PCI DSS v4.0 Req. 12.6.3 |
Upon hire and at least once every 12 months |
Phishing and social engineering (12.6.3.1) and acceptable use of end user technologies (12.6.3.2), both mandatory since March 31, 2025 |
Anyone handling or with access to cardholder data or the CDE |
NYDFS Part 500 500.14(a)(3) |
Periodic, but at a minimum annual |
Cybersecurity awareness training that includes social engineering, updated to reflect risks identified in the risk assessment |
All personnel of NY regulated financial services covered entities |
HIPAA Security Rule 45 CFR 164.308(a)(5) |
No interval stated. Security reminders are an addressable specification |
Security reminders, protection from malicious software, log-in monitoring, password management |
All workforce members of covered entities and business associates, including management |
FTC Safeguards Rule 16 CFR 314.4(e) |
No interval stated. Updated as necessary to reflect risks identified by the risk assessment |
Security awareness training, plus separate ongoing updates and training for security personnel |
Non bank financial institutions under GLBA, which reaches auto dealers, mortgage brokers, and tax preparers |
NIST SP 800-171 Rev. 3 03.02.01 |
Initial training for new users, then at an organization defined frequency, plus after defined events |
Recognizing and reporting indicators of insider threat, social engineering, and social mining |
Contractors handling controlled unclassified information, and the basis for CMMC assessment |
SOC 2 Common Criteria |
Not a regulation. Your own stated commitment becomes the tested control |
Whatever your policy says, which is why auditors ask for the policy before they ask for the records |
Any service organization under audit, most commonly SaaS vendors |