One Person, Many Roles: Building a NIST SP 800-171 Rev. 3 Awareness and Training Program
If you want to survive NIST-SP-800-171 compliance as a solopreneur you need to think small. A one-person company does not need a learning management system. You do not have to film a library of animated phishing videos, or hire a full-time training manager to build a defensible security awareness and training program.
NIST-SP-800-171 rev 3 created a philosophical shift in terminology. Instead of awareness and training we now focus on security literacy and awareness. Not much needs to change around your awareness and training program beyond explicit requirements to offer training after an incident.
How does a one person shop do this?
All you need to do is create a defensible and repeatable process.
Solopreneur often serves as the company president. You spend hours as the system owner, and respond to surveys as security officer. Other times you work as system administrator, and yet your company has only one authorized CUI user. NIST SP 800-171 Rev. 3 does not erase those responsibilities just because one person fills every role. The owner still needs general security literacy training as a system user and role-based training for the administrative and security duties that the owner performs. Basically you complete different training based on the hat you currently wear.
The most practical approach uses one short annual training package, a few event-driven refreshers, and one reliable completion record. The System Security Plan (SSP) can contain the entire procedure. This eliminates the need for a separate Awareness and Training Plan or SOP.
If you have a Facility Clearance License your existing training program will meet the requirements. You have to have an insider threat program and a risk assessment. Just supplement your existing training with the Mandatory DoD CUI training and you are done.
What Rev. 3 Actually Requires
The Awareness and Training family contains two active requirements:
-
03.02.01, Literacy Training and Awareness, requires security literacy training during initial training, at an organization-defined frequency, after defined events or system changes, and on recognizing and reporting insider threats, social engineering, and social mining. The organization must also define when it reviews and updates the training content.
-
03.02.02, Role-Based Training, requires training before a person receives access to the system or CUI, before the person performs assigned security duties, at an organization-defined frequency thereafter, and after defined events or system changes. The organization must also define when it updates the role-based content.
Those two requirements contain eight organization-defined parameters. A compliant program must choose the recurring frequency and triggering events for each type of training and for each content review. “As needed” does not make a strong definition. “Annually and within 30 days after a listed triggering event” gives the owner and an assessor something concrete to evaluate.
NIST also expects the training to match the organization, the systems, and the work environment. A solopreneur should not take a generic phishing course and call the family complete. The program must also teach the owner how the company actually protects CUI on its one-laptop system.
Wear Both Hats During the Same Training Session
A one-person company can combine security literacy and role-based training into one annual session, but it should label and document the two modules separately.
The security literacy module should cover the duties that apply to the owner as a user. Topics should include:
- identifying CUI and reading its markings and dissemination controls;
- using only the authorized device, accounts, applications, and storage locations for CUI;
- protecting credentials and using multifactor authentication;
- recognizing phishing, impersonation, pretexting, baiting, thread hijacking, and other social-engineering techniques;
- recognizing social mining, including attempts to gather useful details from websites, social media, proposals, job postings, conversations, and professional networking;
- recognizing insider-threat indicators, including the possibility that the owner’s own stress, convenience, or work habits can create risk;
- handling, transmitting, storing, and destroying CUI according to the SSP;
- responding to a suspected incident, lost device, misdirected message, or accidental disclosure; and
- reporting the event through the company’s defined channel.
The last item can feel strange when the only employee would report a concern to themself. The SSP should still name an external escalation path. Depending on the company’s contracts and support model, that path may include an MSP, security consultant, prime contractor, contracting contact, or federal reporting channel. The owner should not invent the reporting path during an incident.
The role-based module should cover the duties that apply to the same person as system owner, administrator, and security officer. Topics should include:
- using a standard account for daily work and a separate privileged account for administration;
- reviewing alerts, logs, vulnerabilities, and security-tool status;
- approving and documenting system changes;
- installing patches and addressing vulnerabilities within the company’s defined timeframes;
- managing accounts, licenses, devices, and external service providers;
- protecting backups and testing recovery;
- executing the incident-response and reporting procedures;
- reviewing the SSP, risk assessment, and Plan of Action and Milestones; and
- understanding which responsibilities the company retains when an MSP or cloud provider performs part of the work.
One course can cover both modules in 60 to 90 minutes. The owner should complete a short knowledge check and review every incorrect response. The goal does not involve proving that the owner watched a video. The goal involves showing that the owner understands the company’s rules and can act on them.
Your role based training should also get impacted by your solution. If you use GCCH, Preveil, or Kiteworks, speak to doing an annual training or refresher course. You want to know how to use the tools you chose.
Your risk assessment should also drive the content you choose. You need to train against the risks to the confidentiality of CUI that you identified. These can often get covered by free trainings available to the government. Just make the connection between your risk assessment and your training program explicit in your System Security Plan.
Put the Whole Procedure in the SSP
Rev. 3 makes this consolidation possible. Requirement 03.15.01 allows organizations to document procedures in the SSP instead of maintaining separate procedure documents. A small company can therefore place the policy, frequencies, triggers, training topics, completion criteria, responsibilities, and recordkeeping method directly in the Awareness and Training section of the SSP.
The SSP language, if you define learning components at the requirement could read as follows:
Responsibility and scope. The System Owner serves as the organization’s only system user and also performs the System Administrator, Security Officer, and management roles. The System Owner completes both security literacy and role-based security training.
Initial and recurring training. The System Owner completes security literacy training before receiving access to CUI. The System Owner completes role-based training before performing administrative or security duties. The System Owner repeats both training modules annually during January. The annual training contains a knowledge check. The System Owner must score at least 80 percent and review each incorrect response before recording completion.
Event-driven training. The System Owner completes relevant supplemental training within 30 calendar days after a material change to the CUI system, the adoption of a new security or administrative tool, a change in contractual or legal requirements, an assessment or audit finding related to user behavior or assigned duties, a security incident or near miss, or the identification of a new threat that materially changes the company’s procedures. The System Owner may complete the training sooner when an incident, system change, or contract requires immediate action.
Security literacy content. Training covers CUI identification, approved CUI handling, account and credential protection, multifactor authentication, authorized system use, incident recognition and reporting, insider-threat indicators, social engineering, social mining, and the company’s system-specific user responsibilities.
Role-based content. Training covers the System Owner’s management, system administration, security administration, configuration management, vulnerability management, audit review, incident response, backup, recovery, and external-service-provider oversight duties.
Content review and update. The System Owner reviews both modules annually before completing the annual training. The System Owner also reviews and updates the relevant content within 30 calendar days after any event that triggers supplemental training. The review confirms that the content matches the current SSP, system architecture, contractual requirements, threats, security tools, and reporting paths.
Records. The System Owner records the completion date, training type, content version, topics covered, score, incorrect answers reviewed, supplemental training reason when applicable, and an affirmation of completion. The System Owner stores the record in the designated training-record repository and retains it according to the company’s records-retention policy. Training records do not contain CUI, credentials, incident details, detailed vulnerabilities, or copies of the SSP.
That language creates an executable process. It also answers the questions an assessor will likely ask: Who trains? What training occurs? When does it occur? What triggers additional training? When does the content change? How does the company verify understanding? Where does it keep evidence?
At the objective level you might write:
| Requirement | Assessment Objective | SSP Implementation Statement |
|---|---|---|
| 3.2.1 |
3.2.1[a]Security risks associated with organizational activities involving CUI are identified. |
The organization identifies security risks associated with the System Owner’s activities involving CUI in this SSP and in the security literacy training content. Identified risks include improper CUI marking, handling, storage, transmission, or destruction; phishing, impersonation, social engineering, and social mining; credential compromise and fraudulent multifactor-authentication requests; loss or theft of the authorized endpoint; use of unauthorized software, storage, removable media, printing, or external systems; insecure remote-work practices; delayed incident reporting; misuse of privileged access; and failure to oversee external service providers. The System Owner reviews the identified risks annually before the January training session and after each defined event, and updates them within 30 calendar days when the review identifies a change. |
| 3.2.1 |
3.2.1[b]Policies, standards, and procedures related to system security are identified. |
This SSP identifies and contains the policies, standards, and procedures that apply to the CUI system, including requirements for authorized system use; CUI marking and handling; identity, authentication, and multifactor authentication; standard and privileged accounts; endpoint security; approved email and file-sharing services; media and printing; remote work; physical protection; incident recognition and reporting; configuration and change management; vulnerability and patch management; audit review; backup and recovery; and external-service-provider oversight. The System Owner reviews these requirements annually before the January training session and after each defined event, and updates the SSP and affected training content when necessary. |
| 3.2.1 |
3.2.1[c]Managers, system administrators, and users are made aware of the security risks associated with their activities. |
The System Owner serves as the organization’s manager, system administrator, security officer, and only system user. The System Owner completes initial security literacy training before receiving authorization to access the CUI system or CUI, completes recurring training annually during January, and completes relevant supplemental training within 30 calendar days after each defined event or sooner when immediate action is required. Training addresses the security risks identified under 3.2.1[a] and includes a knowledge check requiring a score of at least 80 percent and review of every incorrect response. The System Owner records the completion date, training type, content version, topics, score, incorrect-answer review, triggering event when applicable, and completion affirmation in the designated training-record repository. |
| 3.2.1 |
3.2.1[d]Managers, system administrators, and users are made aware of applicable policies, standards, and procedures related to system security. |
Initial, annual, and event-driven security literacy training makes the System Owner aware of the policies, standards, and procedures identified under 3.2.1[b]. Training explains the actions required to protect CUI, use the system securely, recognize and report suspected incidents, and perform work in accordance with this SSP. The System Owner completes training before initial access, annually during January, and within 30 calendar days after a defined event. The System Owner reviews and updates the content annually and after defined events, and records completion in the designated training-record repository. |
| 3.2.2 |
3.2.2[a]Information-security-related duties, roles, and responsibilities are defined. |
This SSP defines the System Owner, management, system administrator, and security officer roles. Defined duties include authorizing and reviewing access; using separate standard and privileged accounts; administering the endpoint, identity service, cloud services, and security tools; approving and documenting changes; reviewing alerts and audit information; managing vulnerabilities and patches; protecting and testing backups; executing incident-response and reporting procedures; reviewing the SSP, risk assessment, and Plan of Action and Milestones; and overseeing external service providers. The System Owner reviews these definitions annually and after each defined event and updates them when responsibilities, systems, services, or requirements change. |
| 3.2.2 |
3.2.2[b]Information-security-related duties, roles, and responsibilities are assigned to designated personnel. |
The organization assigns the System Owner, management, system administrator, and security officer roles to the company’s sole owner. The SSP identifies any security functions performed by an external service provider and identifies the System Owner’s retained responsibility for approving, monitoring, and verifying those services. The System Owner reviews role assignments annually and after each defined event. The System Owner documents a new or changed assignment in the SSP before performing the affected duty. |
| 3.2.2 |
3.2.2[c]Personnel are adequately trained to carry out assigned information-security-related duties, roles, and responsibilities. |
The System Owner completes role-based security training before receiving authorization to access the CUI system or CUI and before performing assigned management, administrative, or security duties. The System Owner repeats role-based training annually during January and completes supplemental training before performing a newly assigned duty and otherwise within 30 calendar days after a defined event. Training covers privileged-account use, system and security administration, access management, configuration and change management, vulnerability and patch management, audit review, incident response, backup and recovery, CUI handling, and external-service-provider oversight. The training includes an 80-percent knowledge-check threshold and review of incorrect responses. The System Owner records the completion date, training type, assigned role, content version, topics, score, incorrect-answer review, triggering event when applicable, and completion affirmation. |
| 3.2.3 |
3.2.3[a]Potential indicators associated with insider threats are identified. |
The organization identifies potential insider-threat indicators in this SSP and in the security literacy training content. Indicators include attempts to obtain access not required for assigned duties; unusual or unexplained access to CUI; unauthorized copying, transmission, printing, or removal of information; attempts to bypass security safeguards; misuse of privileged access; unexplained changes in work patterns; concealment of security-relevant activity; serious policy violations; and personal or workplace conditions that may increase security risk. Because the System Owner is the only employee, the training also addresses how the owner’s own stress, haste, convenience, dissatisfaction, financial pressure, or changing behavior can increase risk. The System Owner reviews these indicators annually and after each defined event and updates them when threat information or organizational circumstances change. |
| 3.2.3 |
3.2.3[b]Security awareness training on recognizing and reporting potential insider-threat indicators is provided to managers and employees. |
The System Owner serves as both management and the organization’s only employee. Initial security literacy training teaches the System Owner to recognize the insider-threat indicators identified under 3.2.3[a], document a suspected indicator, preserve relevant evidence, and report the concern through the external security contact and any prime-contractor or federal reporting channel identified in the Incident Response section of this SSP. The System Owner repeats this training annually during January and completes relevant supplemental training within 30 calendar days after a defined event or sooner when immediate action is required. The System Owner records completion in the designated training-record repository and does not investigate suspected insider activity beyond actions authorized by the incident-response procedure. |
This table retains the nine NIST SP 800-171 Rev. 2 Awareness and Training assessment objectives. Rev. 2 does not contain the Rev. 3 organization-defined parameters. The recurring frequencies, triggering events, content-review schedule, and completion windows above deliberately apply the more explicit Rev. 3 ODP structure to the Rev. 2 implementation.
How Much Does Training Cost?
Nothing. You can find free trainings available from the government that meet your NIST-SP-800-171 needs.
How to use this table: Select training that matches an assigned security duty. A government course does not, by itself, prove that a person can perform the organization’s actual procedures. Pair each external course with a short review of the applicable SSP procedures, tools, system configuration, and reporting contacts. Retain the course certificate or transcript when one is available and record the internal review and knowledge check in the organization’s designated training record.
| Agency | Free offering | Best-fit role or duty | How to use it | Access and completion evidence |
|---|---|---|---|---|
| DoD / DCSA CDSE | DoD Mandatory Controlled Unclassified Information (CUI) Training (IF141.16) | CUI user, CUI custodian, system owner, and manager | Use it as the federal CUI foundation, then review the company’s SSP procedures for authorized storage, transmission, marking, destruction, and incident reporting. | Approximately 45 minutes. The public Security Awareness Hub requires no sign-in and produces a certificate, but CDSE does not retain the record. STEPP retains the completion on the learner’s transcript. Save the certificate before closing the public course. |
| DoD / DCSA CDSE | Introduction to the Risk Management Framework (RMF) (CS124.16) | System owner, security officer, assessor liaison, and person maintaining the SSP or POA&M | Use it to introduce DoD RMF roles and the seven-step process. Follow it with an exercise that identifies the company’s own systems, responsibilities, assessment evidence, and remediation workflow. | Approximately 30 minutes. No clearance or prerequisite is listed. A score of at least 75 percent permits the learner to print a certificate. CDSE states that its courses serve DoD, other U.S. Government personnel, and contractors in the National Industrial Security Program. |
| DoD / DCSA CDSE | RMF: Prepare Step (CS101.16) | System owner, security lead, and personnel supporting assessment and authorization | Use it for deeper training on organization-level and system-level preparation tasks, outcomes, policies, and role assignments. Add a walkthrough of the company’s current SSP and evidence locations. | Approximately 60 minutes. No clearance or prerequisite is listed. The final exam requires a score of at least 75 percent; STEPP can retain the transcript. |
| DoD / DCSA CDSE | Insider Threat Awareness (INT101.16) | Manager, security officer, incident-reporting lead, and insider-threat contact | Use the scenarios to teach recognition and reporting of concerning behavior. Add the company’s reporting contacts, evidence-preservation steps, non-retaliation rules, and limits on self-investigation. | Approximately 60 minutes. The final exam requires a score of at least 75 percent and produces a printable certificate. The stated audience is military, civilian, and industry personnel with classified access, so a CUI-only company should document why the reporting concepts remain relevant. |
| CISA | Cybersecurity for Technical Staff | System administrator, endpoint administrator, cloud administrator, and technical security lead | Use it as broad technical-role development. Add hands-on checks using the company’s actual administrative accounts, security tools, patch process, logging, backup, and approved configuration. | Available through CISA Learning. The learner must create or use an eligible account. Retain the LMS completion record or certificate when offered and record the company-specific practical review separately. |
| CISA | Incident Response 101 | Incident-response coordinator, system administrator, security officer, and management | Use it to establish incident-response concepts, then conduct a short tabletop using the company’s SSP: recognize an event, preserve evidence, isolate the affected asset, notify required parties, and record the incident. | Available through CISA Learning. Retain the completion evidence provided by the learning system and the internal tabletop record. |
| CISA | Risk Management Framework for Leaders | Owner, executive, system owner, and security-program lead | Use it for management-level risk and governance training. Add a review of accepted risks, open POA&M items, external-service-provider dependencies, and who can approve system changes. | Available through CISA Learning. Check current learner eligibility and retain the available LMS completion evidence. |
| CISA | Cloud Security: What Leaders Need to Know | System owner, cloud-service owner, contracting lead, and external-service-provider manager | Use it to support decisions about cloud risk and shared responsibility. Add the company’s approved services, CUI data flows, responsibility matrix, authorization requirements, and provider-monitoring procedures. | Available through CISA Learning. Retain the available LMS record and document the company-specific shared-responsibility review. |
| CISA | Industrial Control Systems Virtual Learning Portal | Operational-technology or manufacturing-system administrator, operator, engineer, and incident responder | Use only when the CUI environment includes operational technology or industrial control systems. Select modules that match the person’s duties, then review the organization’s own segmentation, remote-access, change-control, and incident procedures. | CISA offers virtual ICS training, but enrollment and individual-course availability can vary. Retain the completion evidence supplied for the selected course and record the internal system-specific review. |
| FBI | InfraGard webinars and workshops | Security officer, incident liaison, threat-intelligence contact, and critical-infrastructure owner or operator | Use sessions on current threats, incident coordination, or an applicable critical-infrastructure sector as supplemental training. Record the session title, date, topics, and how the content changes or confirms the company’s procedures. | Membership is free but restricted. Applicants generally must have a connection to critical infrastructure, be U.S. citizens, verify their identity, and pass an FBI security-risk assessment. Programs vary by chapter and may not always issue a certificate; retain registration or attendance evidence and an internal knowledge check. |
| FBI | FBI Virtual Academy for Law Enforcement | Law-enforcement, criminal-justice, intelligence, or military personnel with an applicable cyber-investigation or digital-evidence duty | Use a cyber or digital-evidence course only when it directly matches an assigned duty. This option is normally irrelevant to a commercial CUI contractor that has no law-enforcement or criminal-justice role. | The FBI states that thousands of topics are available at no cost, but the platform serves the criminal-justice community. Access is restricted through registration and applicable eligibility; retain the platform’s completion evidence. |
| NSA | Cybersecurity Speaker Series: Defense Industrial Base | Owner, security lead, supplier-risk lead, and DIB incident or threat contact | Use the public video as a short DIB-threat module. Pair it with an internal knowledge check and a review of the organization’s threat-information, incident-reporting, and external-coordination procedures. | Publicly available without a course enrollment. NSA does not present the video as a certificate-bearing course, so the organization must record the assigned viewing, source and version, completion, and knowledge-check result. |
| NSA | Cybersecurity Advisories and Technical Guidance | System administrator, cloud administrator, secure-configuration owner, developer, and vulnerability-management lead | Build a focused internal module from the NSA guidance that applies to the technology being administered. Require the learner to identify which recommendations apply, demonstrate or document the resulting configuration, and explain any exceptions. | Public and free, but this is technical source material rather than a standardized course. Record the document title and date, assigned sections, practical exercise, result, and reviewer approval. |
Compliance caution: General awareness training does not satisfy role-based training by itself. For NIST SP 800-171 Rev. 2 requirement 3.2.2, the organization should be able to show that training matches each person’s assigned information-security duties. For Rev. 3 requirement 03.02.02, the organization should also apply its defined initial, recurring, and event-driven training frequencies. The NSA entries above are free public training materials rather than certificate-bearing courses; the organization must turn them into documented internal modules. Agency offerings, titles, access rules, and certificates can change; verify the linked page when assigning a course.
You also do not need to pay for an LMS or a system of record. As a one person shop you could create a “Tiny LMS” using Microsoft/Google forms or create a ChatGPT/Claude agent to help you track your requirements.
System One: Use Microsoft Forms as a Tiny LMS
Microsoft Forms offers the simplest option for a one-person company that already uses Microsoft 365. The owner can create one quiz with two sections: “Security Literacy” and “Role-Based Security.” The quiz should identify the training version and include a few scenario-based questions for each module.
The final section should collect or record:
- the owner’s identity;
- the completion date;
- the training version;
- whether the submission covers annual, initial, or event-driven training;
- the event that triggered supplemental training, if applicable;
- the quiz score;
- confirmation that the owner reviewed incorrect answers; and
- an affirmation that the owner understands and will follow the SSP procedures.
Require sign-in, restrict responses to the company account, and do not allow anonymous submissions. After each completion, open the Responses tab and save the results to Excel. Microsoft Forms can maintain the response workbook in OneDrive or SharePoint, and Microsoft also supports exporting the workbook or saving it as a PDF. Store that workbook in the training-record location named in the SSP.
The owner should keep the training content outside the form or attach only content that contains no CUI and no sensitive system details. The quiz can ask, “Where may you store CUI?” without including a real CUI filename, contract number, vulnerability, credential, network diagram, or incident narrative. If the company uses a commercial Microsoft 365 tenant outside the CUI boundary, this separation becomes especially important.
Maintenance takes little time. Once each year, the owner reviews the SSP and quiz, updates the version number, completes the quiz, and confirms that the response appears in the workbook. After a triggering event, the owner updates only the affected questions or adds a short supplemental section.
System Two: Use ChatGPT or Claude as the Training Clerk
An AI assistant can manage the calendar and the clerical work, but it should not become the only place where evidence lives. ChatGPT supports scheduled tasks, and Claude Cowork supports recurring scheduled tasks on paid plans. Either tool can remind the owner to conduct training, guide the knowledge check, prepare a completion record, and place or help place the record in a designated repository.
A reusable instruction could read:
Act as the training coordinator for my one-person company. Remind me each January to complete the annual NIST SP 800-171 Rev. 3 security literacy and role-based training described in my SSP. Continue reminding me until I confirm completion. During the session, cover CUI handling, insider-threat indicators, social engineering, social mining, incident reporting, standard and privileged account use, security administration, configuration changes, vulnerability management, log review, backup and recovery, and external-provider oversight. Give me a ten-question knowledge check. Require an 80 percent score and review every incorrect answer with me. After I finish, create a completion record that contains the date, training type, content version, topics, score, incorrect answers reviewed, and my completion affirmation. Save the record in the approved Training Records folder if you have access. If you cannot save it there, create a downloadable record and remind me to place it in that folder. Do not include CUI, credentials, contract details, detailed vulnerabilities, incident details, or SSP contents in the task, chat, quiz, or record.
The owner should create a second recurring reminder to review the training content before the annual session. The reminder should ask whether the system, tools, threats, contracts, laws, reporting paths, or SSP procedures changed during the year. If the answer is yes, the owner updates the module version before completing the course.
The owner should also return to the assistant after any triggering event and state, “Start the event-driven training workflow.” The assistant can then ask which trigger occurred, select the affected topics, administer a short refresher, and generate a supplemental completion record.
AI creates two risks that the SSP should address. First, the owner must verify the accuracy of AI-generated training content against the SSP and authoritative sources. Second, the owner must not paste CUI, credentials, incident evidence, detailed system configurations, or nonpublic vulnerabilities into an AI service unless the organization has authorized and scoped that service for the data. The assistant runs the workflow; the SSP governs it.
Keep Four Things, Not Forty
NIST SP 800-171 Rev. 3 does not carry the NIST SP 800-53 AT-04 Training Records control into the CUI baseline as a separate requirement. However, NIST SP 800-171A Rev. 3 lists training records among the potential objects that an assessor may examine for both 03.02.01 and 03.02.02. Keeping no evidence would make the program difficult to defend.
A solopreneur can build a reasonable evidence package with only four items:
- The current SSP, including the complete Awareness and Training procedure and all eight organization-defined parameters.
- The current version of the training content or quiz.
- The dated Microsoft Forms response, AI-generated completion record, or course certificate that proves completion.
- A dated content-review entry, which can appear in the same training record.
The company may keep older training versions and records according to its documented retention policy. It does not need to produce extra meeting minutes, attendance rosters, sign-in sheets, training plans, or standalone SOPs for a meeting attended by one person.
During an assessment, the SSP and current training material support the examine method. The owner supports the interview method by explaining the rules and demonstrating how to report a concern. Microsoft Forms or the scheduled AI workflow supports the test method by showing that the reminder, quiz, and recordkeeping process works. NIST SP 800-171A emphasizes evidence sufficiency and does not require every potential assessment object listed in the publication.
Small Does Not Mean Informal
A one-person company can keep its Awareness and Training program small because its workforce and system remain small. It cannot keep the program vague.
Define the frequencies. Define the triggers. Teach both the user role and the privileged roles. Test understanding. Keep one reliable record. Write the entire procedure in the SSP and follow it.
That approach does more than reduce paperwork. It turns annual training from a compliance performance into a short operational check: Do I still understand how my system protects CUI, and can I respond correctly when something goes wrong?
Sources
- NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-171A Rev. 3, Assessing Security Requirements for Controlled Unclassified Information
- Microsoft Forms and Excel workbooks
- Export Microsoft Forms responses
- Scheduled tasks in ChatGPT
- Schedule recurring tasks in Claude Cowork
“SkillsUSA Event at Camp Withycombe” flickr photo by Oregon National Guard https://flickr.com/photos/oregonmildep/52802793150 shared under a Creative Commons (BY 2.0) license