1. Purpose
The Annual Security Awareness Plan defines the organization’s planned information-security awareness and training activities for the year.
The objective is to ensure that employees, contractors, temporary personnel, and relevant third parties:
- Understand their information-security responsibilities
- Recognize common security threats
- Protect organizational and customer information
- Use systems and technology securely
- Follow applicable security policies and procedures
- Know how and when to report security events
- Understand privacy and confidentiality responsibilities
- Receive additional training based on their roles and access
- Maintain security awareness throughout the year
Core Principle
Identify → Plan → Train → Test → Record → Monitor → Reinforce → Improve
2. Scope
This plan applies to relevant:
- Employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Privileged users
- Developers
- IT personnel
- Cloud administrators
- Security personnel
- Personnel handling customer or personal data
- Personnel with access to production systems
- Other third parties where security awareness requirements apply
Training should be proportionate to the person’s role, access, responsibilities, and risk.
3. Annual Plan Information
| Field | Details |
|---|---|
| Plan Year | |
| Organization | |
| ISMS Scope | |
| Security Awareness Owner | |
| HR Owner | |
| Security/IT Owner | |
| Plan Approval Date | |
| Effective Date | |
| Review Date | |
| Version | |
| Approved By |
4. Security Awareness Objectives
The annual program should establish measurable objectives.
Objectives
☐ Ensure new personnel receive security awareness training
☐ Complete annual security awareness training
☐ Provide role-based security training
☐ Improve phishing awareness
☐ Improve incident reporting
☐ Improve password and MFA awareness
☐ Improve information-classification awareness
☐ Improve customer-data protection
☐ Improve privacy awareness
☐ Improve cloud-security awareness
☐ Improve secure development awareness
☐ Improve AI-security awareness
☐ Reinforce acceptable-use requirements
☐ Measure training effectiveness
☐ Track overdue training
☐ Address recurring security weaknesses
5. Audience Classification
Classify personnel according to their security responsibilities.
| Audience | Typical Risk | Training |
|---|---|---|
| All Personnel | General security risk | General awareness |
| New Joiners | Initial security risk | Onboarding training |
| Developers | Application/source-code risk | Secure development |
| IT Administrators | Infrastructure risk | Infrastructure security |
| Cloud Administrators | Cloud/privileged risk | Cloud security |
| Security Team | Security operations risk | Advanced security |
| HR | Personnel/privacy risk | HR security and privacy |
| Finance | Financial/payment risk | Fraud, phishing, financial security |
| Management | Governance/risk | Security responsibilities |
| Customer Support | Customer-data risk | Data protection |
| Privileged Users | High-impact access | Privileged-user security |
| Contractors | Variable | Risk-based training |
| Interns | Limited/variable | Basic awareness |
6. Annual Training Categories
The awareness program should cover appropriate security topics throughout the year.
Core Topics
☐ Information security responsibilities
☐ Information classification
☐ Password security
☐ MFA
☐ Phishing
☐ Social engineering
☐ Malware and ransomware
☐ Safe email usage
☐ Safe browsing
☐ Incident reporting
☐ Data protection
☐ Privacy
☐ Remote working
☐ Mobile-device security
☐ Physical security
☐ Clean desk / clear screen
☐ Acceptable use
☐ Cloud security
☐ SaaS security
☐ Secure file sharing
☐ Third-party security
☐ Backup and recovery awareness
☐ Business continuity
☐ AI security
☐ Security policy awareness
7. Annual Awareness Calendar
A practical annual program can be structured as follows.
| Month | Primary Topic | Activity | Target Audience |
|---|---|---|---|
| January | Security Fundamentals | Annual security briefing | All |
| February | Phishing & Social Engineering | Awareness + simulation | All |
| March | Passwords & MFA | Training campaign | All |
| April | Data Classification & Protection | Training | All |
| May | Privacy & Personal Data | Awareness session | All / relevant roles |
| June | Cloud & SaaS Security | Role-based training | IT / Cloud / Engineering |
| July | Incident Reporting | Tabletop / awareness | All / Security |
| August | Secure Development | Secure coding session | Developers |
| September | Ransomware & Malware | Awareness campaign | All |
| October | AI Security | AI usage/security training | All / relevant roles |
| November | Remote & Endpoint Security | Training | All |
| December | Annual Security Review | Refresher + assessment | All |
The organization may adjust the calendar based on risk, incidents, audit findings, regulatory requirements, and business priorities.
8. January — Security Fundamentals
Topics
- Information-security responsibilities
- Security policies
- Acceptable use
- Information classification
- Confidentiality
- Passwords
- MFA
- Incident reporting
- Physical security
- Remote working
Activities
☐ Annual awareness session
☐ Policy refresher
☐ Security responsibilities communication
☐ Knowledge assessment
Evidence
- Training material
- Attendance/completion record
- Assessment results
- Communication evidence
9. February — Phishing and Social Engineering
Topics
- Phishing
- Spear phishing
- Business email compromise
- Social engineering
- Malicious links
- Malicious attachments
- Fake login pages
- Credential theft
- Urgency and manipulation techniques
Activities
☐ Phishing awareness training
☐ Phishing simulation where appropriate
☐ Reporting exercise
☐ Results analysis
Metrics
- Simulation participation
- Click rate
- Credential submission rate where safely measured
- Reporting rate
- Repeat failures
10. March — Passwords and MFA
Topics
- Strong authentication
- Password reuse
- Password managers
- MFA
- MFA fatigue
- Authentication security
- Credential sharing
- Account recovery
Activities
☐ Awareness campaign
☐ MFA refresher
☐ Password-security communication
☐ Assessment
11. April — Information Classification and Protection
Topics
- Public information
- Internal information
- Confidential information
- Restricted information
- Customer information
- Sensitive information
- Secure storage
- Secure transfer
- Information sharing
Practical Exercise
Provide examples and ask personnel to classify information correctly.
| Example | Expected Classification |
|---|---|
| Public website content | Public |
| Internal procedure | Internal |
| Customer contract | Confidential |
| Production credentials | Restricted |
The organization’s actual classification scheme should be used.
12. May — Privacy and Personal Data
Topics
- Personal data
- Sensitive information
- Data minimization
- Purpose limitation
- Secure handling
- Data sharing
- Data retention
- Data deletion
- Privacy incidents
- Individual rights where applicable
Target Audience
☐ All personnel
☐ HR
☐ Customer support
☐ Sales
☐ Marketing
☐ Product
☐ Engineering
☐ Personnel handling personal data
13. June — Cloud and SaaS Security
Topics
- Cloud security responsibilities
- IAM
- MFA
- Least privilege
- Secure configuration
- Secrets
- Cloud logging
- Data protection
- SaaS security
- Shadow IT
- API security
Target Audience
Primarily:
- IT
- Cloud administrators
- Developers
- DevOps
- Security personnel
14. July — Incident Reporting
Personnel should understand:
See → Stop → Report → Preserve → Cooperate
Training Topics
- What is a security incident?
- What is a security event?
- When should an incident be reported?
- Who should be contacted?
- What information should be provided?
- What should not be done?
- How to preserve evidence
Examples
- Lost device
- Phishing email
- Malware
- Suspicious login
- Data leakage
- Accidental disclosure
- Compromised credentials
- Unauthorized access
15. August — Secure Development
For engineering personnel:
☐ Secure coding
☐ Authentication security
☐ Authorization
☐ Input validation
☐ Secrets management
☐ Dependency security
☐ Vulnerability management
☐ Secure APIs
☐ Logging
☐ Security testing
☐ Code review
☐ Software supply-chain security
☐ SBOM awareness
☐ Secure deployment
16. September — Malware and Ransomware
Topics
- Malware
- Ransomware
- Malicious attachments
- Drive-by downloads
- Credential theft
- Suspicious software
- Endpoint protection
- Backup importance
- Incident reporting
Exercise
Conduct a short ransomware awareness scenario.
Example:
An employee opens an attachment and notices files becoming inaccessible.
Personnel should know:
- Stop interacting with the suspected system.
- Disconnect only according to the organization’s incident procedure.
- Report immediately.
- Do not attempt unauthorized remediation.
- Preserve relevant information.
- Cooperate with the incident-response team.
17. October — AI Security
Where AI tools are used, awareness should cover:
- Approved AI tools
- Confidential information
- Customer data
- Personal data
- Source code
- Credentials and secrets
- Prompt injection
- AI-generated content
- Data retention
- Third-party AI services
- Human review
- Accuracy and verification
- Intellectual property
- Shadow AI
Key Rule
Do not enter confidential, restricted, personal, customer, credential, or secret information into an AI service unless explicitly authorized.
18. November — Remote and Endpoint Security
Topics
☐ Secure remote working
☐ Device locking
☐ Endpoint protection
☐ Software updates
☐ Secure Wi-Fi
☐ VPN where required
☐ Device encryption
☐ USB/removable media
☐ Public locations
☐ Screen privacy
☐ Lost/stolen devices
☐ Physical security
19. December — Annual Security Refresher
Conduct an annual review covering:
- Major security policies
- Common incidents
- Lessons learned
- Phishing results
- Training completion
- Security weaknesses
- Policy changes
- Major audit findings
- New technologies
- New threats
- Upcoming security priorities
Final Assessment
☐ Annual refresher completed
☐ Knowledge assessment completed
☐ Outstanding training identified
☐ Corrective actions identified
☐ Next year’s priorities identified
20. New Joiner Training
Security awareness should not wait for the annual campaign.
New personnel should receive appropriate security awareness training as part of onboarding.
Minimum Topics
☐ Information-security responsibilities
☐ Acceptable use
☐ Passwords
☐ MFA
☐ Information classification
☐ Data protection
☐ Incident reporting
☐ Phishing
☐ Remote working
☐ Security policies
☐ Confidentiality
Evidence
☐ Training assigned
☐ Training completed
☐ Assessment completed where applicable
☐ Acknowledgement recorded
21. Role-Based Training
Additional training should be provided where a person’s role creates additional security responsibilities.
Examples
Developers
- Secure coding
- OWASP risks
- Dependency management
- Secrets
- Code security
Cloud Administrators
- IAM
- Privileged access
- Cloud configuration
- Logging
- Network security
HR
- Employee information
- Privacy
- Confidentiality
- Personnel security
Finance
- Fraud
- Business email compromise
- Payment security
Management
- Risk
- Security responsibilities
- Incident escalation
- Business continuity
Security Personnel
- Incident response
- Security monitoring
- Vulnerability management
- Evidence handling
22. Privileged User Training
Personnel with privileged access should receive additional training.
☐ Least privilege
☐ Privileged account security
☐ MFA
☐ Administrative activity
☐ Credential protection
☐ Logging
☐ Secure administration
☐ Emergency access
☐ Incident reporting
☐ Cloud security
☐ Production security
23. Security Awareness Delivery Methods
Use multiple methods rather than relying only on annual training.
Methods
- Classroom training
- Online training
- Security newsletters
- Email campaigns
- Short videos
- Posters
- Security alerts
- Phishing simulations
- Tabletop exercises
- Knowledge assessments
- Security quizzes
- Team meetings
- Policy acknowledgements
- Incident-based awareness
24. Security Awareness Campaigns
Campaigns may be launched in response to:
☐ Emerging threats
☐ Security incidents
☐ Phishing trends
☐ Audit findings
☐ Vulnerabilities
☐ New technology
☐ New regulations
☐ New customer requirements
☐ Policy changes
☐ Business changes
Campaign Record
| Campaign | Reason | Audience | Date | Result |
|---|---|---|---|---|
25. Phishing Simulation Program
Where appropriate, phishing simulations may be performed.
Before Simulation
☐ Objective defined
☐ Scope defined
☐ Participants identified
☐ Approval obtained
☐ Privacy considerations assessed
☐ Simulation rules defined
After Simulation
☐ Results analyzed
☐ High-risk behavior identified
☐ Additional training assigned
☐ Repeat trends analyzed
☐ Management reporting completed
Simulations should be conducted responsibly and should not unnecessarily collect or expose sensitive employee information.
26. Knowledge Assessment
Training effectiveness may be assessed through:
- Quizzes
- Tests
- Practical exercises
- Phishing simulations
- Tabletop exercises
- Interviews
- Observation
- Incident-reporting exercises
Assessment Result
| Training | Participants | Pass Rate | Issues | Action |
|---|---|---|---|---|
27. Training Completion Tracking
Maintain a training register.
| Employee | Role | Training | Assigned | Completed | Score | Status |
|---|---|---|---|---|---|---|
Status
- Not Assigned
- Assigned
- In Progress
- Completed
- Failed
- Overdue
- Exempted
28. Overdue Training
Where training is overdue:
- Identify the individual.
- Send reminder.
- Escalate where appropriate.
- Assign a completion deadline.
- Record the exception if required.
- Consider access/risk implications for high-risk roles.
- Confirm completion.
Overdue Register
| Person | Training | Due Date | Days Overdue | Escalation | Resolution |
|---|---|---|---|---|---|
29. Security Awareness Metrics
Track meaningful metrics rather than only training attendance.
Suggested Metrics
Training Completion Rate
Completed Training ÷ Assigned Training × 100
Assessment Pass Rate
Passed Assessments ÷ Completed Assessments × 100
Phishing Click Rate
Users Who Clicked ÷ Users Tested × 100
Phishing Reporting Rate
Users Who Reported ÷ Users Tested × 100
Overdue Training Rate
Overdue Training ÷ Assigned Training × 100
Additional Metrics
☐ Incident-reporting rate
☐ Repeat phishing failures
☐ Security-policy acknowledgement
☐ Training effectiveness
☐ Role-based training completion
☐ High-risk user completion
☐ Security-awareness findings
30. Training Effectiveness
Completion alone does not demonstrate effectiveness.
Evaluate whether personnel:
- Understand security requirements
- Apply security practices
- Recognize threats
- Report suspicious activity
- Protect information
- Follow policies
- Avoid repeated security mistakes
Effectiveness Evidence
☐ Assessment results
☐ Phishing results
☐ Incident trends
☐ Audit findings
☐ Interviews
☐ Observation
☐ Policy compliance results
☐ Repeat-failure analysis
31. Incident-Driven Training
Security incidents should be considered when updating awareness activities.
Example:
If multiple employees report phishing incidents involving fake Microsoft 365 login pages, the organization may launch a targeted campaign covering credential phishing, MFA fatigue, URL verification, and reporting.
Incident → Awareness Process
Incident → Analyze Cause → Identify Human Factor → Update Training → Deliver → Test → Monitor
32. Audit-Finding-Driven Training
Where an audit identifies a personnel-related weakness:
☐ Finding reviewed
☐ Root cause considered
☐ Training requirement assessed
☐ Target audience identified
☐ Training delivered
☐ Effectiveness tested
☐ Evidence retained
☐ Finding follow-up completed
Training should not be used as the automatic solution for every security finding. Where the root cause is a process, technology, or governance weakness, the organization should address that underlying issue.
33. Security Policy Awareness
The annual program should reinforce important security policies.
Examples:
- Information Security Policy
- Acceptable Use Policy
- Access Control Policy
- Password/MFA requirements
- Information Classification Policy
- Incident Management Policy
- Remote Working Policy
- Cloud Security Policy
- Data Protection/Privacy Policy
- AI Security Policy
- Supplier Security Policy
Evidence
☐ Policy communication
☐ Training
☐ Acknowledgement
☐ Assessment
☐ Refresher communication
34. Third-Party Awareness
Where relevant, third-party personnel should receive appropriate security information.
Examples:
- Security requirements
- Confidentiality
- Access restrictions
- Incident reporting
- Data handling
- Acceptable use
- Physical security
- Customer requirements
Training requirements should be defined contractually or through the applicable supplier-security process where necessary.
35. Security Awareness Register
| ID | Activity | Audience | Owner | Date | Completion | Result | Evidence |
|---|---|---|---|---|---|---|---|
36. Annual Training Plan Register
| Month | Topic | Audience | Delivery | Owner | Planned Date | Actual Date | Status |
|---|---|---|---|---|---|---|---|
| January | Security Fundamentals | All | Training | ||||
| February | Phishing | All | Simulation | ||||
| March | Password/MFA | All | Campaign | ||||
| April | Classification | All | Training | ||||
| May | Privacy | Relevant | Training | ||||
| June | Cloud Security | IT/Engineering | Training | ||||
| July | Incident Reporting | All | Exercise | ||||
| August | Secure Development | Developers | Workshop | ||||
| September | Ransomware | All | Campaign | ||||
| October | AI Security | All | Training | ||||
| November | Endpoint/Remote Work | All | Training | ||||
| December | Annual Refresher | All | Assessment |
37. Annual Review of the Program
At the end of the year, review:
☐ Training completion
☐ Assessment performance
☐ Phishing results
☐ Security incidents
☐ Human-related findings
☐ Repeat security weaknesses
☐ Policy changes
☐ Technology changes
☐ Business changes
☐ Regulatory changes
☐ Customer requirements
☐ Emerging threats
☐ Training effectiveness
☐ Feedback from personnel
38. Improvement Actions
| Issue | Root Cause | Improvement | Owner | Due Date | Status |
|---|---|---|---|---|---|
Potential improvements may include:
- New training modules
- More frequent awareness
- Role-based training
- Additional phishing simulations
- Updated policies
- Improved reporting channels
- Technical controls
- Process changes
- Additional management communication
39. Roles and Responsibilities
Management
- Approve security-awareness objectives
- Support participation
- Review significant results
- Provide resources
Security Team
- Define security topics
- Maintain the awareness program
- Identify emerging threats
- Conduct security campaigns
- Monitor effectiveness
HR
- Support onboarding
- Maintain personnel/training records
- Track mandatory training
- Support escalation
Managers
- Ensure team participation
- Address overdue training
- Support role-based training
Employees and Contractors
- Complete required training
- Understand responsibilities
- Apply security practices
- Report security events
- Participate in exercises
40. Evidence and Records
Retain appropriate evidence such as:
- Annual awareness plan
- Training calendar
- Training material
- Attendance records
- Completion records
- Assessment results
- Phishing simulation results
- Campaign communications
- Policy acknowledgements
- Role-based training records
- Overdue training records
- Training exceptions
- Effectiveness measurements
- Improvement actions
- Management reports
Records should be protected from unauthorized access and retained according to the organization’s records-retention requirements.
41. Exceptions
Where required training cannot be completed:
☐ Exception documented
☐ Reason recorded
☐ Risk assessed
☐ Compensating measure considered
☐ Responsible manager identified
☐ Security review completed where necessary
☐ Approval obtained
☐ Expiry/review date defined
42. AWS SaaS Startup Example
Consider a SaaS startup operating production workloads in AWS with:
- 30 employees
- 8 developers
- 2 cloud administrators
- 2 security personnel
- Remote workforce
- Customer data
- Production AWS access
- GitHub source code
- SaaS applications
- AI tools used by employees
Annual Awareness Plan
| Month | Activity |
|---|---|
| January | ISO 27001/security responsibilities |
| February | Phishing simulation |
| March | Password and MFA awareness |
| April | Customer-data classification |
| May | Privacy awareness |
| June | AWS/IAM security training |
| July | Incident-response tabletop |
| August | Secure coding workshop |
| September | Ransomware awareness |
| October | AI security awareness |
| November | Endpoint/remote-working security |
| December | Annual assessment |
Role-Based Training
Developers
- Secure coding
- Secrets management
- Dependency security
- GitHub security
- API security
Cloud Administrators
- AWS IAM
- MFA
- Privileged access
- CloudTrail/logging
- Secure configuration
All Employees
- Phishing
- MFA
- Data classification
- Customer data
- Incident reporting
- AI security
Audit Evidence
The startup can demonstrate:
Annual Plan → Training Calendar → Training Material → Attendance → Assessment → Phishing Results → Role-Based Training → Metrics → Improvement Actions
43. Startup-Friendly Awareness Model
A small startup does not need a large training department.
A practical model is:
Monthly
- One short security topic
- One awareness communication
- Relevant security alert
Quarterly
- One focused training session
- One knowledge assessment or exercise
Semi-Annual
- Phishing simulation
- Security-awareness metrics review
Annual
- Full security-awareness refresher
- Policy review
- Program effectiveness review
- Management reporting
- Next-year planning
This provides continuous awareness without creating excessive administrative overhead.
44. Common Mistakes
Avoid:
- Conducting security awareness only once per year.
- Measuring only attendance.
- Giving identical training to every role.
- Ignoring contractors.
- Ignoring privileged users.
- Ignoring developers.
- Ignoring cloud administrators.
- Not training new joiners.
- Not tracking overdue training.
- Not testing effectiveness.
- Not using incidents to improve training.
- Not addressing repeat phishing failures.
- Using training as the solution for every security weakness.
- Retaining unnecessary sensitive employee information.
- Not documenting evidence.
- Not reporting meaningful metrics to management.
45. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness requirements |
| Security Awareness and Training Procedure | Defines how training is performed |
| Annual Security Awareness Plan | Defines yearly activities |
| Security Awareness Training Register | Records training |
| Employee Onboarding Checklist | Ensures new joiner awareness |
| Employee Security Responsibilities | Defines personnel responsibilities |
| Acceptable Use Policy | Defines acceptable technology use |
| Incident Response Procedure | Provides incident-reporting requirements |
| Information Classification Policy | Defines information-handling requirements |
| Access Control Policy | Defines access-security responsibilities |
| HR Security Procedure | Supports personnel security |
| Security Compliance Monitoring Procedure | Measures compliance |
| Internal Audit Procedure | Provides independent assurance |
| Management Review | Reviews awareness performance where relevant |
46. ISO 27001 Connection
Security awareness supports the organization’s information-security objectives by ensuring that personnel understand relevant security responsibilities and are competent to perform security-related activities.
The organization’s awareness and training program should be based on:
- ISMS scope
- Information-security risks
- Roles and responsibilities
- Required competencies
- Applicable controls
- Security incidents
- Audit findings
- Legal/regulatory requirements
- Customer requirements
- Technology changes
- Business changes
The Annual Security Awareness Plan is not itself a universally mandatory ISO 27001 form. The organization should determine the appropriate training activities, frequency, audience, evidence, and effectiveness measures based on its ISMS and risk environment.
47. Annual Management Summary
At year-end, management should receive a concise summary.
| Metric | Result | Target | Status |
|---|---|---|---|
| Training completion | |||
| Assessment pass rate | |||
| Phishing click rate | |||
| Phishing reporting rate | |||
| Overdue training | |||
| Role-based training | |||
| Security campaigns | |||
| Training-related findings | |||
| Repeat failures |
Management Observations
Improvement Priorities
48. Approval
Plan Owner: __________________________
Security Owner: _______________________
HR Owner: _____________________________
Management Approver: _________________
Approval Date: ________________________
Plan Period: __________________________
Next Review Date: _____________________
49. Audit Evidence Checklist
For audit readiness, retain:
☐ Approved annual security awareness plan
☐ Annual training calendar
☐ Training materials
☐ New joiner training records
☐ Annual training records
☐ Role-based training records
☐ Training assessments
☐ Phishing simulation evidence
☐ Security campaign evidence
☐ Policy acknowledgement records
☐ Overdue training records
☐ Training exceptions
☐ Effectiveness metrics
☐ Incident-driven training evidence
☐ Audit-finding-driven training evidence
☐ Management reporting
☐ Improvement actions
☐ Next-year plan
50. Final Audit Trail
For each year, the organization should be able to demonstrate:
What security awareness risks did we identify?
Who required training?
What training did we plan?
Why did we select those topics?
Was training completed?
Did personnel understand the material?
How did we test effectiveness?
What did phishing simulations show?
What security incidents or audit findings influenced training?
What role-based training was provided?
What training remained overdue?
What improvements were identified?
Did management review the results?
Final Principle
Security awareness should not be treated as an annual checkbox. It should be a continuous, risk-based program that turns security policies and requirements into behaviors that employees, contractors, and other relevant personnel can understand, apply, and demonstrate.
Annual cycle:
Assess Risk → Identify Training Needs → Plan → Communicate → Train → Test → Measure → Reinforce → Improve → Plan Again
