Training & People · AT Domain

Training. Engineered.

Security awareness training that runs inside the 1TEN appliance. Courses are assigned by role, completion is tracked for every user, and the records link to the AT.L2 practices an assessor asks to see.

AT.L2 Practices 3.2.1, 3.2.2, 3.2.3
By role Courses assigned per user role
Per user Timestamped completion records
Capability

What Training Covers

1TEN includes security awareness courses covering CUI identification and handling, media protection procedures, social engineering recognition and reporting, system security responsibilities, incident reporting procedures, and physical security awareness. Courses are delivered within the appliance. No external LMS, no third-party platform, no CUI leaving the facility to reach a training system.

Courses are assigned by role. A production floor operator receives different content than an IT administrator or an executive. The role-based assignment approach satisfies both AT.L2-3.2.1 (general security awareness) and AT.L2-3.2.2 (role-specific security responsibilities) from a single training program.

Dashboard Requirements Evidence Training Reports

Training Courses

Total Courses
10
Active Courses
10
Library Templates
10
Course Type Duration Frequency Assignments Status Actions
CUI Awareness Training
CUI-101
AT.L2-3.2.1, AT.L2-3.2.2
Awareness
CUI
45 min Annual 48 total 4 done Active
Insider Threat Awareness
INT-101
AT.L2-3.2.3
Awareness
Insider Threat
35 min Annual 3 total 2 done Active
Media Protection
MED-101
MP.L2-3.8.1, MP.L2-3.8.2
Awareness
Media Protection
20 min Annual 2 total 2 done Active
Mobile Device Security
MOB-101
AC.L2-3.1.18, AC.L2-3.1.19
Awareness
Security
25 min Annual 0 total 0 done Active
New Employee Security Orientation
NEW-101
AT.L2-3.2.1, PS.L2-3.9.1
Awareness
Onboarding
60 min Annual 3 total 2 done Active
Password Security & MFA
PWD-101
IA.L2-3.5.1, IA.L2-3.5.2
Awareness
Security
20 min Annual 0 total 0 done Active
Phishing Awareness
PHI-101
AT.L2-3.2.1
Awareness
Security
20 min Annual 3 total 2 done Active
Physical Security
PHY-101
PE.L2-3.10.1, PE.L2-3.10.2
Awareness
Physical Security
25 min Annual 0 total 0 done Active
Security Awareness Training
SEC-101
AT.L2-3.2.1, AT.L2-3.2.2
Awareness
Security
40 min Annual 3 total 2 done Active
Security Incident Reporting
INC-101
IR.L2-3.6.1, IR.L2-3.6.2
Awareness
Incident Response
30 min Annual 0 total 0 done Active
Showing 10 of 10 courses
Evidence

Completion Records and Assessment Evidence

Every course completion is timestamped and attributed to a named user, capturing the course name, completion date, and the account that completed it. Records are exportable in the format assessors expect and are linked directly to AT.L2 requirements in the Requirements Browser, so the evidence connection is made before the assessor asks for it.

Inside the Module

What You See Inside

Role-based assignment
Different course sets for general users, IT staff, privileged users, and management, assigned by each user's role.
Per-user completion tracking
Every completion timestamped and attributed to a named account, with course name and date on the record.
Completion certificates
Generated per user per course. Printable and exportable in the format C3PAO assessors expect.
Overdue alerts
Surface on the Assessment Summary dashboard and Compliance Calendar before a renewal deadline forces the question.
Annual renewal tracking
Renewal due dates calculated automatically from each user's prior completion date.
On-premises delivery
All courses run inside the appliance. No external LMS, no user training data leaving the facility.
The problem this solves

When a C3PAO assessor asks to see training records, the answer is either a dated completion log with named individuals or it's a gap. An annual all-hands email with a PDF attachment, a verbal confirmation that everyone watched the video, or a sign-in sheet from two years ago does not satisfy the requirement. The records must be specific to individuals, tied to course content, and dated within the required renewal window.

Course Library

Included Courses

CUI Identification and Handling
All users · Annual renewal
AT.L2-3.2.1
Media Protection Procedures
All users · Annual renewal
AT.L2-3.2.1
Social Engineering Recognition and Reporting
All users · Annual renewal
AT.L2-3.2.3
Incident Reporting Procedures
All users · Annual renewal
AT.L2-3.2.1IR.L2-3.6.1
Physical Security Awareness
All users · Annual renewal
AT.L2-3.2.1
IT Security Responsibilities
IT administrators · Annual renewal
AT.L2-3.2.2
Privileged Access Responsibilities
Privileged users · Annual renewal
AT.L2-3.2.2
Security Oversight Responsibilities
Management · Annual renewal
AT.L2-3.2.2
Practices

Practices Satisfied

Practice IDDescription
AT.L2-3.2.1 Ensure that organizational personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems.
AT.L2-3.2.2 Ensure that organizational personnel are trained to carry out their assigned information security responsibilities.
AT.L2-3.2.3 Provide security awareness training on recognizing and reporting potential threats, including social engineering attacks.
Connected Modules

Related Modules

Engineered for the DIB.

1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.

Request a Demo