621a735a331e46557d71f08ee3e5ca8","properties":{"rationale":"Role-based training raises the security competency of high-risk roles, reducing the overall training-adequacy gap for that population.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-aware-insufficient-training-7cb09d2f.json","targetId":"risk:aware-insufficient-training","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a719b66719db37dbad8afddc1978a5f8f76e7b036f2710e5e64d0b6e3f993f6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c15-3675020d.json","sourceId":"wf:C15","targetDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","targetId":"uc:UC-TRAIN-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8840228b5792bb5a13d1dba4bce91c17d5c5fdd378732ee53e697cddc84f2adf","properties":{"control_id":"PR.AT-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-at-02-179bcd35.json","targetId":"ctrl:nist-csf-2:PR.AT-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a306191484e064184a32a2288870f1db77fce30cf40f37506d571daa159e0c64","properties":{"control_id":"PM-13","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-13-bc63c843.json","targetId":"ctrl:nist-800-53:PM-13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c5e343da88e7cad219e4ad0e373a945da75f672d6cf35a70d1981b80e25d3bff","properties":{"control_id":"AT-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-at-3-003c8052.json","targetId":"ctrl:nist-800-53:AT-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf9a9de4f93bdcbe6c30703ff757a5cf8fdd0ed6812075e12406eb84de743794","properties":{"rationale":"Role-based training for administrators directly reduces the misconfiguration and incorrect-privilege-setting errors the risk names.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f03995f9ce07a0711c5ff0a5bddd73b8ff642f1d17b626a734053d230f07e39b","properties":{"rationale":"Role-based training for senior leaders and privileged staff directly defends against executive-targeted spear-phishing/BEC.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"}],"schemaVersion":1}
