Requirements / Awareness and Training (AT)
AT.L2-3.2.3
Insider Threat Awareness
Official Source Material
Provide security awareness training on recognizing and reporting potential indicators of insider threat.
Determine if:
- [a] potential indicators associated with insider threats are identified; and
- [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
The free CDSE course carries this requirement.
Insider Threat Awareness, course INT101 from the Center for Development of Security Excellence, is built for exactly this requirement. Assign it, keep the completion record, and most of the work is done. Unlike AT.L2-3.2.1, this requirement has no organization-specific policy component, so generic government training can carry it.
Train on this annually.
The requirement text names no frequency. The CMMC rule at 32 CFR 170.4 defines periodically as at least annually, and assessors apply that reading here. A single session at hire earns a Not Met.
Add the reporting path.
The course tells people what an indicator looks like. Your training has to tell them who to report it to in your organization. One slide or one paragraph with the name and the channel is enough, and it is the one part the generic course cannot supply.
Do not agonize over the list of indicators.
The objectives ask that indicators are identified and that people are trained on them. There is no required count. The CDSE list is a fine starting set.
What falls short
- A single session with no recurrence. Training that has lapsed no longer provides what [b] asks for.
- The DoD Annual Security Refresher on its own. It touches insider threat only in passing, so it neither identifies the indicators for [a] nor trains people to recognize and report them for [b].
Edge cases
- Cleared facilities already run annual insider threat training under NISPOM, the National Industrial Security Program Operating Manual. It can do double duty only if everyone who handles CUI (Controlled Unclassified Information) takes it, including staff without clearances.
- Subcontractor staff with accounts on your system need the training too. Whose problem it is under NISPOM does not change whose problem it is under this requirement, because they are users of your system.