KSI-CED-RAT — Reviewing All Training
Official CR26 Key Security Indicator in the Cybersecurity Education family (KSI-CED). The statement below is verbatim from the catalog.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
Official requirement
The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.
Assessment considerations
The official reference cites no related SP 800-53 controls for this indicator.
Static HTML reference: scm.cc/ksi/ksi-ced-rat/. Interactive view: KSI Explorer (in progress).
Related hub pages
Primary sources
- FedRAMP 20x Key Security Indicators (CR26) (retrieved 2026-09-27)
Last verified 2026-09-27. FedRAMP.gov is authoritative.