AT-3 Training: Same Completion Rate, Different Role Match
Two agencies. Same checklist answer: all personnel with CJI access have completed required annual security awareness training. Both reported 100% completion. Both had CJIS Online records to prove it.
The auditor asked what the IT administrator's training covered.
Agency A could show that the IT administrator completed the general awareness course — the same one patrol officers completed, the same one dispatchers completed. One course. One record. Training complete.
Agency B could show that the IT administrator completed a training program that addressed the IT user tier: AC-17 remote access monitoring, AU-6 audit log review, CM configuration management, IA identification and authentication, IR incident response, SA-9 external system services, and SI system integrity. The training content was matched to the role. The record showed which tier the individual was assigned to and which content was delivered.
The auditor noted Agency A's finding: AT-3(d)(2) requires additional training for IT users that covers specific control families not addressed in the general awareness curriculum. A general awareness course does not satisfy the IT user tier requirement regardless of completion status.
What the control actually requires
AT-3(d) defines four personnel tiers: general users, IT users, privileged users, and organizational personnel with security responsibilities. Each tier carries progressively broader training content requirements. The general tier is a subset of what the IT tier requires. Completing the general course does not satisfy the IT course requirement any more than completing a driver's education class satisfies a commercial vehicle licensing requirement.
AT-3(5) adds a fifth obligation for personnel with access to unencrypted CJI: training in the employment and operation of PII processing and transparency controls. This applies regardless of tier.
What the auditor is looking for
A roster showing which personnel are assigned to which tier. Training content documentation showing what each tier's curriculum covers and how it maps to the AT-3(d) requirements. Completion records per individual per tier. Evidence that the curriculum is updated when the policy changes, since AT-3(d)(3) requires privileged user training to address the most recent policy changes.
A 100% completion rate on the wrong course is a finding.
The common failure mode
Training was set up when the system was first deployed. One course was selected, everyone completed it, the records went into CJIS Online. Nobody revisited the training architecture when v6.0 restructured the requirements onto NIST 800-53 or when v6.1 took effect in June 2026. The course that satisfied the previous standard may not address what the current tiers require.
Written by Dr. Alexis W. Perdereaux-Weekes
DBA · CISA · CISM · CRISC · CDPSE
Founder, CJIS360 LLC
Sources: CJIS Security Policy v6.1, 06/25/2026 — AT-3 Role-Based Training; AT-3(d) Role-Based Training Content; AT-3(5) Processing Personally Identifiable Information; AT-4 Training Records; §1.4 Terminology Used in This Document.