All questions

What type of control is security awareness training?

The straight answer

Security awareness training is an administrative control, sometimes called a managerial or operational control, because it works through people and policy rather than technology. Its primary function is preventive: it reduces the chance of a successful attack before one happens. It also builds a detective capability, because trained staff who report suspicious emails become sensors for attacks already in progress.

Where the frameworks place it

In NIST SP 800-53 awareness and training has its own control family, AT, with AT-2 covering literacy training and awareness for all users. ISO 27001:2022 carries it as control 6.3, and PCI DSS requires a formal programme under requirement 12.6. If you are answering an exam or audit question, "administrative, preventive" is the expected classification.

FrameworkWhere training sits
NIST SP 800-53AT control family (AT-2, Literacy Training and Awareness)
ISO 27001:2022Control 6.3, awareness, education and training
PCI DSS v4Requirement 12.6, security awareness programme
Essential EightComplementary people-layer control alongside the eight technical strategies

train2secure maps its courses to the frameworks auditors ask about, with per-employee completion evidence you can hand over.

See how train2secure covers the control