Why: Training personnel to carry out their assigned security duties is precisely this practice's core activity: a roles-to-competencies map, role-based training booked against the largest gaps, and cross-training so no duty is one person deep.
What this does not claim: Supports implementation of the requirement; it does not decide an assessment outcome on its own. Security duties also sit outside the technical team — HR handling terminations, shipping handling marked media — and those roles need duty training the practice as written does not reach.
- Maintain a role-to-competency matrix with tracked currency
- Book role-based training against identified gaps and cross-train single-person dependencies
- Feed exercise findings back into the training plan
- The roles-to-skills plan with completion evidence retained
- Skills-coverage and exercise-outcome tracking over time
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06