GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-005 Role-Based Security Training

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Personnel in roles with elevated security responsibilities, including system administrators, developers, data handlers, and incident responders, receive role-specific security training before gaining access to production systems and at defined intervals thereafter. Training records are maintained for each individual. The training programme names the roles and positions that require security skills, the criteria by which a role enters the programme and the competence each named group reaches. The members of the management body are one such group, and their standard is enough knowledge and skill to identify risks and to assess the organisation's risk-management practices and their effect on the services it provides. The curriculum for each group covers the secure configuration and operation of the systems that group touches, the threats current against them and what to do when a security-relevant event occurs. Training is delivered before a transfer into a role the programme names as well as before production access is granted. The effect of the training is assessed rather than its completion counted, and the assessment result feeds the next revision of the programme.

Rationale

General awareness training is insufficient for personnel who make security-critical decisions or hold elevated privileges. Role-based training ensures that those with the greatest access have the domain-specific knowledge to exercise it safely. A group with a competence standard is a different instrument from a course with an attendance list: it says what the person can do afterwards, which is what makes a non-executive director with no system access trainable under a control whose original trigger was production access. The management body is the group most often outside every syllabus and the one a regulator asks about first. An assessment of effect rather than completion stops the programme drifting into a compliance click-through, and unless its result feeds the next revision it is only a second attendance record.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

Art. 20(2) and Annex points 8.2.2 to 8.2.4 are now stated: named role groups with the criteria by which a role enters the programme, a competence standard per group, the members of the management body as one of those groups with the Art. 20(2) standard of enough knowledge and skill to identify risks and assess risk-management practices and their effect on the services, training on transfer into a named role, and effectiveness assessed rather than completion counted. Annex point 8.1, the awareness programme reaching direct suppliers and service providers, stays a note on HRS-004.

Framework Mappings (13)

HRS-12Personal and Sensitive Data Awareness and Trainingfull
HRS-14AI Competency Traininginformative
HRS-12Personal and Sensitive Data Awareness and Trainingfull
EU-AI-Art.4AI Literacy — Measures to Support Staff and Operator Literacyinformative
HIPAA-164.308.a.5.iSecurity Awareness and Traininginformative
6.3Information security awareness, education and trainingpartial
NIS2-Art.20.2Management Body Cybersecurity Trainingfull
NIS2-Art.21.2.gBasic Cyber Hygiene Practices and Cybersecurity Traininginformative
NIS2-CIR-8.2Security Trainingfull
AT-3Role-based Trainingfull
AT-4Training Recordsfull
PM-13Security and Privacy Workforcepartial
CC1.4COSO Principle 4: Demonstrates Commitment to Competencepartial

Evidence (2)

system_exporttechnicalautomated

Role-based security training completion records for personnel in elevated-privilege or security-critical roles.

Example: Training completion records from the LMS (KnowBe4 / internal training platform) filtered to role-based tracks, e.g. 'Cloud Security for Admins', 'Secure Coding', 'Incident Response', showing: employee name, role, training completed, completion date, and next due date.

Test: Export role-based training completion records for system administrators, developers, and incident responders. Verify: (1) every individual in a defined elevated-privilege role has a training completion record for the relevant role track, (2) completion occurred before or within 30 days of gaining production access, (3) annual renewal completions are on file, (4) no individual in a high-privilege role is overdue. (5) every member of the management body carries a completion record against that group's curriculum, (6) a person who transferred into a named role in the period completed its training on or before the transfer date, (7) the effectiveness assessment for each group is recorded with its result and the revision it produced.

policydocumentmanual

Role-based training procedure defining which roles require additional training, the required curriculum per role, and the completion deadline before production access is granted.

Example: Role-Based Security Training Procedure (Confluence), listing: designated high-sensitivity roles (e.g. sysadmin, DevOps, data engineer, security analyst), required training modules per role, maximum time-to-complete after role assignment, and records retention requirement.

Test: Request the role-based training procedure. Verify: (1) at least three distinct elevated-privilege role categories are listed, (2) specific training modules are assigned to each role, (3) a maximum time-to-complete deadline is stated, (4) the procedure is approved and dated within the last 12 months. (5) the procedure names the criteria by which a role enters the programme rather than only listing the roles, (6) each named group carries a competence standard and a curriculum covering secure configuration and operation, current threats and behaviour when a security-relevant event occurs, (7) the members of the management body are a named group with a competence standard of their own, (8) the procedure triggers training on transfer into a named role as well as on the grant of production access.

Questions (3)

boolean

Do personnel in elevated-privilege or security-critical roles (e.g. sysadmins, developers, incident responders) receive role-specific security training before gaining production access and at defined intervals thereafter?

Role-based training records should show completion before or within 30 days of production access being granted, with annual renewal records on file.

multi

Which of the following role-specific security training tracks does your organisation deliver?

Secure coding / application security for developersCloud or infrastructure security for system administratorsIncident response procedures for the security teamData handling and privacy for data engineers or analystsCybersecurity for the members of the management body, against a competence standard of their ownAI system governance or responsible AI for ML or AI rolesNone of the above

At least three distinct role tracks covering different privilege tiers are expected. Training is matched to the systems and data each role can reach. The management body track is the one most often absent, because the programme is usually built around who holds production access and the board holds none.

select

How is the effect of role-based training measured?

Assessed against the role's competence standard, with the result feeding the next revision of the programmeAssessed against the role's competence standardChecked by a test at the end of the moduleCompletion recorded, with no measure of effectNeither completion nor effect is recorded

Options run from strongest to weakest. A test at the end of a module measures recall of the module, not competence in the role, which is why it sits below an assessment against the standard. Answer on what happened at the last delivery rather than on what the procedure describes.