What type of control is security awareness training?
Security awareness training is an administrative control, sometimes called a managerial or operational control, because it works through people and policy rather than technology. Its primary function is preventive: it reduces the chance of a successful attack before one happens. It also builds a detective capability, because trained staff who report suspicious emails become sensors for attacks already in progress.
Where the frameworks place it
In NIST SP 800-53 awareness and training has its own control family, AT, with AT-2 covering literacy training and awareness for all users. ISO 27001:2022 carries it as control 6.3, and PCI DSS requires a formal programme under requirement 12.6. If you are answering an exam or audit question, "administrative, preventive" is the expected classification.
| Framework | Where training sits |
|---|---|
| NIST SP 800-53 | AT control family (AT-2, Literacy Training and Awareness) |
| ISO 27001:2022 | Control 6.3, awareness, education and training |
| PCI DSS v4 | Requirement 12.6, security awareness programme |
| Essential Eight | Complementary people-layer control alongside the eight technical strategies |
train2secure maps its courses to the frameworks auditors ask about, with per-employee completion evidence you can hand over.
See how train2secure covers the control