I don’t have a naughty nature, so I will refrain from ODP puns and discuss how Patching your People through your Security Training program needs to evolve with the transition to NIST-SP-800-177 Rev 3 from Rev 2.

NIST SP 800-171 Revision 3 introduces both theoretical and operational changes to the Awareness and Training family. Over the years the emphasis on training becomes stronger and stronger while we spend more assuming breach and expecting systems have already failed. We know over 80% of breaches begin with your people. Revision three of NIST-SP-800 171 went beyond the general requirements found in Revision 2. Revision 3 replaces the general awareness requirement with security literacy training.

This new theoretical definition seeks to emphasize that personnel must not only complete security information training but must understand and be able to apply foundational security knowledge.

Literacy as Security or GRC = General Reading Comprehension

Scholars and nerds have used the word “literacy” for differentiating applied knowledge and contrasting this with declarative knowledge for a long time. Basically knowing and doing = literacy. Sylvia Scribner in her 1984 piece “Literacy in Three Metaphors" kicked off the trend and argued literacy does not have a single, context-free essence. She analyzed three metaphors:

  • Literacy as adaptation — the skills needed to function effectively in everyday life.
  • Literacy as power — the capacity to analyze conditions and act upon them.
  • Literacy as a state of grace — literacy as intellectual, cultural, or personal development.

The first metaphor finds a home wit compliance and NIST. Under the adaptation model, literacy allows functioning in a particular social and technological environment.

Think about stuff like:

  • security literacy
  • health literacy
  • financial literacy
  • scientific literacy;
  • information literacy
  • digital literacy

In 1999 the National Research Council published, “Being Fluent with Information Technology.” The committee deliberately preferred fluency over basic “computer literacy.” It described information-technology fluency as having three interconnected components:

  • contemporary skills — the ability to use current technological tools
  • foundational concepts — understanding the enduring principles underlying technology
  • intellectual capabilities — the ability to reason about information, manage complexity, solve problems, and adapt knowledge to new situations

The NIST definition included in NIST-SP-800-53, which spawned the revision to 171, best aligns with theoretical constructs similar to Yoram Eshet-Alkalai’s,“Digital Literacy: A Conceptual Framework for Survival Skills in the Digital Era,” which was published in 2004.

Folks would make academic careers writing pieces debating if we really meant technology fluency or literacy (technically my PhD was from the New Literacies Research Lab…we really stretched the metaphor).

Training Roots

The emphasis gets placed on functioning effectively, not possessing declarative knowledge alone. NIST baked this functional definition of security literacy in long-standing awareness-and-training model in SP 800-50 and SP 800-16.The original NIST SP 800-16 (1998) contains a section expressly titled “3.1 Definition and Purpose.” which defines IT security literacy as:

“An individual’s familiarity with—and ability to apply—a core knowledge set…needed to protect electronic information and systems.” definition fits squarely within these broader educational traditions.

It defined IT security literacy as familiarity with and the ability to apply a core knowledge set needed to protect information and systems.The first version of SP 800-50 contained descriptive definitions in Chapter 2, although it did not use “literacy training” as a principal formal term. It distinguishes the learning continuum as following awareness, training, education, and professional development

NIST publication Concept Meaning
NIST SP 800-53 Rev. 5 — AT-2 Literacy Training and Awareness Foundational security and privacy learning for system users, delivered initially, recurrently, and when changes or events require it. Users learn why security matters, what actions they must take, and how to respond to suspected incidents.
NIST SP 800-50 Rev. 1 — Appendix B Awareness Training The foundational cybersecurity or privacy training program for all personnel. It helps learners understand their role in protecting information, cybersecurity, and privacy-related assets. SP 800-50 Rev. 1 expressly notes that this is called “literacy” training in SP 800-53 Rev. 5.
NIST SP 800-16 — Chapters 2–3 Security Basics and Literacy An individual’s familiarity with—and ability to apply—a core knowledge set needed to protect electronic information and systems. Security literacy represents the transition between passive awareness and specialized, role-based training.
CyberDI Security Literacy The ability to understand and apply foundational security knowledge so a person can recognize risk, protect information and systems, and take the correct action in context.

Literacy in Action

This concept of security literacy training gets operationalized through role based training. This now reflects a more lifecycle approach. Revision 2 required organizations to make managers, system administrators, and users aware of security risks and applicable security requirements; train personnel to perform their assigned security duties and provide awareness training on recognizing and reporting potential insider-threat indicators. Revision 3 incorporates the former standalone insider-threat requirement into this broader literacy requirement rather than eliminating it.

The assessment objectives in NIST-SP-800-171a call for some evidence of measuring a users’ knowledge and identifies continuing awareness activities that reinforce literacy. These can include advisories, login messages, videos, webinars, and other awareness events.The revisions also call for specific content. A training must address the actions users are expected to take to maintain security. Rev 3 includes explicit requirements to train employees to respond to incidents and protect CUI. They must continue, like Rev 2 to recognize and report indicators of insider threats. Revision three does explicitly add social engineering and social mining as required content.

Awareness and Training: CMMC Rev. 2 to Rev. 3 Crosswalk
Rev. 2 Requirement Rev. 2 Focus Rev. 3 Requirement Rev. 3 Focus Change
3.2.1 Ensure managers, system administrators, and users understand the security risks associated with their activities and the applicable policies, standards, and procedures. 03.02.01 — Literacy Training and Awareness Provide and periodically update security literacy training. Training includes recognizing and reporting insider threats, social engineering, and social mining. Expands general awareness into recurring security literacy training with defined content, update requirements, and event-driven training.
3.2.2 Ensure personnel are trained to perform their assigned information security duties and responsibilities. 03.02.02 — Role-Based Training Provide training before personnel receive access or perform assigned security roles, and repeat training at an organization-defined frequency and following specified changes or events. Adds explicit timing, frequency, role-based content, and training-update requirements.
3.2.3 Provide security awareness training on recognizing and reporting indicators of insider threat. 03.02.03 — Withdrawn and incorporated into 03.02.01 Insider-threat recognition and reporting are included within Literacy Training and Awareness under 03.02.01. The requirement is retained but consolidated with general security literacy training rather than maintained as a separate requirement.

Security Literacy and Organizational Defined Parameters

One of the biggest changes to the training family involves frequencies and triggers. Under Revision 2 an organization assigned frequency and just needed to prove the rules got followed. In Rev 3 the annual requirement remains but specific triggers for content update were added to organizational defined parametersOverall, the change from Revision 2 to Revision 3 moves awareness and training from a relatively static, compliance-oriented activity toward a continuous, role-sensitive learning program. Organizations must now define training frequencies and triggering events, periodically review and update course content, and revise training after events such as system changes, audit findings, incidents, changes in threats, or changes to applicable requirements. The practical expectation is no longer satisfied merely by assigning an annual awareness course and retaining a completion record.

Organizations should be able to demonstrate that training is timely, relevant to their environment and CUI-handling practices, appropriate to each person’s responsibilities, reinforced through continuing awareness activities, and effective in developing the knowledge personnel need to recognize risks and act securely.

NIST SP 800-171 Rev. 2 and NIST SP 800-171 Rev. 3.

NIST SP 800-171 Rev. 3 — 03.02.01 Literacy Training and Awareness ODPs
Requirement Objective Organization-Defined Parameter Assigned Value
03.02.01 03.02.01.a.01 Frequency after initial security literacy training Annually
03.02.01 03.02.01.a.02 Events requiring additional security literacy training
  • Significant changes
  • Incidents or breaches
  • Legal, regulatory, or contractual changes
  • Audit or assessment findings
  • Material threat changes
03.02.01 03.02.01.b.01 Frequency for reviewing and updating security literacy training content Annually
03.02.01 03.02.01.b.02 Events requiring security literacy training content updates
  • Significant changes
  • Incidents or breaches
  • Legal, regulatory, or contractual changes
  • Audit or assessment findings
  • Material threat changes

Updating your Security Training Program

If you have a mature Awareness and Training Program for your organization you can easily update for NIST-SP-800-171 rev 3. You need to add new content around social engineering and mining, and update your plans to account for ODP triggers.Need to begin formulating a real security training program beyond the annual video you make staff suffer through?

  • Start with your risk assessment. Your employees must get trained on the risks to CUI in your system. You can not develop a compliant training without first conducting a risk assessment
  • Identify all the learning objectives you want to cover in your program. I expand beyond the security literacy domain and think about all controls that could benefit from training. For example, take removable media. At a minimum employees should sign an Acceptable Use Policy they understand how to handle removable media. That’s training.
  • Then decide which role must demonstrate they met the objective.
  • Next map all the training you currently provide* Then crosswalk against the objectives to make sure they all get met* Create any custom content to fill in the holes
  • Develop a flexible plan that allows you to deliver just in time awareness training.

Feel free to check out and remix my training matrix.

 A detailed table lists various tasks related to Risk Assessment with corresponding priority values, audiences, and criteria such as Role adopting controls, Baseline Configuration, Policy Training and Certification, Security Testing, and JT Assessment.