Awareness and Training Plan
Documents how the system's user, administrator, and developer populations are trained in security awareness, role-based duties, insider-threat indicators, social-engineering / phishing recognition, and how training records are maintained. Covers the controls of the AT family in NIST SP 800-53 r5 and aligns with NIST SP 800-50 (Building an Information Technology Security Awareness and Training Program), NIST SP 800-181 r1 (NICE Workforce Framework), DoD 8140.03 (Cyberspace Workforce Qualification and Management), and Federal Information Security Modernization Act (FISMA) annual training requirements.