7.4 Awareness, Training, Evidence Collection and Monitoring-Strategy Revision
Key Takeaways
- Security and privacy awareness training is a recurring compliance obligation whose completion records are the primary assessment evidence.
- Role-based training under AT-3 targets personnel with significant security responsibilities and is distinct from general awareness training under AT-2.
- Evidence must be contemporaneous, attributable, and retained for the defined period, because evidence reconstructed before an audit demonstrates documentation rather than operation.
- Third-party contracts, service level agreements, policies, and procedures must be reviewed and updated as part of ongoing compliance, not only at renewal.
- The monitoring strategy itself must be revised when legal, regulatory, supplier, security, or privacy requirements change, or the programme monitors an obsolete requirement set.
Awareness, Training, Evidence Collection and Monitoring-Strategy Revision
Three bullets of task 7.2 cover the sustaining activities that keep a compliance programme honest between assessments: evidence collected and documentation updated, awareness and training performed and retained, and monitoring strategies revised in response to changing requirements. These are the activities most likely to lapse quietly, which is why they are so heavily represented in audit findings.
1. Awareness and Training
The blueprint names the categories explicitly — contingency, incident response, annual security and privacy — and the exam tests the distinction between two different obligations.
| Control | Audience | Content | Typical Cadence |
|---|---|---|---|
| AT-2 — Literacy Training and Awareness | Everyone with system access | General security and privacy awareness: phishing, handling rules, reporting obligations, acceptable use | On hire, then annually |
| AT-3 — Role-Based Training | Personnel with significant security or privacy responsibilities | Skills specific to the role: assessors, ISSOs, developers, privileged administrators, AOs | On assignment, then annually |
| IR-2 — Incident Response Training | Personnel with IR roles | Their specific responsibilities during an incident | Annually |
| CP-3 — Contingency Training | Personnel with recovery roles | Their specific responsibilities during recovery | Annually |
| AT-4 — Training Records | — | Documentation and retention of all of the above | Per retention schedule |
The common failure is treating general awareness training as satisfying every training control. Annual awareness training that everyone completes does not satisfy AT-3, IR-2, or CP-3, each of which addresses a distinct population with distinct content. An organization with 100% awareness completion and no role-based training for its privileged administrators has an open finding.
AT-2 also carries an insider-threat awareness element, and privacy training obligations attach wherever PII is processed — commonly reinforced by SAOP-directed content beyond the general curriculum.
Training Records Are the Evidence
AT-4 requires that training be documented and retained. The assessor tests completion, not availability: a course that exists in the learning management system and that 40% of staff completed is not a satisfied control. Records must show who completed what, when, and for role-based training, that the content matched the role. New joiners and role-changers are the population where gaps concentrate, because they fall outside the annual cycle.
2. Evidence Collection Discipline
Continuous monitoring produces evidence continuously — or it produces nothing an assessor can use. Three properties determine whether evidence is credible:
| Property | Requirement | Failure |
|---|---|---|
| Contemporaneous | Generated when the activity occurred | A review "documented" months later from memory |
| Attributable | Identifies who performed the activity and when | An undated, unsigned checklist |
| Retained | Kept for the defined period, protected from alteration | Logs rotated away before the retention period elapses |
[!IMPORTANT] Evidence assembled before an audit proves documentation, not operation. If an organization performs quarterly access reviews but only records them the week before an assessment, the assessor cannot distinguish a genuine quarterly process from a single retrospective exercise. In assessment terms, an activity that cannot be evidenced contemporaneously did not occur. This is why evidence collection is designed into the operational process rather than bolted on.
Typical evidence includes configuration exports and baseline comparisons, vulnerability scan results over time, access review records with reviewer and date, change records with security impact analyses, incident tickets with timestamps, training completion records, contingency test results, and audit log samples with review annotations.
3. Keeping Documentation and Third-Party Agreements Current
The blueprint explicitly names service level agreements, third-party contracts, policies, and procedures as documentation requiring update — which places supplier governance squarely inside ongoing compliance.
Third-party agreements drift out of alignment in predictable ways: security requirements written years ago no longer reflect current standards; the provider has changed its architecture, subprocessors, or data locations; incident notification timelines in the contract no longer satisfy current regulatory deadlines; assessment and audit rights were never exercised; the provider's own certification or authorization has lapsed.
Ongoing supplier compliance therefore includes reviewing agreements against current requirements, obtaining and reviewing the provider's current assurance artifacts (SOC 2 Type II reports, ISO/IEC 27001 certificates, FedRAMP authorization status), confirming customer-responsibility controls remain correctly implemented locally, and tracking fourth-party dependencies where a provider's own subprocessors change.
A concrete and examinable case: an SLA specifying incident notification "within five business days" cannot support a controller who must notify a supervisory authority within 72 hours under GDPR Article 33, or an agency that must notify CISA within one hour. The contract term must be renegotiated — the regulatory deadline does not bend to accommodate it.
Policies and procedures require the same treatment. Every SP 800-53 family's -1 control requires review at an organization-defined frequency and upon significant change. Procedures that describe a decommissioned tool or a superseded workflow are findings, and they are also operationally dangerous, because staff following them do the wrong thing.
4. Revising the Monitoring Strategy
The final bullet is the one candidates most often overlook: "revising monitoring strategies based on updates to legal, regulatory, supplier, security and privacy requirements." The monitoring strategy is not a fixed artifact approved once at Task S-6. It is itself subject to change control.
Triggers that require revision:
| Trigger | Example | Effect on Monitoring |
|---|---|---|
| New or amended regulation | A new breach-notification law with a shorter deadline | Add detection and notification-timeliness metrics |
| Framework revision | A new revision of the control catalog or an updated overlay | Re-map monitored controls; add newly required ones |
| Supplier change | A provider moves services to a new region or subprocessor | Add monitoring of the new dependency and its assurance status |
| Threat environment shift | A control's associated technique becomes actively exploited | Increase that control's assessment frequency |
| Incident or assessment findings | Repeated findings in one family | Increase frequency; add targeted metrics |
| Architecture change | Migration to containers or a new cloud service | Existing instrumentation may no longer observe the control |
The governance requirement behind this is regulatory horizon scanning — a defined, assigned responsibility for tracking changes in applicable legal, regulatory, and framework requirements, with a path from "a requirement changed" to "the control set, documentation, and monitoring strategy were updated accordingly." Organizations without that assignment discover requirement changes during audits, which is the most expensive possible moment.
[!NOTE] Revisions follow the same approval path as the original. A materially changed monitoring strategy is reviewed and approved by the Authorizing Official, because the AO's ongoing risk acceptance depends on the monitoring regime that informs it. Silently reducing assessment frequencies to save effort changes the basis on which authorization was granted — and an AO who learns of it during an audit rather than through the approval path has been deprived of the information their decision rests on.
An organization reports 100% completion of its annual security awareness training for all staff. During assessment, the assessor cites a training deficiency. What is the most likely basis?
A cloud provider's service level agreement commits to notifying the customer of security incidents within five business days. The customer is a GDPR controller and a US federal agency. What is the compliance problem?
To reduce operational effort, an ISSO extends the assessment interval for several controls in the continuous monitoring strategy without notifying anyone. Why is this a governance failure?