# AT-05 Contacts with Security Groups and Associations

NIST SP 800-53 control. Family: AT Awareness and Training. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into PM-15.

Statement: The organization establishes and maintains contacts with special interest groups, specialized forums, professional associations, news groups, and/or peer groups of security professionals in similar organizations to stay up to date with the latest recommended security practices, techniques, and technologies and to share the latest security-related information including threats, vulnerabilities, and incidents.
Guidance: To facilitate ongoing security education and training for organizational personnel in an environment of rapid technology changes and dynamic threats, the organization establishes and institutionalizes contacts with selected groups and associations within the security community. The groups and associations selected are in keeping with the organization’s mission requirements. Information sharing activities regarding threats, vulnerabilities, and incidents related to information systems are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance.

## Patterns that use it (2)
- Standard (2): SP-014 Awareness and Training Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern

## Clauses by framework (17 frameworks)
- iso_42001_2023: A.3.3
- anssi: Hygiene.1, Hygiene.4
- osfi_b13: B-13.1.1, B-13.3.3
- finma_circular: IV.B.a(48), IV.B.b(52), IV.B.c(53)
- gdpr: Art.39(1)(b)
- dora: Art.13(6), Art.45(1)
- lgpd_bcb: BCB.Art.4
- sama_csf: 1.6
- bom_ctrm: 3.8, 5.3
- cbe_csf: GOV-4
- cbn_csf: Part8
- eba_ict: 3.4.7
- ffiec_is: I.A
- iosco_cyber: PROT-4, SA-1, SA-2
- sebi_cscrf: CAPACITY, PR.AT
- cmmc_2: AT
- lloyds_ms: MS8.13

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AT-05
- Clauses only: /api/v1/controls/AT-05?fields=mappings
- Page for people: /controls/at-05/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
