When you compare the evolution of NIST-SP-800-171 rev 2 to NIST-SP-800-171 rev 3 you can see the emphasis on training grow. We now focus not just on awareness and training, but on security literacy and awareness. Patching the people has become an even greater priority.

Yet companies can struggle with developing role-bases trainings. Large companies rely on commercial products, but may have workers who can not dedicate time to training. Small companies with one to two people may not understand how you differentiate role based training when you have all the roles.

In NIST-SP-800-171 rev 3 you must:

Provide training before personnel receive access or perform assigned security roles, and repeat training at an organization-defined frequency and following specified changes or events. Yet companies do not know where to begin with role based training. Many end up providing a compliant solution without thinking deeply on how to patch their people. You have many routes to meeting the role based training requirements

Certifications Required Before Hiring

NIST-SP-800-171 rev 3 requires training before people have access to Controlled unclassified information and the security stackFor companies big and small you can do your role training a priori, or before hiring. You simply require a specific certificate for a role. Say a Security+, CISSP, or specific AWS cloud certifications if that fits your stack.

Then during the course of a year employees must maintain their CEUs based on that certification. If your company utilizes a GCC or GCCH stack you can require employees to have specialized certifications.

For a small organization using Entra, Intune, Defender, and Purview, I would prioritize:

  • SC-900 — Security foundation. Appropriate for management, compliance staff, help desk personnel, and technical personnel who need a common Microsoft security vocabulary.

  • MD-102 — Endpoint administration. Primary credential for personnel administering Intune-managed CUI endpoints, Windows security settings, applications, updates, and Defender for Endpoint.

  • SC-300 — Identity and access. Primary credential for Entra ID, MFA, Conditional Access, access reviews, privileged roles, and account lifecycle management.

  • SC-401 — Information Protection. Appropriate when Purview, DLP, retention, insider risk, or sensitivity labels protect or prevent the mishandling of CUI.

  • SC-200 — Security monitoring and incident response. Appropriate for personnel reviewing Defender XDR alerts, logs, incidents, and threat information.

  • SC-100 — Security architecture. Appropriate for the individual designing or approving the overall Microsoft security architecture and integrating identity, endpoints and GCC or GCCH.

Sponsoring Certification Trainings

Companies do not have to require certifications before someone gets hired. This just helps to to meet requirements that training gets complete before authorized access. For ongoing role based training companies may choose to sponsor employees classes and certification demands

Auto-generated description: The graphic promotes investing in ISACA certifications such as CISM and CISA to strengthen organizational cybersecurity by highlighting their benefits, training requirements, and contact information for CyberDI.

Assigning Required 171 Training Per Role

A micro-business can meet this requirement by relying on content required under NIST-SP-800-171 and assigning it to only specific roles. Have a CUI enclave? Only assign the Mandatory CUI training to inscope users. Need to do Internal threat training? Just have management complete it. Want to address the new incident response training requirements? Assign it to the IR team.

You now have role based training and did not need to create additional content beyond what NIST-SP-800-171 requires.

Annual Conference Attendance

Some companies provide a professional development budget for their staff. This counts as role-based training. Just make sure you have procedures in place to ensure employees select conferences related to your security role.

Contributing to the Knowledge Base

Most companies struggle with documentation and maintaining a knowledge base for their procedures. Editing and mantaining your company docs takes time and skill. Recognize this effort as part of official training. As your IT folks write or curate AI written procedures they learn, much better than they do with a passive PowerPoint.

Policy Acknowledgements

Having assets read and sign a policy acknowledgement gets used by many small and micro businesses to meet the role based training requirements.

Create an Annual Professional Growth Plan

A company can get employees to participate in their role based training. Have a procedure in place where employees must choose annual learning goals and describe the steps they will take. If you have an annual professional development budget developing personal learning plans provides great accountability.

Department Meetings

You do not have to sit for a formal training to gather evidence for NIST-SP-800-171 rev 3. Maybe you have department meetings to discuss which alerts should get required reporting. Maybe you host a lunch and learn for all your machinists and review the policy of not putting the USB drive attached to the big ugly stick in your pocket. These scheduled security meetings count as role based training.

Commercial Curriculum

If you utilize a vendor like KnowBe4 or have the learning add-on for Huntress you can create a role based training program. Many vendors include a commercially available training product. If you assign some content to some people and different content to others, you have done role based training.