Sekit CSF · Training & Awareness · Process
RCF-0395Role-based training
Role-specific security training is consistently delivered to developers, administrators and other technical staff
Mapping at a glance
RCF-0395Role-based trainingTraining & Awareness · Process
A.6.3Information security awareness, education and trainingISO/IEC 27001:2022PR.AT-01General security awareness trainingNIST CSF 2.0PR.AT-02Role-based security trainingNIST CSF 2.0A.4.6Human resourcesISO/IEC 42001:2023 — Annex AA.9.2Processes for responsible use of AI systemsISO/IEC 42001:2023 — Annex A
RCF-0395 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.4.6Human resourcessupportsDelivering role-specific training to technical staff is the mechanism an AI competence program would reuse, though today it carries no AI content.A.9.2Processes for responsible use of AI systemssupportsRCF-0395 delivers and verifies role-specific training for developers and administrators on schedule, a routine that extends naturally to AI oversight roles once those roles are added to the list it tracks.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
From the Sekit evidence catalog
This topic through the other lenses
All Training & Awareness controls
Ask Sekura: “What evidence proves RCF-0395?”
Also via MCP, free with account