ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Role-Based Security Training Matrix

Role-Based Security Training Matrix

1. Purpose

The Role-Based Security Training Matrix defines the security training requirements for different organizational roles based on their responsibilities, information access, system access, and security risk.

The objective is to ensure that employees receive:

  • General security awareness appropriate to everyone
  • Additional training appropriate to their role
  • Enhanced training for sensitive or privileged responsibilities
  • Training when responsibilities or access change
  • Refresher training at appropriate intervals
  • Evidence-based assessment of training completion and effectiveness

Core Principle

Role → Information → Access → Risk → Training → Assessment → Evidence → Review


2. Scope

This matrix may apply to:

  • Employees
  • Contractors
  • Interns
  • Temporary personnel
  • Consultants
  • Privileged users
  • Developers
  • Cloud administrators
  • IT personnel
  • Security personnel
  • HR personnel
  • Finance personnel
  • Management
  • Customer-support personnel
  • Personnel handling personal data
  • Personnel handling confidential or restricted information
  • Other relevant third parties

Training requirements should be proportionate to the actual role and risk.


3. Matrix Information

FieldDetails
Organization
Matrix Owner
Security Owner
HR Owner
Effective Date
Review Date
Version
Approved By

4. Training Level Definitions

Use a risk-based training model.

Level 1 — General Awareness

For personnel with normal organizational access.

Typical topics:

  • Security responsibilities
  • Passwords
  • MFA
  • Phishing
  • Information classification
  • Incident reporting
  • Acceptable use
  • Privacy
  • Remote working
  • Physical security

Level 2 — Role-Based

For employees with additional responsibilities.

Typical topics:

  • Role-specific information handling
  • Application security
  • Customer-data protection
  • Privacy
  • Business processes
  • Security procedures

Level 3 — Enhanced

For personnel with sensitive information, technical, administrative, or security responsibilities.

Typical topics:

  • Privileged access
  • Cloud security
  • Incident response
  • Vulnerability management
  • Secure configuration
  • Security monitoring
  • Advanced threat awareness

Level 4 — Specialized

For highly sensitive or specialist roles.

Typical topics:

  • Security operations
  • Digital forensics
  • Advanced incident response
  • Secure architecture
  • Penetration testing
  • Cloud security engineering
  • Security governance
  • Risk management

5. Core Training Topics

The organization may maintain the following training modules.

CodeTraining Topic
SEC-01Information Security Fundamentals
SEC-02Security Responsibilities
SEC-03Passwords and MFA
SEC-04Phishing and Social Engineering
SEC-05Malware and Ransomware
SEC-06Information Classification
SEC-07Data Protection and Privacy
SEC-08Incident Reporting
SEC-09Acceptable Use
SEC-10Remote Working Security
SEC-11Endpoint Security
SEC-12Physical Security
SEC-13AI Security
SEC-14Cloud Security
SEC-15Privileged Access Security
SEC-16Secure Development
SEC-17Vulnerability Management
SEC-18Security Logging and Monitoring
SEC-19Incident Response
SEC-20Business Continuity and Disaster Recovery
SEC-21Supplier and Third-Party Security
SEC-22Security Risk Management
SEC-23Security Governance
SEC-24Security Testing
SEC-25Data Breach Response
SEC-26Software Supply-Chain Security

6. Master Role-Based Training Matrix

Legend:

  • M = Mandatory
  • R = Required based on role/access
  • A = Awareness
  • E = Enhanced
  • S = Specialized
  • N/A = Normally not required
RoleGeneralPhishingPrivacyIncidentCloudPrivilegedSecure DevVulnerabilityAIBCP/DR
All EmployeesMMA/RMAN/AN/AAMA
ManagersMMRMARN/AAMM
HRMMMMAN/AN/AAMA
FinanceMMMMARN/AAMM
SalesMMMMAN/AN/AAMA
MarketingMMMMAN/AN/AAMA
Customer SupportMMMMRN/AN/AAMA
DevelopersMMRMRRMMMR
DevOpsMMRMMMMMMM
IT AdministratorsMMRMMMRMMM
Cloud AdministratorsMMRMMMRMMM
Security TeamMMRMMMRMMM
Database AdministratorsMMMMRMRMMM
System AdministratorsMMRMMMRMMM
Product TeamMMMMRRRRMR
Internal AuditMMMMRRRRMM
Senior ManagementMMMMARN/AAMM

This matrix should be customized to the organization’s actual roles, access, risks, and responsibilities.


7. All Employees

Mandatory

☐ SEC-01 Information Security Fundamentals

☐ SEC-02 Security Responsibilities

☐ SEC-03 Passwords and MFA

☐ SEC-04 Phishing and Social Engineering

☐ SEC-05 Malware and Ransomware

☐ SEC-06 Information Classification

☐ SEC-07 Data Protection and Privacy

☐ SEC-08 Incident Reporting

☐ SEC-09 Acceptable Use

☐ SEC-10 Remote Working Security

☐ SEC-11 Endpoint Security

☐ SEC-12 Physical Security

☐ SEC-13 AI Security where applicable

Frequency

  • New joiner
  • Annual refresher
  • Additional training when risk changes

8. Managers

Managers require all applicable general awareness training plus:

☐ Security responsibilities for teams

☐ Access approval responsibilities

☐ Security exception awareness

☐ Incident escalation

☐ Employee role changes

☐ Security policy enforcement

☐ Business continuity responsibilities

☐ Risk awareness

☐ Security performance monitoring

Additional Training

SEC-22 Security Risk Management

SEC-23 Security Governance

SEC-20 Business Continuity and Disaster Recovery


9. HR Personnel

HR personnel may handle sensitive employee information.

Required

☐ Personnel security

☐ Confidentiality

☐ Personal-data protection

☐ Employee information classification

☐ Secure document handling

☐ Employee onboarding security

☐ Employee offboarding security

☐ Security incident reporting

☐ Social engineering

☐ AI security

Additional

☐ Personnel screening requirements

☐ Data retention

☐ Access control

☐ Privacy requirements


10. Finance Personnel

Finance personnel may handle financial and payment information.

Required

☐ Phishing

☐ Business email compromise

☐ Payment fraud

☐ Financial information protection

☐ Approval fraud

☐ Social engineering

☐ Incident reporting

☐ Privacy

☐ Access security

☐ MFA

Enhanced

☐ Fraud scenarios

☐ Payment-security requirements

☐ Executive impersonation


11. Sales and Marketing

Training should include:

☐ Customer information protection

☐ CRM security

☐ Personal-data protection

☐ Secure file sharing

☐ Phishing

☐ Social engineering

☐ Approved SaaS applications

☐ AI usage

☐ External communication

☐ Incident reporting


12. Customer Support

Customer-support personnel may have direct access to customer information.

Required

☐ Customer-data protection

☐ Identity verification

☐ Authentication requirements

☐ Social engineering

☐ Account-takeover awareness

☐ Data classification

☐ Secure communication

☐ Incident reporting

☐ Privacy

☐ AI security

Enhanced Where Applicable

☐ Customer account administration

☐ Privileged customer support

☐ Production-data access


13. Developers

Developers require specialized secure-development training.

Required

☐ Secure Software Development Lifecycle

☐ Secure coding

☐ Authentication

☐ Authorization

☐ Input validation

☐ API security

☐ Secrets management

☐ Dependency management

☐ Vulnerability remediation

☐ Security testing

☐ Code review

☐ Source-code security

☐ Software supply-chain security

☐ SBOM awareness

☐ Secure deployment

☐ Production security

☐ AI-assisted development security


14. DevOps / Platform Engineers

Required

☐ Cloud security

☐ IAM

☐ Least privilege

☐ MFA

☐ Secrets management

☐ Infrastructure-as-Code security

☐ CI/CD security

☐ Container security

☐ Vulnerability management

☐ Logging

☐ Monitoring

☐ Backup

☐ Incident response

☐ Production access

☐ Change management

☐ Supply-chain security


15. IT Administrators

Required

☐ Identity and access management

☐ Privileged access

☐ Endpoint security

☐ Network security

☐ Patch management

☐ Vulnerability management

☐ Malware protection

☐ Logging and monitoring

☐ Backup and recovery

☐ Incident response

☐ Secure configuration

☐ Remote access

☐ MFA


16. Cloud Administrators

Required

☐ Cloud architecture security

☐ IAM

☐ Least privilege

☐ MFA

☐ Privileged access

☐ Network security

☐ Encryption

☐ Key management

☐ Secrets management

☐ Logging

☐ Monitoring

☐ Secure configuration

☐ Backup

☐ Disaster recovery

☐ Cloud incident response

☐ Cloud vulnerability management

AWS Example

Training may include:

  • AWS IAM
  • CloudTrail
  • Security Groups
  • KMS
  • Secrets Manager
  • S3 security
  • EC2 security
  • Cloud logging
  • GuardDuty/security monitoring where used

17. Database Administrators

Required

☐ Database security

☐ Privileged access

☐ Authentication

☐ Authorization

☐ Encryption

☐ Backup

☐ Recovery

☐ Database logging

☐ Data classification

☐ Sensitive-data handling

☐ Vulnerability management

☐ Secure administration

☐ Incident response


18. Security Personnel

Security personnel require enhanced or specialized training.

Required

☐ Security monitoring

☐ Incident response

☐ Security event analysis

☐ Incident investigation

☐ Evidence handling

☐ Vulnerability management

☐ Security testing

☐ Risk management

☐ Security architecture

☐ Threat awareness

☐ Security logging

☐ Business continuity

☐ Security reporting

Specialized Where Applicable

☐ Digital forensics

☐ Threat hunting

☐ Penetration testing

☐ Malware analysis

☐ Cloud security

☐ Security engineering


19. Senior Management

Senior management should understand security from a governance and risk perspective.

Required

☐ Information-security responsibilities

☐ Business risk

☐ Cybersecurity risk

☐ Major security incidents

☐ Security governance

☐ Risk acceptance

☐ Business continuity

☐ Regulatory obligations

☐ Customer security requirements

☐ Security metrics

☐ Security investment

☐ Crisis escalation


20. Internal Audit

Internal auditors should understand:

☐ ISMS principles

☐ Risk management

☐ Control objectives

☐ Evidence evaluation

☐ Audit methodology

☐ Security governance

☐ Access controls

☐ Security operations

☐ Cloud security where relevant

☐ Supplier security

☐ Incident management

☐ Business continuity

☐ Privacy

☐ Applicable regulatory requirements

Auditor competence should be appropriate to the scope and criteria of the audit.


21. Product Team

Product personnel may influence security requirements and customer commitments.

Required

☐ Security-by-design

☐ Privacy-by-design

☐ Customer security requirements

☐ Data classification

☐ Secure product requirements

☐ Security testing

☐ Vulnerability management

☐ Third-party components

☐ AI security

☐ Security incident escalation

☐ Regulatory/customer requirements


22. Security Training by Access Level

Training should also be determined by access, not only job title.

Access TypeMinimum Additional Training
Standard UserGeneral Awareness
Sensitive InformationData Protection + Classification
Customer DataPrivacy + Customer Data Protection
Personal DataPrivacy + Data Protection
Source CodeSecure Development
Cloud AccessCloud Security
Production AccessProduction Security
Privileged AccessPrivileged Access Security
Security AdministrationSecurity Operations
Database AccessDatabase Security
Incident ResponseIncident Response
Security TestingSecurity Testing
AI System AdministrationAI Security

23. Training Frequency

Training TypeSuggested Frequency
General Security AwarenessOnboarding + Annual
Phishing AwarenessAnnual + Periodic Campaigns
PrivacyOnboarding + Annual/Role-Based
Incident ReportingOnboarding + Annual
Privileged AccessOnboarding + Periodic Refresh
Cloud SecurityRole-Based + Periodic Refresh
Secure DevelopmentRole-Based + Periodic Refresh
Security OperationsRole-Based + Continuous
AI SecurityOnboarding + Annual + Change-Based
BCP/DRRole-Based + Exercise
Policy ChangesWhen Material Change Occurs
Incident-Driven TrainingAs Required
Audit-Finding TrainingAs Required

The actual frequency should be based on risk and organizational requirements.


24. New Employee Training

Before or shortly after access is granted, according to the organization’s onboarding process:

☐ General security awareness

☐ Password/MFA

☐ Phishing

☐ Incident reporting

☐ Information classification

☐ Acceptable use

☐ Privacy

☐ Remote working

☐ AI security where applicable

☐ Role-specific training


25. Role Change Training

When an employee changes roles:

☐ New role assessed

☐ New information access identified

☐ New system access identified

☐ New security risks assessed

☐ Training matrix reviewed

☐ Additional training identified

☐ Training assigned

☐ Training completed

☐ Evidence recorded


26. Privileged User Training

Employees receiving privileged access should receive enhanced training.

☐ Privileged account responsibilities

☐ Least privilege

☐ MFA

☐ Administrative credentials

☐ Secure administration

☐ Production security

☐ Logging

☐ Monitoring

☐ Emergency access

☐ Incident response

☐ Change management

☐ Access review


27. Training Assessment

Training should be assessed where appropriate.

Methods include:

  • Quiz
  • Knowledge test
  • Practical exercise
  • Phishing simulation
  • Tabletop exercise
  • Interview
  • Observation
  • Technical assessment
EmployeeRoleTrainingScoreResultRetest

28. Training Completion Register

EmployeeRoleTraining LevelRequired ModulesCompletedOutstandingStatus

Status

☐ Compliant

☐ Partially Compliant

☐ Training Outstanding

☐ Additional Training Required

☐ Exception Approved


29. Training Effectiveness

Training effectiveness should not be measured only by completion.

Consider:

☐ Assessment results

☐ Phishing results

☐ Incident trends

☐ Repeat security mistakes

☐ Audit findings

☐ Policy violations

☐ Security behavior

☐ Employee feedback

☐ Practical exercises

Effectiveness Result


30. Training Trigger Events

Additional training may be required following:

☐ New employee

☐ Role change

☐ New privileged access

☐ New production access

☐ New technology

☐ New cloud platform

☐ New application

☐ Security incident

☐ Data breach

☐ Major vulnerability

☐ Audit finding

☐ Policy change

☐ Regulatory change

☐ Customer requirement

☐ Significant business change

Process

Trigger → Assess Training Need → Assign → Complete → Assess → Record


31. Training Exceptions

Where required training cannot be completed:

Employee/Role: _______________________

Training: _____________________________

Reason: ______________________________

Risk: _________________________________

Compensating Control: _________________

Approver: _____________________________

Due Date: _____________________________

Review Date: __________________________


32. Training Evidence

Maintain appropriate evidence such as:

☐ Training assignment

☐ Training completion

☐ Attendance

☐ Assessment results

☐ Practical exercises

☐ Phishing results

☐ Role-based training records

☐ Policy acknowledgement

☐ Training exceptions

☐ Remedial training

☐ Management reports

☐ Effectiveness reviews

Do not retain unnecessary passwords, credentials, private keys, or other secrets as training evidence.


33. Matrix Review

Review the matrix periodically and when significant changes occur.

Review Triggers

☐ New role created

☐ Role responsibilities changed

☐ New technology

☐ New cloud platform

☐ New security risk

☐ Security incident

☐ Audit finding

☐ Regulatory change

☐ Customer requirement

☐ Organizational restructuring

☐ New AI technology

Review Result

☐ No Change Required

☐ Training Updated

☐ New Module Required

☐ Role Requirements Updated


34. AWS SaaS Startup Example

Consider a SaaS startup with:

  • 30 employees
  • AWS production infrastructure
  • GitHub source code
  • Customer data
  • Remote workforce
  • 8 developers
  • 2 cloud administrators
  • 2 privileged administrators

Training Matrix

RoleCorePrivacyCloudPrivilegedSecure DevIncidentAI
All Employees✓✓Awareness——✓✓
Developer✓✓Role-BasedIf applicable✓✓✓
Cloud Admin✓✓✓✓Role-Based✓✓
Security✓✓✓✓Role-Based✓✓
Management✓✓AwarenessAwareness—✓✓

Example

A developer who only has development AWS access does not automatically require the same cloud/privileged training as an AWS production administrator.

The training requirement follows:

Role + Information + Access + Risk

rather than job title alone.


35. Startup-Friendly Model

A startup can maintain the matrix without creating excessive administrative overhead.

Step 1 — Define Roles

Create a list of actual organizational roles.

Step 2 — Identify Risk

For each role identify:

  • Information
  • Systems
  • Privileged access
  • Production access
  • Customer data
  • Personal data
  • Security responsibility

Step 3 — Map Training

Assign:

  • General awareness
  • Role-based modules
  • Enhanced modules
  • Specialized modules

Step 4 — Track Completion

Maintain one training register.

Step 5 — Review

Review the matrix at least annually and whenever significant changes occur.


36. Common Mistakes

Avoid:

  • Giving every employee identical training.
  • Using job title alone to determine training.
  • Ignoring actual system access.
  • Ignoring privileged users.
  • Ignoring production access.
  • Ignoring developers.
  • Ignoring cloud administrators.
  • Ignoring customer-data access.
  • Not training new joiners.
  • Not updating requirements after role changes.
  • Measuring only completion.
  • Not tracking failed assessments.
  • Not tracking overdue training.
  • Not using incidents to update training.
  • Not reviewing the matrix when technology changes.
  • Creating too many training requirements without considering risk.

37. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness expectations
Security Awareness and Training ProcedureDefines training process
Annual Security Awareness PlanDefines yearly awareness activities
Employee Security Training ChecklistVerifies individual training
New Employee Security Onboarding ChecklistDefines initial onboarding requirements
Employee Role Change ChecklistTriggers training reassessment
Role-Based Security Responsibilities MatrixDefines role responsibilities
Privileged User Management ProcedureSupports privileged-user training
Access Management ProcedureIdentifies access-related training needs
Incident Response ProcedureProvides incident-related training requirements
Corrective Action TrackerTracks training-related corrective actions
Internal Audit ChecklistVerifies training implementation

38. ISO 27001 Connection

Role-based security training supports the organization’s ability to ensure that personnel performing work under its control have appropriate awareness and competence for their responsibilities.

Training requirements should be based on:

  • Job responsibilities
  • Information handled
  • System access
  • Privileged access
  • Production access
  • Security risks
  • Required competencies
  • Applicable policies
  • Security incidents
  • Audit findings
  • Legal and regulatory requirements
  • Customer requirements
  • Technology changes

The Role-Based Security Training Matrix is not itself a universally prescribed ISO 27001 form. The organization should determine the appropriate roles, training topics, frequency, assessment methods, and evidence based on its ISMS, risk assessment, applicable controls, and business requirements.


39. Management Summary

Management should be able to see whether security training is appropriately aligned with organizational risk.

MetricResultTargetStatus
General Training Completion
Role-Based Training Completion
Privileged User Training
Developer Training
Cloud Training
Incident Response Training
Privacy Training
AI Security Training
Overdue Training
Failed Assessments

Key Findings

Improvement Actions


40. Approval

Matrix Owner: _________________________

Security Owner: _______________________

HR Owner: _____________________________

Management Approver: _________________

Approval Date: ________________________

Next Review Date: _____________________


41. Final Audit Checklist

☐ Organizational roles identified

☐ Role responsibilities documented

☐ Information access assessed

☐ System access assessed

☐ Privileged access assessed

☐ Production access assessed

☐ Security risks considered

☐ General training defined

☐ Role-based training defined

☐ Enhanced training defined

☐ Specialized training defined

☐ Training frequency defined

☐ New-joiner requirements defined

☐ Role-change requirements defined

☐ Privileged-user requirements defined

☐ Training assessment defined

☐ Training evidence defined

☐ Effectiveness measurement defined

☐ Exceptions process defined

☐ Matrix review triggers defined

☐ Management reporting defined

☐ Matrix approved

☐ Matrix periodically reviewed


42. Final Audit Trail

For every important organizational role, the organization should be able to demonstrate:

What is the role?
What information does the role handle?
What systems does the role access?
Does the role have privileged or production access?
What security risks does the role create?
What training is therefore required?
Was the training completed?
Was understanding assessed?
Was additional training required?
What happens when the role changes?
How is training effectiveness monitored?
When is the matrix reviewed?

Final Principle

Security training should follow risk, not job title. The right training requirement is determined by the combination of a person’s role, information handled, system access, security responsibilities, and risk exposure.

Training lifecycle:

Role → Information → Access → Risk → Training → Assessment → Evidence → Monitor → Reassess