Why: The requirement names managers, systems administrators, and users as the populations to be made aware of security risks; the practice's role mapping and recurring training rhythm work directly on the administrator and manager slices of that population.
What this does not claim: Supports implementation of the requirement for the technical and leadership roles the practice concentrates on; the general user population's awareness program is separate work the practice does not carry. Records for the whole population, not just technical staff, are what an assessor examines within the organization's defined system boundary.
- Map each core defensive capability to its operators and train against the largest gaps first
- Run recurring exercises that keep risk awareness current rather than annual
- Role-to-operator mapping with identified gaps
- Training and exercise completion records for technical and leadership roles
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06