# AT-03 (05) Processing Personally Identifiable Information — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/at-3.5

Canonical id: `at-3.5` · family `AT`

> Provide [personnel or roles] with initial and [frequency] training in the employment and operation of personally identifiable information processing and transparency controls.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

_In no Rev5 baseline for any certification class._

## Key Security Indicators that reach it

- `KSI-CED-RAT` — Reviewing All Training (Cybersecurity Education)
  The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

## FedRAMP guidance

_No FedRAMP-specific guidance attaches to this control._
