NIST CSF 2.0 · derived mapping target
PR.AT-02Role-based security training
Give people in specialized roles the deeper training they need to handle the specific security risks of their work, beyond general awareness.
Mapping at a glance
PR.AT-02Role-based security trainingNIST CSF 2.0
RCF-0388Security awareness programTraining & Awareness · PolicyRCF-0389Security awareness programTraining & Awareness · ProcessRCF-0390Security awareness programTraining & Awareness · TechnicalRCF-0391Phishing simulationsTraining & Awareness · PolicyRCF-0392Phishing simulationsTraining & Awareness · Process
PR.AT-02 is covered by 9 Sekit CSF controls. +4 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0388Security awareness program · PolicyRCF-0389Security awareness program · ProcessRCF-0390Security awareness program · TechnicalRCF-0391Phishing simulations · PolicyRCF-0392Phishing simulations · ProcessRCF-0393Phishing simulations · TechnicalRCF-0394Role-based training · PolicyRCF-0395Role-based training · ProcessRCF-0396Role-based training · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.AT-02?”
Also via MCP, free with account