7.4 Awareness, Training, Evidence Collection and Monitoring-Strategy Revision

Key Takeaways

  • Security and privacy awareness training is a recurring compliance obligation whose completion records are the primary assessment evidence.
  • Role-based training under AT-3 targets personnel with significant security responsibilities and is distinct from general awareness training under AT-2.
  • Evidence must be contemporaneous, attributable, and retained for the defined period, because evidence reconstructed before an audit demonstrates documentation rather than operation.
  • Third-party contracts, service level agreements, policies, and procedures must be reviewed and updated as part of ongoing compliance, not only at renewal.
  • The monitoring strategy itself must be revised when legal, regulatory, supplier, security, or privacy requirements change, or the programme monitors an obsolete requirement set.
Last updated: August 2026

Awareness, Training, Evidence Collection and Monitoring-Strategy Revision

Three bullets of task 7.2 cover the sustaining activities that keep a compliance programme honest between assessments: evidence collected and documentation updated, awareness and training performed and retained, and monitoring strategies revised in response to changing requirements. These are the activities most likely to lapse quietly, which is why they are so heavily represented in audit findings.


1. Awareness and Training

The blueprint names the categories explicitly — contingency, incident response, annual security and privacy — and the exam tests the distinction between two different obligations.

ControlAudienceContentTypical Cadence
AT-2 — Literacy Training and AwarenessEveryone with system accessGeneral security and privacy awareness: phishing, handling rules, reporting obligations, acceptable useOn hire, then annually
AT-3 — Role-Based TrainingPersonnel with significant security or privacy responsibilitiesSkills specific to the role: assessors, ISSOs, developers, privileged administrators, AOsOn assignment, then annually
IR-2 — Incident Response TrainingPersonnel with IR rolesTheir specific responsibilities during an incidentAnnually
CP-3 — Contingency TrainingPersonnel with recovery rolesTheir specific responsibilities during recoveryAnnually
AT-4 — Training RecordsDocumentation and retention of all of the abovePer retention schedule

The common failure is treating general awareness training as satisfying every training control. Annual awareness training that everyone completes does not satisfy AT-3, IR-2, or CP-3, each of which addresses a distinct population with distinct content. An organization with 100% awareness completion and no role-based training for its privileged administrators has an open finding.

AT-2 also carries an insider-threat awareness element, and privacy training obligations attach wherever PII is processed — commonly reinforced by SAOP-directed content beyond the general curriculum.

Training Records Are the Evidence

AT-4 requires that training be documented and retained. The assessor tests completion, not availability: a course that exists in the learning management system and that 40% of staff completed is not a satisfied control. Records must show who completed what, when, and for role-based training, that the content matched the role. New joiners and role-changers are the population where gaps concentrate, because they fall outside the annual cycle.


2. Evidence Collection Discipline

Continuous monitoring produces evidence continuously — or it produces nothing an assessor can use. Three properties determine whether evidence is credible:

PropertyRequirementFailure
ContemporaneousGenerated when the activity occurredA review "documented" months later from memory
AttributableIdentifies who performed the activity and whenAn undated, unsigned checklist
RetainedKept for the defined period, protected from alterationLogs rotated away before the retention period elapses

[!IMPORTANT] Evidence assembled before an audit proves documentation, not operation. If an organization performs quarterly access reviews but only records them the week before an assessment, the assessor cannot distinguish a genuine quarterly process from a single retrospective exercise. In assessment terms, an activity that cannot be evidenced contemporaneously did not occur. This is why evidence collection is designed into the operational process rather than bolted on.

Typical evidence includes configuration exports and baseline comparisons, vulnerability scan results over time, access review records with reviewer and date, change records with security impact analyses, incident tickets with timestamps, training completion records, contingency test results, and audit log samples with review annotations.


3. Keeping Documentation and Third-Party Agreements Current

The blueprint explicitly names service level agreements, third-party contracts, policies, and procedures as documentation requiring update — which places supplier governance squarely inside ongoing compliance.

Third-party agreements drift out of alignment in predictable ways: security requirements written years ago no longer reflect current standards; the provider has changed its architecture, subprocessors, or data locations; incident notification timelines in the contract no longer satisfy current regulatory deadlines; assessment and audit rights were never exercised; the provider's own certification or authorization has lapsed.

Ongoing supplier compliance therefore includes reviewing agreements against current requirements, obtaining and reviewing the provider's current assurance artifacts (SOC 2 Type II reports, ISO/IEC 27001 certificates, FedRAMP authorization status), confirming customer-responsibility controls remain correctly implemented locally, and tracking fourth-party dependencies where a provider's own subprocessors change.

A concrete and examinable case: an SLA specifying incident notification "within five business days" cannot support a controller who must notify a supervisory authority within 72 hours under GDPR Article 33, or an agency that must notify CISA within one hour. The contract term must be renegotiated — the regulatory deadline does not bend to accommodate it.

Policies and procedures require the same treatment. Every SP 800-53 family's -1 control requires review at an organization-defined frequency and upon significant change. Procedures that describe a decommissioned tool or a superseded workflow are findings, and they are also operationally dangerous, because staff following them do the wrong thing.


4. Revising the Monitoring Strategy

The final bullet is the one candidates most often overlook: "revising monitoring strategies based on updates to legal, regulatory, supplier, security and privacy requirements." The monitoring strategy is not a fixed artifact approved once at Task S-6. It is itself subject to change control.

Triggers that require revision:

TriggerExampleEffect on Monitoring
New or amended regulationA new breach-notification law with a shorter deadlineAdd detection and notification-timeliness metrics
Framework revisionA new revision of the control catalog or an updated overlayRe-map monitored controls; add newly required ones
Supplier changeA provider moves services to a new region or subprocessorAdd monitoring of the new dependency and its assurance status
Threat environment shiftA control's associated technique becomes actively exploitedIncrease that control's assessment frequency
Incident or assessment findingsRepeated findings in one familyIncrease frequency; add targeted metrics
Architecture changeMigration to containers or a new cloud serviceExisting instrumentation may no longer observe the control

The governance requirement behind this is regulatory horizon scanning — a defined, assigned responsibility for tracking changes in applicable legal, regulatory, and framework requirements, with a path from "a requirement changed" to "the control set, documentation, and monitoring strategy were updated accordingly." Organizations without that assignment discover requirement changes during audits, which is the most expensive possible moment.

[!NOTE] Revisions follow the same approval path as the original. A materially changed monitoring strategy is reviewed and approved by the Authorizing Official, because the AO's ongoing risk acceptance depends on the monitoring regime that informs it. Silently reducing assessment frequencies to save effort changes the basis on which authorization was granted — and an AO who learns of it during an audit rather than through the approval path has been deprived of the information their decision rests on.

Loading diagram...
Sustaining Activities: Training, Evidence and Monitoring-Strategy Revision
Test Your Knowledge

An organization reports 100% completion of its annual security awareness training for all staff. During assessment, the assessor cites a training deficiency. What is the most likely basis?

A
B
C
D
Test Your Knowledge

A cloud provider's service level agreement commits to notifying the customer of security incidents within five business days. The customer is a GDPR controller and a US federal agency. What is the compliance problem?

A
B
C
D
Test Your Knowledge

To reduce operational effort, an ISSO extends the assessment interval for several controls in the continuous monitoring strategy without notifying anyone. Why is this a governance failure?

A
B
C
D