NIST CSF 2.0 · derived mapping target
PR.AT-01General security awareness training
Provide all staff with awareness and training so they can do their everyday work with cyber risks in mind and recognize common threats like phishing.
Mapping at a glance
PR.AT-01General security awareness trainingNIST CSF 2.0
RCF-0388Security awareness programTraining & Awareness · PolicyRCF-0389Security awareness programTraining & Awareness · ProcessRCF-0390Security awareness programTraining & Awareness · TechnicalRCF-0391Phishing simulationsTraining & Awareness · PolicyRCF-0392Phishing simulationsTraining & Awareness · Process
PR.AT-01 is covered by 12 Sekit CSF controls. +7 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0388Security awareness program · PolicyRCF-0389Security awareness program · ProcessRCF-0390Security awareness program · TechnicalRCF-0391Phishing simulations · PolicyRCF-0392Phishing simulations · ProcessRCF-0393Phishing simulations · TechnicalRCF-0394Role-based training · PolicyRCF-0395Role-based training · ProcessRCF-0396Role-based training · TechnicalRCF-0397Executive briefings · PolicyRCF-0398Executive briefings · ProcessRCF-0399Executive briefings · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
Phishing simulation results
The proof that phishing simulations are run to test employees and the follow-up training given to those who fall for them.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.AT-01?”
Also via MCP, free with account