Ensures all OCSI personnel are aware of cybersecurity risks and trained in their responsibilities for protecting CUI — covering 3 controls per NIST SP 800-171 Rev 2.
OCSI shall ensure that all personnel are aware of cybersecurity risks associated with their activities and that they are adequately trained to carry out their assigned information security-related duties and responsibilities.
| Control | Requirement | Implementation | Status |
|---|---|---|---|
| 3.2.1 | Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems | NOT IMPLEMENTED. No formal security awareness training program exists. No training platform, no completion tracking, no CUI handling orientation. This is an organizational requirement that must be established. | Not Implemented |
| 3.2.2 | Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities | NOT IMPLEMENTED. No role-specific security training program. No documented training materials for Command Center administrators or CUI data handlers. | Not Implemented |
| 3.2.3 | Provide security awareness training on recognizing and reporting potential indicators of insider threat | NOT IMPLEMENTED. No insider threat awareness program. No training materials or assessment mechanism. | Not Implemented |