NIST 800-171 · Awareness and Training

Requirement 3.2.1

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
4 assessment objectives

Official requirement text

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.2.1[a]security risks associated with organizational activities involving CUI are identified.
  2. 3.2.1[b]policies, standards, and procedures related to the security of the system are identified.
  3. 3.2.1[c]managers, systems administrators, and users of the system are made aware of the security risks associated with their activities.
  4. 3.2.1[d]managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.