AT-3(3): Practical Exercises
Control Family:
Parent Control:
Baselines:
(Not part of any baseline)
Next Version:
- NIST Special Publication 800-53 Revision 5:
- AT-3(3): Practical Exercises
Control Statement
The organization includes practical exercises in security training that reinforce training objectives.
Supplemental Guidance
Practical exercises may include, for example, security training for software developers that includes simulated cyber attacks exploiting common software vulnerabilities (e.g., buffer overflows), or spear/whale phishing attacks targeted at senior leaders/executives. These types of practical exercises help developers better understand the effects of such vulnerabilities and appreciate the need for security coding standards and processes.