Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.2.2OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.2.2Security duty training

3.2 Awareness and Training · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Anyone with an assigned security duty must be trained to perform it — the person running the firewall knows the firewall, the person reviewing logs knows what normal looks like. Awareness posters do not cover this; the requirement is about competence in specific duties, and in a small shop those duties concentrate in one or two people.

Across revisions

Carried into Rev. 3 as Role-Based Training (03.02.02) with equivalent substance; frequency and content updates become organization-defined parameters.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: Training personnel to carry out their assigned security duties is precisely this practice's core activity: a roles-to-competencies map, role-based training booked against the largest gaps, and cross-training so no duty is one person deep.

What this does not claim: Supports implementation of the requirement; it does not decide an assessment outcome on its own. Security duties also sit outside the technical team — HR handling terminations, shipping handling marked media — and those roles need duty training the practice as written does not reach.

Practice-side activities
  • Maintain a role-to-competency matrix with tracked currency
  • Book role-based training against identified gaps and cross-train single-person dependencies
  • Feed exercise findings back into the training plan
Evidence this produces
  • The roles-to-skills plan with completion evidence retained
  • Skills-coverage and exercise-outcome tracking over time

Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Write down who operates each security-relevant capability — identity, endpoints, backup, response — and what each role needs to know; the gaps become the training plan.
  • Cross-train against single-person dependencies, because a duty only one person can perform is a duty that lapses on their first vacation.
  • Remember non-IT duties: the office manager who signs visitors in and the shipping clerk who handles marked media carry security duties too.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • A role-to-competency record showing what each security-relevant role requires
  • Training completion or certification records for the people holding those roles
  • A currency check showing training kept pace with tooling changes

Suggested owners, derived from the mapped practices and artifacts: Executive sponsor · IT leader · Executive sponsor or HR lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated