ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Rev 3Rev 2AudienceBasic Cybersecurity trainingAcceptable Use PolicyMandatory CUI TrainingRole specific CUI TrainingBaseline CertificationsIT TrainingInternal RiskRisk AssessmentIncident RespsonseIncident Response TabletopsSupply Chain Risks JIT Awareness MessagingKnowledge Base
2
Participate in annual risk assessment03.02.013.2.1Managementxxx
3
Users are made aware of security risks to CUI in the System03.02.013.2.1All employeesxxxx
4
Acknowledge and follow rules for system use and protecting CUI before access is authorized.03.15.03newIn scope employeesxxx
5
Use approved external system only03.01.203.1.20All employeesxxx x
6
Control the use of removable media on system components.03.08.073.8.7In scope employeesxxx
7
Use only approved systems for the storing, processing, or transmitting CUI03.01.203.1.20In scope employeesxx
8
Prohibit portable storage devices with no identifiable owner.03.08.073.8.8All employeesxxx
9
Describe strategies for preventing CUI from being posted to a public system03.01.223.1.22In scope employeesxx
10
Identity company policies that govern your security program03.15.01newManagement/ISSO
11
Define authorized alternate sites and the organization-selected safeguards required at those sites.03.10.063.10.6In scope employeesx
12
Enforce safeguarding measures for CUI at alternate work sites.03.10.063.10.6In scope employeesxx
13
Define common indicators of Insider Risk03.02.013.2.3All employeesxx
14
Recognize idicators of Insider Risk03.02.013.2.3In scope employeesx
15
Describe the methods of social engineering03.02.013.2.1All employeesxx
16
Summarize social mining techniques03.02.013.2.1All employeesxx
17
Complete Incident Response training03.06.04newIncident Response Team
18
Summarize DFARS 72 hour reporting metodology03.06.04newISSO/IRTx
19
Know how to recognize suspected CUI Incidents03.06.04newIn scope employees
20
Identify and communicate risk to the upply-chain risk from processing, storing, or transmitting CUI.03.11.013.11.1Mangement, ITx
21
Identify and address supply-chain weaknesses and enforce03.17.03newManagement, ITxxx
22
Identify procedures and plans that govern your security responsibility03.02.023.2.2Managemt, IT, ISSOxxx
23
Apply approved security requirements at authorized alternate work sites.03.10.063.10.6IT,ISSO
24
Maintain baseline security certifications for your role03.02.023.2.2IT, ISSOxxxx
25
Complete training based on your security role protecting company systems 03.02.023.2.2In scope employees
26
Use company plans and procedures in your security role03.02.023.2.2IT. ISSO, Management, HRxxx
27
Describe company approved security tools03.02.023.2.2ITxx
28
Collaborate on company knowledge base for your security role03.02.023.2.2ITxxx
29
Mark media with required CUI markings and distribution limitations.03.08.043.8.4In scope employeesxxx
30
Sanitize equipment removed for off-site maintenance of any CUI.03.07.043.7.3In scope employees, xx
31
Sanitize or destroy system media containing CUI before disposal or reuse03.08.033.8.3ITxxx
32
Establish an operational incident-handling capability03.06.013.6.1Incident Response Teamx
33
Track, document, and report incidents to designated official03.06.023.6.2ISSO xx
34
Summarize the Incident response plan03.06.05newIn scope employeesxx
35
Define roles and responsibilities in the incident response plan03.06.05newIncident Response Team
36
Execute assigned steps in the incident-handling lifecycle in accordance with the incident response plan.03.06.013.6.1Incident Response Team
37
Participate in incident-response tests, tabletop exercises, and simulations.03.06.033.6.3Incident Response Teamxx
38
Evaluate incident-response tests, tabletop exercises, and simulations.03.06.033.6.3Incident Response Teamxx
39
Identify required company screening methods03.09.013.9.1Human Resourcesxx
40
Describe company approved triggers for rescreening03.09.013.9.1Human Resourcesxx
41
Define methods to protect CUI and systems during personnel termination or transfer03.09.023.9.2Human Resourcesxx
42
Describe company policy to responding to assessment, monitoring, and audit findings.03.11.04newITx
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100