Why: Role-based training is the practice's core substance: mapping security-relevant roles to required competencies, training before duties begin, and refreshing as the stack changes is what both the practice and the requirement describe.
What this does not claim: The requirement covers everyone with security-relevant duties, including non-technical roles — the person who approves accounts, the office manager who handles visitor access — and outsourced ones; a program scoped only to the IT team leaves those populations unaddressed. Timing matters too: training must precede access and duties, which a catch-up program does not demonstrate.
- Maintain the role-to-competency matrix, including MSP and non-technical security duties
- Gate new duty assignments on completion of the role's training
- Refresh role training when platforms change
- The role-to-training matrix
- Completion records aligned to role assignment dates
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06