1. Purpose
The Information Security Awareness Policy establishes the organization’s requirements for ensuring that employees, contractors, consultants, interns, temporary workers, and relevant third-party personnel understand their information-security responsibilities.
The objective is to ensure that personnel:
- Understand the organization’s security expectations
- Recognize common security threats
- Protect organizational and customer information
- Use systems and information securely
- Understand their access responsibilities
- Report security incidents and weaknesses promptly
- Understand applicable policies and procedures
- Receive security awareness appropriate to their role and risk
- Maintain security awareness throughout their engagement
Core Principle
Communicate → Train → Understand → Apply → Test → Monitor → Reinforce → Improve
2. Scope
This policy applies to:
☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Remote workers
☐ Third-party personnel with organizational access
☐ Privileged users
☐ Personnel with access to customer information
☐ Personnel with access to confidential or restricted information
☐ Personnel with security-sensitive responsibilities
The policy applies to information handled through:
- Applications
- Cloud services
- SaaS platforms
- Company devices
- Collaboration platforms
- Source-code repositories
- Production systems
- Databases
- Physical records
- Remote-working environments
3. Policy Statement
The organization shall provide information-security awareness appropriate to the responsibilities, access, information exposure, and risk of personnel.
Personnel shall:
- Understand applicable security policies
- Protect information entrusted to them
- Use organizational systems responsibly
- Protect passwords and credentials
- Use MFA where required
- Recognize and report suspicious activity
- Report security incidents and weaknesses
- Follow access-control requirements
- Protect customer and personal information
- Follow applicable security procedures
- Participate in required security awareness activities
Security awareness shall be treated as an ongoing activity rather than a one-time training event.
4. Security Awareness Objectives
The security awareness program should aim to:
☐ Reduce security-related human error
☐ Improve threat recognition
☐ Improve incident reporting
☐ Protect confidential information
☐ Protect customer information
☐ Protect personal data
☐ Improve password and authentication practices
☐ Improve phishing resistance
☐ Support secure remote working
☐ Support secure use of cloud and SaaS services
☐ Support compliance obligations
☐ Reinforce security responsibilities
☐ Improve security culture
5. Roles and Responsibilities
5.1 Management
Management shall:
- Support the security awareness program
- Provide appropriate resources
- Promote security accountability
- Review significant awareness risks
- Support corrective actions
5.2 Information Security
Information Security shall:
- Define awareness requirements
- Develop or coordinate awareness content
- Identify security-awareness risks
- Coordinate security campaigns
- Monitor awareness metrics
- Review effectiveness
- Report significant issues to management
5.3 HR / People Team
HR shall:
- Integrate awareness into onboarding
- Maintain relevant personnel records
- Coordinate required training
- Support role-change training
- Support offboarding requirements
5.4 Managers
Managers shall:
- Ensure personnel complete required training
- Identify role-specific training needs
- Reinforce security responsibilities
- Escalate repeated non-compliance
- Ensure employees understand security expectations
5.5 IT
IT shall support:
- Technical security awareness
- Phishing simulations where approved
- MFA awareness
- Secure device practices
- Access-related awareness
- Security communications
5.6 Employees and Contractors
Personnel shall:
- Complete required training
- Follow security policies
- Protect credentials
- Protect information
- Report suspicious activity
- Participate in awareness activities
- Cooperate with security investigations
- Ask for clarification when security requirements are unclear
6. Security Awareness Requirements
Personnel shall receive awareness appropriate to their role and responsibilities.
Awareness may cover:
☐ Information security policies
☐ Acceptable use
☐ Password security
☐ MFA
☐ Phishing
☐ Social engineering
☐ Malware
☐ Ransomware
☐ Business email compromise
☐ Data protection
☐ Information classification
☐ Secure information sharing
☐ Remote working
☐ Device security
☐ Cloud security
☐ SaaS security
☐ Incident reporting
☐ Physical security
☐ Privacy
☐ AI and generative AI
☐ Customer-specific security requirements
7. Security Awareness Before Access
Where appropriate, security awareness shall be completed before personnel receive access to sensitive systems or information.
Before access is granted, verify applicable requirements such as:
☐ Security responsibilities communicated
☐ Relevant policies provided
☐ Confidentiality requirements completed
☐ Basic security awareness completed
☐ MFA requirements understood
☐ Incident reporting process communicated
Higher-risk access may require additional role-specific training.
8. New Joiner Awareness
Security awareness shall be incorporated into employee onboarding.
New personnel should understand:
- Information-security responsibilities
- Acceptable use
- Password and MFA requirements
- Information classification
- Confidentiality
- Phishing
- Incident reporting
- Device security
- Remote working
- Customer-data protection
- Personal-data protection
- AI usage requirements
Evidence may include:
- Training record
- Learning-management record
- Security acknowledgement
- Onboarding checklist
9. Annual Security Awareness
Personnel shall receive periodic security awareness appropriate to organizational risk.
Annual awareness may include:
☐ Security policy refresher
☐ Phishing awareness
☐ Social engineering
☐ Password/MFA security
☐ Data protection
☐ Incident reporting
☐ Remote working
☐ Device security
☐ Cloud/SaaS security
☐ AI security
☐ Physical security
☐ Recent organizational security incidents
☐ Emerging threats
The frequency should be based on risk and organizational requirements rather than treating annual training as the only possible awareness activity.
10. Role-Based Security Awareness
Personnel with specialized responsibilities shall receive additional training appropriate to their role.
Developers
Training may include:
- Secure coding
- Dependency security
- Secrets management
- Source-code protection
- Secure code review
- Vulnerability management
- Production security
DevOps / Cloud Administrators
Training may include:
- IAM
- MFA
- Privileged access
- Cloud configuration
- Logging
- Secrets
- Infrastructure security
- Production access
Security Personnel
Training may include:
- Incident response
- Threat detection
- Security monitoring
- Evidence handling
- Vulnerability management
- Security testing
Finance Personnel
Training may include:
- Business email compromise
- Payment fraud
- Phishing
- Financial information protection
- Social engineering
HR Personnel
Training may include:
- Employee personal data
- Confidential records
- Access control
- Phishing
- Privacy requirements
11. Security Policy Awareness
Personnel shall be made aware of policies relevant to their responsibilities.
These may include:
☐ Information Security Policy
☐ Acceptable Use Policy
☐ Access Control Policy
☐ Password/MFA requirements
☐ Remote Working Policy
☐ Information Classification Policy
☐ Incident Management Policy
☐ Data Protection/Privacy Policy
☐ Cloud Security Policy
☐ Secure Development Policy
☐ AI Security Policy
☐ Business Continuity Policy
☐ Physical Security Policy
Policy communication may occur through:
- Training
- Employee portals
- Security campaigns
- Team meetings
- Learning platforms
- Policy acknowledgements
12. Security Acknowledgement
Where required, personnel shall acknowledge applicable security policies.
☐ Policy communicated
☐ Policy made available
☐ Employee reviewed policy
☐ Acknowledgement completed
☐ Overdue acknowledgements tracked
☐ Exceptions documented
Acknowledgement demonstrates communication and review. It does not by itself demonstrate that personnel understand or comply with every requirement.
13. Phishing Awareness
The organization shall promote awareness of phishing and social engineering.
Personnel should understand how to identify:
- Suspicious links
- Unexpected attachments
- Fake login pages
- Urgent payment requests
- Credential requests
- Impersonation
- Executive fraud
- Supplier impersonation
- Fake support requests
- Malicious QR codes
Personnel shall know how to report suspected phishing.
14. Phishing Simulations
Where appropriate and proportionate, the organization may conduct controlled phishing simulations.
Before conducting simulations:
☐ Objective defined
☐ Scope defined
☐ Appropriate authorization obtained
☐ Privacy considerations assessed
☐ Personnel impact considered
☐ Reporting process defined
☐ Results handling defined
Simulation results should be used primarily for education and improvement rather than unnecessary embarrassment or punitive treatment.
15. Password and Authentication Awareness
Personnel shall understand:
- Password protection
- MFA requirements
- Credential confidentiality
- Password reuse risks
- Password-manager use where approved
- Phishing-resistant authentication where available
- Account compromise reporting
Personnel shall not:
- Share passwords
- Share MFA codes
- Store credentials insecurely
- Bypass authentication controls
- Approve unexpected MFA requests
16. Information Classification Awareness
Personnel shall understand how to identify and handle:
Public
Information approved for public disclosure.
Internal
Information intended for internal organizational use.
Confidential
Information requiring controlled access and sharing.
Restricted
Highly sensitive information requiring enhanced protection.
Training shall explain applicable:
- Access requirements
- Sharing restrictions
- Storage requirements
- Transmission requirements
- Disposal requirements
17. Customer Information Awareness
Personnel handling customer information shall understand:
☐ Customer confidentiality
☐ Authorized access
☐ Data minimization
☐ Secure sharing
☐ Customer-specific requirements
☐ Incident reporting
☐ Retention requirements
☐ Deletion/return requirements
Customer contractual requirements shall be incorporated into awareness where relevant.
18. Personal Data and Privacy Awareness
Personnel who handle personal data shall understand:
- Appropriate use
- Access restrictions
- Data minimization
- Secure transfer
- Retention
- Deletion
- Privacy incidents
- Unauthorized disclosure
- Data-subject considerations where applicable
Privacy awareness shall be aligned with applicable legal and regulatory requirements.
19. Secure Remote Working Awareness
Remote personnel shall understand:
☐ Secure Wi-Fi/network use
☐ MFA
☐ Device security
☐ Screen locking
☐ Confidential conversations
☐ Secure information handling
☐ Public/shared environment risks
☐ VPN/secure access where required
☐ Lost-device reporting
☐ Phishing risks
20. Cloud and SaaS Awareness
Personnel using cloud and SaaS services shall understand:
- Approved cloud services
- Approved SaaS applications
- Access control
- MFA
- Data sharing
- Shadow IT risks
- File-sharing security
- Cloud credentials
- Secure configuration responsibilities
Personnel shall not introduce unapproved cloud services to process organizational or customer information where prohibited.
21. AI and Generative AI Awareness
Personnel using AI or generative AI tools shall understand:
☐ Approved AI tools
☐ Prohibited information
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ Confidential information restrictions
☐ Source-code restrictions
☐ Security risks
☐ Hallucination risks
☐ Output verification
☐ Intellectual-property considerations
☐ AI incident reporting
Sensitive organizational information shall not be submitted to AI services unless the use is authorized and appropriate safeguards are in place.
22. Security Incident Awareness
Personnel shall know how to report:
- Phishing
- Malware
- Lost devices
- Credential compromise
- Unauthorized access
- Accidental data disclosure
- Suspicious activity
- Security weaknesses
- Privacy incidents
- Suspected ransomware
- Unauthorized software
- Misuse of information
Personnel should be encouraged to report suspected incidents promptly rather than delay reporting because they are uncertain.
23. Security Weakness Reporting
Personnel should be encouraged to report security weaknesses such as:
- Misconfigured systems
- Exposed information
- Unprotected files
- Excessive access
- Security-control failures
- Vulnerabilities
- Suspicious applications
- Unusual system behavior
A defined reporting channel shall be available.
24. Physical Security Awareness
Where applicable, personnel shall understand:
☐ Visitor controls
☐ Badge protection
☐ Secure-area access
☐ Clean desk
☐ Clear screen
☐ Document protection
☐ Device protection
☐ Secure disposal
☐ Tailgating risks
☐ Lost access cards
25. Security Awareness Communications
Awareness may be reinforced through periodic communications.
Examples:
- Security newsletters
- Security tips
- Phishing alerts
- Threat advisories
- Short videos
- Posters
- Team briefings
- Security campaigns
- Incident lessons learned
- Security reminders
Communications should focus on relevant risks rather than generating excessive notification fatigue.
26. Security Awareness Campaigns
The organization may conduct focused campaigns such as:
January
Password and MFA security
February
Phishing awareness
March
Data protection
April
Secure remote working
May
Cloud security
June
Incident reporting
July
Social engineering
August
Secure development
September
Physical security
October
Cybersecurity awareness
November
AI security
December
Security lessons learned
The campaign schedule may be adjusted based on current threats and organizational risk.
27. Security Awareness Testing
Where appropriate, awareness effectiveness may be tested through:
☐ Knowledge assessments
☐ Phishing simulations
☐ Tabletop exercises
☐ Incident-reporting exercises
☐ Short quizzes
☐ Practical demonstrations
☐ Security drills
☐ Interviews
☐ Audit sampling
Testing should assess whether personnel can apply security requirements, not merely remember training content.
28. Security Awareness Metrics
The organization may monitor:
- Training completion rate
- Overdue training
- Policy acknowledgement rate
- Phishing simulation results
- Phishing reporting rate
- Security incident reporting rate
- Security quiz results
- Repeat awareness failures
- Role-specific training completion
- New-joiner training completion
- Privileged-user training completion
29. Awareness Effectiveness
The organization shall periodically evaluate whether awareness activities are effective.
Consider:
☐ Training completion
☐ Knowledge assessment
☐ Incident trends
☐ Phishing reporting
☐ Security violations
☐ Audit findings
☐ Access-related incidents
☐ Employee feedback
☐ Repeat failures
☐ Changes in threat environment
Training should be improved where evidence indicates that personnel are not effectively applying security requirements.
30. Security Awareness Exceptions
Where personnel cannot complete required training:
☐ Exception documented
☐ Reason recorded
☐ Risk assessed
☐ Compensating measure defined
☐ Manager approval obtained
☐ Security approval where required
☐ Completion deadline defined
☐ Exception monitored
31. Non-Compliance
Failure to complete required awareness activities may result in:
- Reminder
- Additional training
- Manager escalation
- Temporary restriction of sensitive access where appropriate
- Corrective action
- Disciplinary action where applicable
Any disciplinary action shall follow applicable organizational policy and law.
32. Third-Party Awareness
Relevant third-party personnel shall receive or acknowledge applicable security requirements.
This may include:
☐ Confidentiality
☐ Access requirements
☐ Information handling
☐ Incident reporting
☐ Customer requirements
☐ Acceptable use
☐ Cloud/security requirements
☐ Data protection
☐ Security testing restrictions
Supplier agreements should define responsibilities where appropriate.
33. Security Awareness Records
Appropriate records may include:
☐ Training attendance
☐ Course completion
☐ Assessment results
☐ Policy acknowledgements
☐ Awareness communications
☐ Phishing simulation results
☐ Campaign records
☐ Role-specific training
☐ Exceptions
☐ Corrective actions
☐ Effectiveness reviews
Records shall be protected against unauthorized access or modification.
34. Privacy of Awareness Records
Security awareness records may contain personnel information.
The organization shall:
- Limit access
- Collect only necessary information
- Define retention requirements
- Protect records
- Apply appropriate privacy controls
- Securely dispose of records when no longer required
35. Security Awareness Register
Maintain an appropriate register where needed.
| Personnel | Role | Training | Date | Status | Assessment | Next Due |
|---|---|---|---|---|---|---|
36. Awareness Review
The awareness program shall be reviewed periodically and when significant changes occur.
Review triggers may include:
☐ Major security incident
☐ Phishing increase
☐ New technology
☐ New cloud service
☐ New AI tool
☐ Regulatory change
☐ Customer requirement
☐ Significant audit finding
☐ New threat
☐ Organizational restructuring
☐ Major role changes
37. Security Awareness Governance
The organization shall maintain appropriate governance over the awareness program.
This may include:
- Program owner
- Training requirements
- Target audiences
- Training schedule
- Metrics
- Effectiveness assessment
- Exceptions
- Corrective actions
- Management reporting
38. Management Reporting
Significant awareness results may be reported to management.
Examples:
- Training completion
- Phishing trends
- Security incident trends
- Repeat awareness failures
- High-risk personnel training
- Awareness exceptions
- Security culture indicators
- Improvement actions
39. Continual Improvement
The organization shall improve the awareness program based on:
- Security incidents
- Audit findings
- Phishing results
- Employee feedback
- Emerging threats
- Technology changes
- Regulatory requirements
- Customer requirements
- Lessons learned
Improvement Cycle
Measure → Analyze → Improve → Communicate → Test → Reassess
40. AWS SaaS Startup Example
An AWS SaaS startup has:
- Developers
- DevOps engineers
- Sales personnel
- Customer support
- Finance
- HR
- Remote employees
A common awareness program could include:
All Personnel
- Phishing
- MFA
- Passwords
- Incident reporting
- Data classification
- Remote working
- AI usage
Developers
- Secure coding
- Secrets
- Source-code protection
- Dependency security
DevOps
- AWS IAM
- Privileged access
- Production security
- Cloud logging
- Secrets management
Finance
- Business email compromise
- Payment fraud
- Supplier impersonation
Customer Support
- Customer-data protection
- Identity verification
- Secure information sharing
HR
- Employee personal data
- Confidential information
- Phishing
Evidence
The startup should be able to demonstrate:
Training Assigned → Training Completed → Knowledge/Behavior Tested → Results Reviewed → Improvements Made
41. Startup-Friendly Awareness Model
A startup can operate a lightweight but effective program.
At Joining
Security Orientation → Policy Review → Acknowledgement → Role Training
Monthly
Security Tip / Threat Alert
Quarterly
Focused Awareness Campaign
Annually
Security Awareness Refresher + Effectiveness Assessment
After Significant Events
Incident Lesson → Targeted Awareness → Control Improvement
For high-risk roles, add role-specific training and periodic testing.
42. Common Mistakes
Avoid:
- Treating annual training as the entire security-awareness program.
- Training everyone identically regardless of role.
- Measuring only training completion.
- Ignoring contractors and third-party personnel.
- Failing to train new employees before sensitive access.
- Not providing incident-reporting instructions.
- Ignoring phishing and social engineering.
- Ignoring AI-related security risks.
- Using excessive security communications that create alert fatigue.
- Failing to evaluate whether training changed behavior.
- Retaining unnecessary personal information in training records.
- Failing to update training after major incidents.
- Treating acknowledgement as proof of compliance.
- Not providing role-specific training for privileged personnel.
43. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Establishes overall security expectations |
| Employee Security Responsibilities | Defines personnel security obligations |
| Employee Security Acknowledgement | Records communication and acknowledgement |
| Employee Onboarding Checklist | Introduces security requirements |
| Employee Role Change Checklist | Identifies new training requirements |
| Employee Offboarding Procedure | Controls security during exit |
| Security Awareness Training Procedure | Defines operational training process |
| Security Awareness Training Register | Records training |
| Phishing Awareness Procedure | Supports phishing education/testing |
| Acceptable Use Policy | Defines acceptable technology use |
| Information Classification Policy | Defines information handling |
| Incident Management Procedure | Defines incident reporting |
| Access Management Procedure | Defines access responsibilities |
| AI Security Policy | Defines secure AI use |
| Personnel Security Policy | Defines broader personnel controls |
44. ISO/IEC 27001 Connection
Information-security awareness supports the organization’s risk-based management of personnel security, security responsibilities, awareness, training, access, information protection, and related operational controls.
The Information Security Awareness Policy is not itself a universally prescribed ISO/IEC 27001 document title.
The organization should determine the appropriate awareness activities based on:
- ISMS scope
- Risk assessment
- Statement of Applicability
- Personnel roles
- Information handled
- Systems accessed
- Legal/regulatory requirements
- Customer requirements
- Contractual requirements
- Security incidents
- Audit findings
- Threat environment
The awareness program should demonstrate not only that training was delivered, but that relevant personnel received appropriate information and that the organization evaluates whether awareness is effective.
45. Audit Evidence Checklist
The organization should retain appropriate evidence such as:
☐ Approved awareness policy
☐ Awareness plan
☐ Training materials
☐ Training schedule
☐ Training assignments
☐ Training completion records
☐ Security acknowledgements
☐ Knowledge assessments
☐ Phishing simulation results where applicable
☐ Awareness campaigns
☐ Security communications
☐ Role-specific training
☐ Training exceptions
☐ Corrective actions
☐ Effectiveness assessments
☐ Awareness metrics
☐ Management reporting
Evidence should be proportionate to risk and should not contain unnecessary sensitive personnel information.
46. Policy Review
This policy shall be reviewed periodically and when significant changes occur.
Review triggers include:
☐ Major security incident
☐ Significant audit finding
☐ New technology
☐ New regulatory requirement
☐ New customer requirement
☐ Organizational change
☐ Major change in threat environment
☐ Significant changes to the ISMS
Policy Owner
Name/Role: ______________________________
Approval
Approved By: _____________________________
Approval Date: ____________________________
Next Review Date
47. Final Security Awareness Audit Trail
The organization should be able to demonstrate:
Who needs security awareness?
What security knowledge do they need?
Why is that knowledge relevant to their role?
When was the awareness provided?
Did the personnel complete it?
Did they understand the requirements?
Can they recognize and report security threats?
How is awareness effectiveness measured?
What happens when awareness is not effective?
How are lessons from incidents and audits incorporated into future training?
Final Principle
Security awareness is not simply completing a training course. It is an ongoing process of communicating security expectations, developing appropriate knowledge and behavior, testing effectiveness, learning from incidents, and continually improving the organization’s security culture.
