KSI-CED-RATReviewing All Training
The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.
Mapped NIST 800-53 controls (11)
- KSI only11
The mark says whether an authored AWS recipe fetches evidence for the control; the tier strip shows which Rev5 baselines also require it — where automated KSI evidence doubles as Rev5 control evidence. = in the class B, C and D baselines, left to right
- recipe— an authored recipe collects evidence for this control
- KSI only— a Key Security Indicator reaches it, but no recipe is authored yet
- orphan— no Key Security Indicator reaches it — a person writes it up instead
- KSI onlyAT-02ATIn baseline B, C, D
- KSI onlyAT-02 (02)ATIn baseline B, C, D
- KSI onlyAT-02 (03)ATIn baseline C, D
- KSI onlyAT-03ATIn baseline B, C, D
- KSI onlyAT-03 (05)ATIn no class baseline
- KSI onlyAT-04ATIn baseline B, C, D
- KSI onlyCP-03CPIn baseline B, C, D
- KSI onlyIR-02IRIn baseline B, C, D
- KSI onlyIR-02 (03)IRIn no class baseline
- KSI onlyPS-06PSIn baseline B, C, D
- KSI onlySR-11 (01)SRIn baseline B, C, D
Collect evidence (0)
Authored AWS and pipeline recipes whose output is evidence for KSI-CED-RAT. This mapping is this project’s opinion (AWS overlay v3.0.0, pipeline overlay v0.8.0), versioned separately from the dataset — the upstream FedRAMP rules name none of these tools.
No authored recipe proves KSI-CED-RAT yet. That is an authoring gap, not a claim that nothing can — the unwritten indicators are enumerated on the class B narrative register.
Default evidence owed by every indicator (5)
From info.default_artifacts.KSI — no indicator carries its own artifacts; requirement-specific evidence lives on /evidence.
- Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
- Explanation of the cycle for any measures that are implemented persistently (if applicable).
- Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
- Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
- Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
Defined terms used (3)
- Incident
- Has the meaning given in 44 USC § 3552 (b)(2) which is "an occurrence that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies."
- Persistently
- Occurring in a firm, steady way that is repeated over a long period of time in spite of obstacles or difficulties. Persistent activities may vary between actors, may occur irregularly, and may include interruptions or waiting periods between cycles. These attributes of persistent activities should be intentional, understood, and documented; the status of persistent activities will always be known.
- Vulnerability Response
- The systematic process of tracking, evaluating, mitigating, monitoring, remediating, assessing exploitation, reporting, and otherwise managing detected vulnerabilities.
The Cybersecurity Education run (1)
0/1 have an authored AWS recipe- no authored recipeKSI-CED-RATReviewing All Trainingyou are here