Sekit CSF · Training & Awareness · Process
RCF-0389Security awareness program
All employees consistently complete security awareness training and understanding is verified
Mapping at a glance
RCF-0389Security awareness programTraining & Awareness · Process
A.6.3Information security awareness, education and trainingISO/IEC 27001:2022PR.AT-01General security awareness trainingNIST CSF 2.0PR.AT-02Role-based security trainingNIST CSF 2.0A.4.6Human resourcesISO/IEC 42001:2023 — Annex AA.9.2Processes for responsible use of AI systemsISO/IEC 42001:2023 — Annex A
RCF-0389 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.4.6Human resourcessupportsRunning the awareness cycle and checking completion proves people were trained, but without an AI module it says nothing about AI-specific competence.A.9.2Processes for responsible use of AI systemssupportsRCF-0389 makes sure everyone completes awareness training and chases stragglers to closure, a mechanism that can enforce AI-specific acceptable-use training, though today's cycle rarely covers AI tools by name.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
From the Sekit evidence catalog
This topic through the other lenses
All Training & Awareness controls
Ask Sekura: “What evidence proves RCF-0389?”
Also via MCP, free with account