data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_PR_AT_01_2

http://cyfun.data.gift/data/requirement_PR_AT_01_2
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_PR.AT-01

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

PR.AT-01.2: The organisation shall include insider threat awareness and reporting in its cyber- security training to help personnel recognise and respond to potential internal risks.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

PR.AT-01.2

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p105

  • External link
  • Internal link

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_IMPORTANT_E_p75

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.AT-01

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that all personnel are trained to recognise and report potential insider threats, thereby reducing the risk of internal cybersecurity incidents. This control builds on the general awareness from PR.AT-01.1 by introducing specific threat scenarios and response actions. The implementation should consider: - Training should include how to recognise behavioural signs of insiderthreats, such as unusual access patterns, data hoarding, or sudden changes in behaviour. - The organisation should define insider threats clearly (e.g. malicious, negligent, or compromised insiders, including employees and contractors). - Staff should be trained on how and where to report suspicious activity, and why timely reporting matters. - Real-life case studies or simulations should be used to show the impact of insider threats and reinforce learning. - Insider threat awareness should be part of regular security training and onboarding for all staff. - Specialised training should be provided to staff with access to sensitive data or systems, focusing on their specific responsibilities. - Cross-functional teams-training should be developed with both IT security and OT operational expertise (Cross-Training). - Annual refresher training should be used to reinforce key messages and introduce updates. - The organisation should promote a culture of securitywhere employees feel safe to report concerns without fear of retaliation.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that all personnel are trained to recognise and report potential insider threats, thereby reducing the risk of internal cybersecurity incidents. This control builds on the general awareness from PR.AT-01.1 by introducing specific threat scenarios and response actions. The implementation should consider: - Training should include how to recognise behavioural signs of insiderthreats, such as unusual access patterns, data hoarding, or sudden changes in behaviour. - The organisation should define insider threats clearly (e.g. malicious, negligent, or compromised insiders, including employees and contractors). - Staff should be trained on how and where to report suspicious activity, and why timely reporting matters. - Real-life case studies or simulations should be used to show the impact of insider threats and reinforce learning. - Insider threat awareness should be part of regular security training and onboarding for all staff. - Specialised training should be provided to staff with access to sensitive data or systems, focusing on their specific responsibilities. - Cross-functional teams-training should be developed with both IT security and OT operational expertise (Cross-Training). - Annual refresher training should be used to reinforce key messages and introduce updates. - The organisation should promote a culture of securitywhere employees feel safe to report concerns without fear of retaliation.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that all personnel are trained to recognise and report potential insider threats, thereby reducing the risk of internal cybersecurity incidents. This control builds on the general awareness from PR.AT-01.1 by introducing specific threat scenarios and response actions. The implementation should consider: • Training should include how to recognise behavioural signs of insiderthreats, such as unusual access patterns, data hoarding, or sudden changes in behaviour. • The organisation should define insider threats clearly (e.g. malicious, negligent, or compromised insiders, including employees and contractors). • Staff should be trained on how and where to report suspicious activity, and why timely reporting matters. • Real-life case studies or simulations should be used to show the impact of insider threats and reinforce learning. • Insider threat awareness should be part of regular security training and onboarding for all staff. • Specialised training should be provided to staff with access to sensitive data or systems, focusing on their specific responsibilities. • Cross-functional teams-training should be developed with both IT security and OT operational expertise (Cross-Training). • Annual refresher training should be used to reinforce key messages and introduce updates. • The organisation should promote a culture of securitywhere employees feel safe to report concerns without fear of retaliation.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to ensure that all personnel are trained to recognise and report potential insider threats, thereby reducing the risk of internal cybersecurity incidents. This control builds on the general awareness from PR.AT-01.1 by introducing specific threat scenarios and response actions. The implementation should consider:</p><ul><li>Training should include how to recognise behavioural signs of insiderthreats, such as unusual access patterns, data hoarding, or sudden changes in behaviour.</li><li>The organisation should define insider threats clearly (e.g. malicious, negligent, or compromised insiders, including employees and contractors).</li><li>Staff should be trained on how and where to report suspicious activity, and why timely reporting matters.</li><li>Real-life case studies or simulations should be used to show the impact of insider threats and reinforce learning.</li><li>Insider threat awareness should be part of regular security training and onboarding for all staff.</li><li>Specialised training should be provided to staff with access to sensitive data or systems, focusing on their specific responsibilities.</li><li>Cross-functional teams-training should be developed with both IT security and OT operational expertise (Cross-Training).</li><li>Annual refresher training should be used to reinforce key messages and introduce updates.</li><li>The organisation should promote a culture of securitywhere employees feel safe to report concerns without fear of retaliation.</li></ul></div>

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

PR.AT-01.2

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Insider threat awareness training

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall include insider threat awareness and reporting in its cyber- security training to help personnel recognise and respond to potential internal risks.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_IMPORTANT

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

19

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 21 of 21

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.AT-01

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.AT-01

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.