1. Purpose
The Role-Based Security Training Matrix defines the security training requirements for different organizational roles based on their responsibilities, information access, system access, and security risk.
The objective is to ensure that employees receive:
- General security awareness appropriate to everyone
- Additional training appropriate to their role
- Enhanced training for sensitive or privileged responsibilities
- Training when responsibilities or access change
- Refresher training at appropriate intervals
- Evidence-based assessment of training completion and effectiveness
Core Principle
Role → Information → Access → Risk → Training → Assessment → Evidence → Review
2. Scope
This matrix may apply to:
- Employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Privileged users
- Developers
- Cloud administrators
- IT personnel
- Security personnel
- HR personnel
- Finance personnel
- Management
- Customer-support personnel
- Personnel handling personal data
- Personnel handling confidential or restricted information
- Other relevant third parties
Training requirements should be proportionate to the actual role and risk.
3. Matrix Information
| Field | Details |
|---|---|
| Organization | |
| Matrix Owner | |
| Security Owner | |
| HR Owner | |
| Effective Date | |
| Review Date | |
| Version | |
| Approved By |
4. Training Level Definitions
Use a risk-based training model.
Level 1 — General Awareness
For personnel with normal organizational access.
Typical topics:
- Security responsibilities
- Passwords
- MFA
- Phishing
- Information classification
- Incident reporting
- Acceptable use
- Privacy
- Remote working
- Physical security
Level 2 — Role-Based
For employees with additional responsibilities.
Typical topics:
- Role-specific information handling
- Application security
- Customer-data protection
- Privacy
- Business processes
- Security procedures
Level 3 — Enhanced
For personnel with sensitive information, technical, administrative, or security responsibilities.
Typical topics:
- Privileged access
- Cloud security
- Incident response
- Vulnerability management
- Secure configuration
- Security monitoring
- Advanced threat awareness
Level 4 — Specialized
For highly sensitive or specialist roles.
Typical topics:
- Security operations
- Digital forensics
- Advanced incident response
- Secure architecture
- Penetration testing
- Cloud security engineering
- Security governance
- Risk management
5. Core Training Topics
The organization may maintain the following training modules.
| Code | Training Topic |
|---|---|
| SEC-01 | Information Security Fundamentals |
| SEC-02 | Security Responsibilities |
| SEC-03 | Passwords and MFA |
| SEC-04 | Phishing and Social Engineering |
| SEC-05 | Malware and Ransomware |
| SEC-06 | Information Classification |
| SEC-07 | Data Protection and Privacy |
| SEC-08 | Incident Reporting |
| SEC-09 | Acceptable Use |
| SEC-10 | Remote Working Security |
| SEC-11 | Endpoint Security |
| SEC-12 | Physical Security |
| SEC-13 | AI Security |
| SEC-14 | Cloud Security |
| SEC-15 | Privileged Access Security |
| SEC-16 | Secure Development |
| SEC-17 | Vulnerability Management |
| SEC-18 | Security Logging and Monitoring |
| SEC-19 | Incident Response |
| SEC-20 | Business Continuity and Disaster Recovery |
| SEC-21 | Supplier and Third-Party Security |
| SEC-22 | Security Risk Management |
| SEC-23 | Security Governance |
| SEC-24 | Security Testing |
| SEC-25 | Data Breach Response |
| SEC-26 | Software Supply-Chain Security |
6. Master Role-Based Training Matrix
Legend:
- M = Mandatory
- R = Required based on role/access
- A = Awareness
- E = Enhanced
- S = Specialized
- N/A = Normally not required
| Role | General | Phishing | Privacy | Incident | Cloud | Privileged | Secure Dev | Vulnerability | AI | BCP/DR |
|---|---|---|---|---|---|---|---|---|---|---|
| All Employees | M | M | A/R | M | A | N/A | N/A | A | M | A |
| Managers | M | M | R | M | A | R | N/A | A | M | M |
| HR | M | M | M | M | A | N/A | N/A | A | M | A |
| Finance | M | M | M | M | A | R | N/A | A | M | M |
| Sales | M | M | M | M | A | N/A | N/A | A | M | A |
| Marketing | M | M | M | M | A | N/A | N/A | A | M | A |
| Customer Support | M | M | M | M | R | N/A | N/A | A | M | A |
| Developers | M | M | R | M | R | R | M | M | M | R |
| DevOps | M | M | R | M | M | M | M | M | M | M |
| IT Administrators | M | M | R | M | M | M | R | M | M | M |
| Cloud Administrators | M | M | R | M | M | M | R | M | M | M |
| Security Team | M | M | R | M | M | M | R | M | M | M |
| Database Administrators | M | M | M | M | R | M | R | M | M | M |
| System Administrators | M | M | R | M | M | M | R | M | M | M |
| Product Team | M | M | M | M | R | R | R | R | M | R |
| Internal Audit | M | M | M | M | R | R | R | R | M | M |
| Senior Management | M | M | M | M | A | R | N/A | A | M | M |
This matrix should be customized to the organization’s actual roles, access, risks, and responsibilities.
7. All Employees
Mandatory
☐ SEC-01 Information Security Fundamentals
☐ SEC-02 Security Responsibilities
☐ SEC-03 Passwords and MFA
☐ SEC-04 Phishing and Social Engineering
☐ SEC-05 Malware and Ransomware
☐ SEC-06 Information Classification
☐ SEC-07 Data Protection and Privacy
☐ SEC-08 Incident Reporting
☐ SEC-09 Acceptable Use
☐ SEC-10 Remote Working Security
☐ SEC-11 Endpoint Security
☐ SEC-12 Physical Security
☐ SEC-13 AI Security where applicable
Frequency
- New joiner
- Annual refresher
- Additional training when risk changes
8. Managers
Managers require all applicable general awareness training plus:
☐ Security responsibilities for teams
☐ Access approval responsibilities
☐ Security exception awareness
☐ Incident escalation
☐ Employee role changes
☐ Security policy enforcement
☐ Business continuity responsibilities
☐ Risk awareness
☐ Security performance monitoring
Additional Training
SEC-22 Security Risk Management
SEC-23 Security Governance
SEC-20 Business Continuity and Disaster Recovery
9. HR Personnel
HR personnel may handle sensitive employee information.
Required
☐ Personnel security
☐ Confidentiality
☐ Personal-data protection
☐ Employee information classification
☐ Secure document handling
☐ Employee onboarding security
☐ Employee offboarding security
☐ Security incident reporting
☐ Social engineering
☐ AI security
Additional
☐ Personnel screening requirements
☐ Data retention
☐ Access control
☐ Privacy requirements
10. Finance Personnel
Finance personnel may handle financial and payment information.
Required
☐ Phishing
☐ Business email compromise
☐ Payment fraud
☐ Financial information protection
☐ Approval fraud
☐ Social engineering
☐ Incident reporting
☐ Privacy
☐ Access security
☐ MFA
Enhanced
☐ Fraud scenarios
☐ Payment-security requirements
☐ Executive impersonation
11. Sales and Marketing
Training should include:
☐ Customer information protection
☐ CRM security
☐ Personal-data protection
☐ Secure file sharing
☐ Phishing
☐ Social engineering
☐ Approved SaaS applications
☐ AI usage
☐ External communication
☐ Incident reporting
12. Customer Support
Customer-support personnel may have direct access to customer information.
Required
☐ Customer-data protection
☐ Identity verification
☐ Authentication requirements
☐ Social engineering
☐ Account-takeover awareness
☐ Data classification
☐ Secure communication
☐ Incident reporting
☐ Privacy
☐ AI security
Enhanced Where Applicable
☐ Customer account administration
☐ Privileged customer support
☐ Production-data access
13. Developers
Developers require specialized secure-development training.
Required
☐ Secure Software Development Lifecycle
☐ Secure coding
☐ Authentication
☐ Authorization
☐ Input validation
☐ API security
☐ Secrets management
☐ Dependency management
☐ Vulnerability remediation
☐ Security testing
☐ Code review
☐ Source-code security
☐ Software supply-chain security
☐ SBOM awareness
☐ Secure deployment
☐ Production security
☐ AI-assisted development security
14. DevOps / Platform Engineers
Required
☐ Cloud security
☐ IAM
☐ Least privilege
☐ MFA
☐ Secrets management
☐ Infrastructure-as-Code security
☐ CI/CD security
☐ Container security
☐ Vulnerability management
☐ Logging
☐ Monitoring
☐ Backup
☐ Incident response
☐ Production access
☐ Change management
☐ Supply-chain security
15. IT Administrators
Required
☐ Identity and access management
☐ Privileged access
☐ Endpoint security
☐ Network security
☐ Patch management
☐ Vulnerability management
☐ Malware protection
☐ Logging and monitoring
☐ Backup and recovery
☐ Incident response
☐ Secure configuration
☐ Remote access
☐ MFA
16. Cloud Administrators
Required
☐ Cloud architecture security
☐ IAM
☐ Least privilege
☐ MFA
☐ Privileged access
☐ Network security
☐ Encryption
☐ Key management
☐ Secrets management
☐ Logging
☐ Monitoring
☐ Secure configuration
☐ Backup
☐ Disaster recovery
☐ Cloud incident response
☐ Cloud vulnerability management
AWS Example
Training may include:
- AWS IAM
- CloudTrail
- Security Groups
- KMS
- Secrets Manager
- S3 security
- EC2 security
- Cloud logging
- GuardDuty/security monitoring where used
17. Database Administrators
Required
☐ Database security
☐ Privileged access
☐ Authentication
☐ Authorization
☐ Encryption
☐ Backup
☐ Recovery
☐ Database logging
☐ Data classification
☐ Sensitive-data handling
☐ Vulnerability management
☐ Secure administration
☐ Incident response
18. Security Personnel
Security personnel require enhanced or specialized training.
Required
☐ Security monitoring
☐ Incident response
☐ Security event analysis
☐ Incident investigation
☐ Evidence handling
☐ Vulnerability management
☐ Security testing
☐ Risk management
☐ Security architecture
☐ Threat awareness
☐ Security logging
☐ Business continuity
☐ Security reporting
Specialized Where Applicable
☐ Digital forensics
☐ Threat hunting
☐ Penetration testing
☐ Malware analysis
☐ Cloud security
☐ Security engineering
19. Senior Management
Senior management should understand security from a governance and risk perspective.
Required
☐ Information-security responsibilities
☐ Business risk
☐ Cybersecurity risk
☐ Major security incidents
☐ Security governance
☐ Risk acceptance
☐ Business continuity
☐ Regulatory obligations
☐ Customer security requirements
☐ Security metrics
☐ Security investment
☐ Crisis escalation
20. Internal Audit
Internal auditors should understand:
☐ ISMS principles
☐ Risk management
☐ Control objectives
☐ Evidence evaluation
☐ Audit methodology
☐ Security governance
☐ Access controls
☐ Security operations
☐ Cloud security where relevant
☐ Supplier security
☐ Incident management
☐ Business continuity
☐ Privacy
☐ Applicable regulatory requirements
Auditor competence should be appropriate to the scope and criteria of the audit.
21. Product Team
Product personnel may influence security requirements and customer commitments.
Required
☐ Security-by-design
☐ Privacy-by-design
☐ Customer security requirements
☐ Data classification
☐ Secure product requirements
☐ Security testing
☐ Vulnerability management
☐ Third-party components
☐ AI security
☐ Security incident escalation
☐ Regulatory/customer requirements
22. Security Training by Access Level
Training should also be determined by access, not only job title.
| Access Type | Minimum Additional Training |
|---|---|
| Standard User | General Awareness |
| Sensitive Information | Data Protection + Classification |
| Customer Data | Privacy + Customer Data Protection |
| Personal Data | Privacy + Data Protection |
| Source Code | Secure Development |
| Cloud Access | Cloud Security |
| Production Access | Production Security |
| Privileged Access | Privileged Access Security |
| Security Administration | Security Operations |
| Database Access | Database Security |
| Incident Response | Incident Response |
| Security Testing | Security Testing |
| AI System Administration | AI Security |
23. Training Frequency
| Training Type | Suggested Frequency |
|---|---|
| General Security Awareness | Onboarding + Annual |
| Phishing Awareness | Annual + Periodic Campaigns |
| Privacy | Onboarding + Annual/Role-Based |
| Incident Reporting | Onboarding + Annual |
| Privileged Access | Onboarding + Periodic Refresh |
| Cloud Security | Role-Based + Periodic Refresh |
| Secure Development | Role-Based + Periodic Refresh |
| Security Operations | Role-Based + Continuous |
| AI Security | Onboarding + Annual + Change-Based |
| BCP/DR | Role-Based + Exercise |
| Policy Changes | When Material Change Occurs |
| Incident-Driven Training | As Required |
| Audit-Finding Training | As Required |
The actual frequency should be based on risk and organizational requirements.
24. New Employee Training
Before or shortly after access is granted, according to the organization’s onboarding process:
☐ General security awareness
☐ Password/MFA
☐ Phishing
☐ Incident reporting
☐ Information classification
☐ Acceptable use
☐ Privacy
☐ Remote working
☐ AI security where applicable
☐ Role-specific training
25. Role Change Training
When an employee changes roles:
☐ New role assessed
☐ New information access identified
☐ New system access identified
☐ New security risks assessed
☐ Training matrix reviewed
☐ Additional training identified
☐ Training assigned
☐ Training completed
☐ Evidence recorded
26. Privileged User Training
Employees receiving privileged access should receive enhanced training.
☐ Privileged account responsibilities
☐ Least privilege
☐ MFA
☐ Administrative credentials
☐ Secure administration
☐ Production security
☐ Logging
☐ Monitoring
☐ Emergency access
☐ Incident response
☐ Change management
☐ Access review
27. Training Assessment
Training should be assessed where appropriate.
Methods include:
- Quiz
- Knowledge test
- Practical exercise
- Phishing simulation
- Tabletop exercise
- Interview
- Observation
- Technical assessment
| Employee | Role | Training | Score | Result | Retest |
|---|---|---|---|---|---|
28. Training Completion Register
| Employee | Role | Training Level | Required Modules | Completed | Outstanding | Status |
|---|---|---|---|---|---|---|
Status
☐ Compliant
☐ Partially Compliant
☐ Training Outstanding
☐ Additional Training Required
☐ Exception Approved
29. Training Effectiveness
Training effectiveness should not be measured only by completion.
Consider:
☐ Assessment results
☐ Phishing results
☐ Incident trends
☐ Repeat security mistakes
☐ Audit findings
☐ Policy violations
☐ Security behavior
☐ Employee feedback
☐ Practical exercises
Effectiveness Result
30. Training Trigger Events
Additional training may be required following:
☐ New employee
☐ Role change
☐ New privileged access
☐ New production access
☐ New technology
☐ New cloud platform
☐ New application
☐ Security incident
☐ Data breach
☐ Major vulnerability
☐ Audit finding
☐ Policy change
☐ Regulatory change
☐ Customer requirement
☐ Significant business change
Process
Trigger → Assess Training Need → Assign → Complete → Assess → Record
31. Training Exceptions
Where required training cannot be completed:
Employee/Role: _______________________
Training: _____________________________
Reason: ______________________________
Risk: _________________________________
Compensating Control: _________________
Approver: _____________________________
Due Date: _____________________________
Review Date: __________________________
32. Training Evidence
Maintain appropriate evidence such as:
☐ Training assignment
☐ Training completion
☐ Attendance
☐ Assessment results
☐ Practical exercises
☐ Phishing results
☐ Role-based training records
☐ Policy acknowledgement
☐ Training exceptions
☐ Remedial training
☐ Management reports
☐ Effectiveness reviews
Do not retain unnecessary passwords, credentials, private keys, or other secrets as training evidence.
33. Matrix Review
Review the matrix periodically and when significant changes occur.
Review Triggers
☐ New role created
☐ Role responsibilities changed
☐ New technology
☐ New cloud platform
☐ New security risk
☐ Security incident
☐ Audit finding
☐ Regulatory change
☐ Customer requirement
☐ Organizational restructuring
☐ New AI technology
Review Result
☐ No Change Required
☐ Training Updated
☐ New Module Required
☐ Role Requirements Updated
34. AWS SaaS Startup Example
Consider a SaaS startup with:
- 30 employees
- AWS production infrastructure
- GitHub source code
- Customer data
- Remote workforce
- 8 developers
- 2 cloud administrators
- 2 privileged administrators
Training Matrix
| Role | Core | Privacy | Cloud | Privileged | Secure Dev | Incident | AI |
|---|---|---|---|---|---|---|---|
| All Employees | ✓ | ✓ | Awareness | — | — | ✓ | ✓ |
| Developer | ✓ | ✓ | Role-Based | If applicable | ✓ | ✓ | ✓ |
| Cloud Admin | ✓ | ✓ | ✓ | ✓ | Role-Based | ✓ | ✓ |
| Security | ✓ | ✓ | ✓ | ✓ | Role-Based | ✓ | ✓ |
| Management | ✓ | ✓ | Awareness | Awareness | — | ✓ | ✓ |
Example
A developer who only has development AWS access does not automatically require the same cloud/privileged training as an AWS production administrator.
The training requirement follows:
Role + Information + Access + Risk
rather than job title alone.
35. Startup-Friendly Model
A startup can maintain the matrix without creating excessive administrative overhead.
Step 1 — Define Roles
Create a list of actual organizational roles.
Step 2 — Identify Risk
For each role identify:
- Information
- Systems
- Privileged access
- Production access
- Customer data
- Personal data
- Security responsibility
Step 3 — Map Training
Assign:
- General awareness
- Role-based modules
- Enhanced modules
- Specialized modules
Step 4 — Track Completion
Maintain one training register.
Step 5 — Review
Review the matrix at least annually and whenever significant changes occur.
36. Common Mistakes
Avoid:
- Giving every employee identical training.
- Using job title alone to determine training.
- Ignoring actual system access.
- Ignoring privileged users.
- Ignoring production access.
- Ignoring developers.
- Ignoring cloud administrators.
- Ignoring customer-data access.
- Not training new joiners.
- Not updating requirements after role changes.
- Measuring only completion.
- Not tracking failed assessments.
- Not tracking overdue training.
- Not using incidents to update training.
- Not reviewing the matrix when technology changes.
- Creating too many training requirements without considering risk.
37. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness expectations |
| Security Awareness and Training Procedure | Defines training process |
| Annual Security Awareness Plan | Defines yearly awareness activities |
| Employee Security Training Checklist | Verifies individual training |
| New Employee Security Onboarding Checklist | Defines initial onboarding requirements |
| Employee Role Change Checklist | Triggers training reassessment |
| Role-Based Security Responsibilities Matrix | Defines role responsibilities |
| Privileged User Management Procedure | Supports privileged-user training |
| Access Management Procedure | Identifies access-related training needs |
| Incident Response Procedure | Provides incident-related training requirements |
| Corrective Action Tracker | Tracks training-related corrective actions |
| Internal Audit Checklist | Verifies training implementation |
38. ISO 27001 Connection
Role-based security training supports the organization’s ability to ensure that personnel performing work under its control have appropriate awareness and competence for their responsibilities.
Training requirements should be based on:
- Job responsibilities
- Information handled
- System access
- Privileged access
- Production access
- Security risks
- Required competencies
- Applicable policies
- Security incidents
- Audit findings
- Legal and regulatory requirements
- Customer requirements
- Technology changes
The Role-Based Security Training Matrix is not itself a universally prescribed ISO 27001 form. The organization should determine the appropriate roles, training topics, frequency, assessment methods, and evidence based on its ISMS, risk assessment, applicable controls, and business requirements.
39. Management Summary
Management should be able to see whether security training is appropriately aligned with organizational risk.
| Metric | Result | Target | Status |
|---|---|---|---|
| General Training Completion | |||
| Role-Based Training Completion | |||
| Privileged User Training | |||
| Developer Training | |||
| Cloud Training | |||
| Incident Response Training | |||
| Privacy Training | |||
| AI Security Training | |||
| Overdue Training | |||
| Failed Assessments |
Key Findings
Improvement Actions
40. Approval
Matrix Owner: _________________________
Security Owner: _______________________
HR Owner: _____________________________
Management Approver: _________________
Approval Date: ________________________
Next Review Date: _____________________
41. Final Audit Checklist
☐ Organizational roles identified
☐ Role responsibilities documented
☐ Information access assessed
☐ System access assessed
☐ Privileged access assessed
☐ Production access assessed
☐ Security risks considered
☐ General training defined
☐ Role-based training defined
☐ Enhanced training defined
☐ Specialized training defined
☐ Training frequency defined
☐ New-joiner requirements defined
☐ Role-change requirements defined
☐ Privileged-user requirements defined
☐ Training assessment defined
☐ Training evidence defined
☐ Effectiveness measurement defined
☐ Exceptions process defined
☐ Matrix review triggers defined
☐ Management reporting defined
☐ Matrix approved
☐ Matrix periodically reviewed
42. Final Audit Trail
For every important organizational role, the organization should be able to demonstrate:
What is the role?
What information does the role handle?
What systems does the role access?
Does the role have privileged or production access?
What security risks does the role create?
What training is therefore required?
Was the training completed?
Was understanding assessed?
Was additional training required?
What happens when the role changes?
How is training effectiveness monitored?
When is the matrix reviewed?
Final Principle
Security training should follow risk, not job title. The right training requirement is determined by the combination of a person’s role, information handled, system access, security responsibilities, and risk exposure.
Training lifecycle:
Role → Information → Access → Risk → Training → Assessment → Evidence → Monitor → Reassess
