| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Rev 3 | Rev 2 | Audience | Basic Cybersecurity training | Acceptable Use Policy | Mandatory CUI Training | Role specific CUI Training | Baseline Certifications | IT Training | Internal Risk | Risk Assessment | Incident Respsonse | Incident Response Tabletops | Supply Chain Risks | JIT Awareness Messaging | Knowledge Base | ||||||||||
2 | Participate in annual risk assessment | 03.02.01 | 3.2.1 | Management | x | x | x | |||||||||||||||||||
3 | Users are made aware of security risks to CUI in the System | 03.02.01 | 3.2.1 | All employees | x | x | x | x | ||||||||||||||||||
4 | Acknowledge and follow rules for system use and protecting CUI before access is authorized. | 03.15.03 | new | In scope employees | x | x | x | |||||||||||||||||||
5 | Use approved external system only | 03.01.20 | 3.1.20 | All employees | x | x | x | x | ||||||||||||||||||
6 | Control the use of removable media on system components. | 03.08.07 | 3.8.7 | In scope employees | x | x | x | |||||||||||||||||||
7 | Use only approved systems for the storing, processing, or transmitting CUI | 03.01.20 | 3.1.20 | In scope employees | x | x | ||||||||||||||||||||
8 | Prohibit portable storage devices with no identifiable owner. | 03.08.07 | 3.8.8 | All employees | x | x | x | |||||||||||||||||||
9 | Describe strategies for preventing CUI from being posted to a public system | 03.01.22 | 3.1.22 | In scope employees | x | x | ||||||||||||||||||||
10 | Identity company policies that govern your security program | 03.15.01 | new | Management/ISSO | ||||||||||||||||||||||
11 | Define authorized alternate sites and the organization-selected safeguards required at those sites. | 03.10.06 | 3.10.6 | In scope employees | x | |||||||||||||||||||||
12 | Enforce safeguarding measures for CUI at alternate work sites. | 03.10.06 | 3.10.6 | In scope employees | x | x | ||||||||||||||||||||
13 | Define common indicators of Insider Risk | 03.02.01 | 3.2.3 | All employees | x | x | ||||||||||||||||||||
14 | Recognize idicators of Insider Risk | 03.02.01 | 3.2.3 | In scope employees | x | |||||||||||||||||||||
15 | Describe the methods of social engineering | 03.02.01 | 3.2.1 | All employees | x | x | ||||||||||||||||||||
16 | Summarize social mining techniques | 03.02.01 | 3.2.1 | All employees | x | x | ||||||||||||||||||||
17 | Complete Incident Response training | 03.06.04 | new | Incident Response Team | ||||||||||||||||||||||
18 | Summarize DFARS 72 hour reporting metodology | 03.06.04 | new | ISSO/IRT | x | |||||||||||||||||||||
19 | Know how to recognize suspected CUI Incidents | 03.06.04 | new | In scope employees | ||||||||||||||||||||||
20 | Identify and communicate risk to the upply-chain risk from processing, storing, or transmitting CUI. | 03.11.01 | 3.11.1 | Mangement, IT | x | |||||||||||||||||||||
21 | Identify and address supply-chain weaknesses and enforce | 03.17.03 | new | Management, IT | x | x | x | |||||||||||||||||||
22 | Identify procedures and plans that govern your security responsibility | 03.02.02 | 3.2.2 | Managemt, IT, ISSO | x | x | x | |||||||||||||||||||
23 | Apply approved security requirements at authorized alternate work sites. | 03.10.06 | 3.10.6 | IT,ISSO | ||||||||||||||||||||||
24 | Maintain baseline security certifications for your role | 03.02.02 | 3.2.2 | IT, ISSO | x | x | x | x | ||||||||||||||||||
25 | Complete training based on your security role protecting company systems | 03.02.02 | 3.2.2 | In scope employees | ||||||||||||||||||||||
26 | Use company plans and procedures in your security role | 03.02.02 | 3.2.2 | IT. ISSO, Management, HR | x | x | x | |||||||||||||||||||
27 | Describe company approved security tools | 03.02.02 | 3.2.2 | IT | x | x | ||||||||||||||||||||
28 | Collaborate on company knowledge base for your security role | 03.02.02 | 3.2.2 | IT | x | x | x | |||||||||||||||||||
29 | Mark media with required CUI markings and distribution limitations. | 03.08.04 | 3.8.4 | In scope employees | x | x | x | |||||||||||||||||||
30 | Sanitize equipment removed for off-site maintenance of any CUI. | 03.07.04 | 3.7.3 | In scope employees, | x | x | ||||||||||||||||||||
31 | Sanitize or destroy system media containing CUI before disposal or reuse | 03.08.03 | 3.8.3 | IT | x | x | x | |||||||||||||||||||
32 | Establish an operational incident-handling capability | 03.06.01 | 3.6.1 | Incident Response Team | x | |||||||||||||||||||||
33 | Track, document, and report incidents to designated official | 03.06.02 | 3.6.2 | ISSO | x | x | ||||||||||||||||||||
34 | Summarize the Incident response plan | 03.06.05 | new | In scope employees | x | x | ||||||||||||||||||||
35 | Define roles and responsibilities in the incident response plan | 03.06.05 | new | Incident Response Team | ||||||||||||||||||||||
36 | Execute assigned steps in the incident-handling lifecycle in accordance with the incident response plan. | 03.06.01 | 3.6.1 | Incident Response Team | ||||||||||||||||||||||
37 | Participate in incident-response tests, tabletop exercises, and simulations. | 03.06.03 | 3.6.3 | Incident Response Team | x | x | ||||||||||||||||||||
38 | Evaluate incident-response tests, tabletop exercises, and simulations. | 03.06.03 | 3.6.3 | Incident Response Team | x | x | ||||||||||||||||||||
39 | Identify required company screening methods | 03.09.01 | 3.9.1 | Human Resources | x | x | ||||||||||||||||||||
40 | Describe company approved triggers for rescreening | 03.09.01 | 3.9.1 | Human Resources | x | x | ||||||||||||||||||||
41 | Define methods to protect CUI and systems during personnel termination or transfer | 03.09.02 | 3.9.2 | Human Resources | x | x | ||||||||||||||||||||
42 | Describe company policy to responding to assessment, monitoring, and audit findings. | 03.11.04 | new | IT | x | |||||||||||||||||||||
43 | ||||||||||||||||||||||||||
44 | ||||||||||||||||||||||||||
45 | ||||||||||||||||||||||||||
46 | ||||||||||||||||||||||||||
47 | ||||||||||||||||||||||||||
48 | ||||||||||||||||||||||||||
49 | ||||||||||||||||||||||||||
50 | ||||||||||||||||||||||||||
51 | ||||||||||||||||||||||||||
52 | ||||||||||||||||||||||||||
53 | ||||||||||||||||||||||||||
54 | ||||||||||||||||||||||||||
55 | ||||||||||||||||||||||||||
56 | ||||||||||||||||||||||||||
57 | ||||||||||||||||||||||||||
58 | ||||||||||||||||||||||||||
59 | ||||||||||||||||||||||||||
60 | ||||||||||||||||||||||||||
61 | ||||||||||||||||||||||||||
62 | ||||||||||||||||||||||||||
63 | ||||||||||||||||||||||||||
64 | ||||||||||||||||||||||||||
65 | ||||||||||||||||||||||||||
66 | ||||||||||||||||||||||||||
67 | ||||||||||||||||||||||||||
68 | ||||||||||||||||||||||||||
69 | ||||||||||||||||||||||||||
70 | ||||||||||||||||||||||||||
71 | ||||||||||||||||||||||||||
72 | ||||||||||||||||||||||||||
73 | ||||||||||||||||||||||||||
74 | ||||||||||||||||||||||||||
75 | ||||||||||||||||||||||||||
76 | ||||||||||||||||||||||||||
77 | ||||||||||||||||||||||||||
78 | ||||||||||||||||||||||||||
79 | ||||||||||||||||||||||||||
80 | ||||||||||||||||||||||||||
81 | ||||||||||||||||||||||||||
82 | ||||||||||||||||||||||||||
83 | ||||||||||||||||||||||||||
84 | ||||||||||||||||||||||||||
85 | ||||||||||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | ||||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | ||||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | ||||||||||||||||||||||||||
92 | ||||||||||||||||||||||||||
93 | ||||||||||||||||||||||||||
94 | ||||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | ||||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | ||||||||||||||||||||||||||
99 | ||||||||||||||||||||||||||
100 |