ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Security Awareness Training Register

Security Awareness Training Register

1. Purpose

The Security Awareness Training Register provides a centralized record of information-security awareness and training activities performed by the organization.

The register helps demonstrate:

  • Who received security training
  • What training was provided
  • Why the training was required
  • When training was assigned and completed
  • Whether the training was appropriate to the person’s role
  • Whether the employee passed the assessment
  • Whether additional training was required
  • Whether training was completed on time
  • What evidence supports completion
  • Whether training was effective

Core Principle

Identify → Assign → Train → Assess → Record → Monitor → Reinforce → Improve


2. Scope

The register may include training for:

  • Employees
  • Contractors
  • Interns
  • Temporary personnel
  • Consultants
  • Management
  • Developers
  • IT personnel
  • Cloud administrators
  • Security personnel
  • Privileged users
  • Personnel handling customer data
  • Personnel handling personal data
  • Other relevant third parties

The level of detail should be proportionate to the organization’s risk and training requirements.


3. Register Ownership

FieldDetails
Register NameSecurity Awareness Training Register
Register Owner
Security Owner
HR Owner
Effective Date
Review Frequency
Retention Period
Approved By
Version

4. Master Training Register

The following should be the primary tracking table.

Training IDEmployeeRoleDepartmentTrainingTypeAssigned DateDue DateCompletion DateScoreStatusEvidence

Suggested Status Values

  • Not Assigned
  • Assigned
  • In Progress
  • Completed
  • Passed
  • Failed
  • Retest Required
  • Overdue
  • Exempted
  • Cancelled

5. Training Activity Register

Track the overall training activity.

Activity IDTraining TopicAudienceTraining TypeDateTrainer/ProviderParticipantsResultEvidence

Training Types

☐ New Joiner

☐ Annual Awareness

☐ Role-Based

☐ Refresher

☐ Security Campaign

☐ Phishing Simulation

☐ Incident-Driven

☐ Audit-Finding-Driven

☐ Policy Change

☐ Technology Change

☐ Regulatory/Customer Requirement

☐ Specialized Training


6. Employee Training Record

For individual employee tracking:

FieldDetails
Employee Name
Employee ID
Job Title
Department
Manager
Training Level
Role Risk
Training Required
Training Completed
Assessment Score
Overall Status
Next Review/Training Date

7. Training Module Register

Maintain a list of approved training modules.

Module IDTraining ModuleAudienceLevelFrequencyOwnerVersionStatus
SEC-01Information Security FundamentalsAllGeneralAnnual
SEC-02Security ResponsibilitiesAllGeneralAnnual
SEC-03Passwords and MFAAllGeneralAnnual
SEC-04Phishing and Social EngineeringAllGeneralAnnual
SEC-05Malware and RansomwareAllGeneralAnnual
SEC-06Information ClassificationAllGeneralAnnual
SEC-07Data Protection and PrivacyRelevantRole-BasedAnnual
SEC-08Incident ReportingAllGeneralAnnual
SEC-09Acceptable UseAllGeneralAnnual
SEC-10Remote Working SecurityRelevantGeneralAnnual
SEC-11Endpoint SecurityAllGeneralAnnual
SEC-12Physical SecurityAllGeneralAnnual
SEC-13AI SecurityRelevantRole-BasedAnnual
SEC-14Cloud SecurityIT/CloudEnhancedRole-Based
SEC-15Privileged Access SecurityPrivileged UsersEnhancedRole-Based
SEC-16Secure DevelopmentDevelopersSpecializedRole-Based
SEC-17Vulnerability ManagementTechnicalEnhancedRole-Based
SEC-18Security Logging and MonitoringTechnicalEnhancedRole-Based
SEC-19Incident ResponseSecurity/ITSpecializedRole-Based
SEC-20Business Continuity and DRRelevantRole-BasedPeriodic

8. New Employee Training

For every new employee:

EmployeeJoin DateTraining AssignedDue DateCompletedAssessmentStatus

Verify:

☐ Security awareness assigned

☐ Security policies communicated

☐ MFA training completed

☐ Phishing training completed

☐ Incident reporting explained

☐ Information classification explained

☐ Acceptable use explained

☐ Privacy requirements explained where applicable

☐ Role-specific training completed


9. Annual Security Awareness Training

Track annual refresher training.

EmployeeRoleAnnual TrainingAssignedCompletedScoreStatus

Annual Completion Target

Target: __________________ %

Actual: __________________ %

Variance: _______________ %


10. Role-Based Training

Training should be linked to the Role-Based Security Training Matrix.

EmployeeRoleRequired ModuleAssignedCompletedAssessmentStatus
DeveloperSecure Development
Cloud AdminCloud Security
Privileged UserPrivileged Access
SecurityIncident Response

11. Privileged User Training

Track enhanced training for privileged personnel.

EmployeePrivileged RoleTrainingDateAssessmentResultNext Review

Verify:

☐ Privileged access training completed

☐ Least privilege understood

☐ MFA understood

☐ Administrative security understood

☐ Production security understood

☐ Logging understood

☐ Incident reporting understood


12. Developer Security Training

For software-development personnel:

EmployeeSecure CodingSource CodeSecretsDependency SecuritySecurity TestingStatus

Potential modules:

☐ Secure coding

☐ OWASP/security risks

☐ Authentication

☐ Authorization

☐ API security

☐ Secrets management

☐ Dependency management

☐ Vulnerability remediation

☐ Security testing

☐ Code review

☐ Software supply-chain security

☐ AI-assisted development security


13. Cloud Security Training

For cloud personnel:

EmployeeRoleCloud TrainingIAMPrivileged AccessLoggingAssessmentStatus

Potential topics:

  • IAM
  • MFA
  • Least privilege
  • Cloud configuration
  • Network security
  • Encryption
  • Logging
  • Monitoring
  • Backup
  • Secrets
  • Cloud incident response

14. Security Awareness Campaign Register

Track short awareness campaigns.

Campaign IDTopicReasonAudienceDateCommunicationResultFollow-Up

Common Campaign Topics

  • Phishing
  • Ransomware
  • Passwords
  • MFA
  • Data protection
  • Privacy
  • AI security
  • Remote working
  • USB security
  • Social engineering
  • Secure file sharing
  • Shadow IT

15. Phishing Simulation Register

Where simulations are used:

Simulation IDDateAudienceUsers TestedClickedReportedClick RateReport RateFollow-Up

Metrics

Click Rate

Users who clicked ÷ Users tested × 100

Reporting Rate

Users who reported ÷ Users tested × 100

The organization should use simulations responsibly and protect employee information.


16. Training Assessment Register

Assessment IDEmployeeTrainingDateScorePassing ScoreResultRetest

Result

☐ Passed

☐ Failed

☐ Retest Required

☐ Additional Training Required


17. Practical Exercise Register

Track practical security exercises.

Examples:

  • Phishing identification
  • Incident reporting
  • Information classification
  • Lost-device scenario
  • Social-engineering scenario
  • AI-security scenario
  • Ransomware response
  • Tabletop exercise
Exercise IDEmployee/TeamScenarioDateResultGapAction

18. Overdue Training Register

Track incomplete training.

EmployeeTrainingDue DateDays OverdueManagerEscalationResolution

Process

Identify → Remind → Escalate → Complete → Verify → Close


19. Failed Training Register

Where an employee does not meet the required assessment threshold:

EmployeeTrainingDateScoreRequired ScoreActionRetestFinal Result

Possible actions:

  • Additional training
  • Coaching
  • Retest
  • Manager follow-up
  • Security review
  • Access-risk assessment for sensitive roles

20. Training Exception Register

Exception IDEmployeeTrainingReasonRiskCompensating ControlApproverExpiryStatus

Exceptions should be time-bound and reviewed.


21. Incident-Driven Training Register

Additional training may result from a security incident.

Incident IDEmployee/TeamTraining NeedTraining AssignedCompletedEffectivenessAction

Example

A phishing incident identifies repeated credential-entry behavior.

Action:

Incident → Root Cause → Training Need → Phishing Refresher → Simulation → Effectiveness Review


22. Audit-Finding-Driven Training

Finding IDAreaTraining RequirementAudienceCompletedEvidenceStatus

Training should be used only where training is an appropriate corrective action. Process, technology, or governance weaknesses may require other controls.


23. Policy Change Training

When a security policy changes:

☐ Change identified

☐ Training requirement assessed

☐ Target audience identified

☐ Training material updated

☐ Training assigned

☐ Training completed

☐ Acknowledgement recorded where required

Register

PolicyChange DateTraining RequiredAudienceCompletedStatus

24. Technology Change Training

Training may be required when introducing:

  • New cloud platform
  • New SaaS
  • New security tool
  • New authentication technology
  • New AI tool
  • New development platform
  • New production environment
  • New security process
TechnologyChangeAffected RolesTrainingDateStatus

25. Training Provider Register

If external providers are used:

ProviderTrainingAudienceCertificationContractSecurity ReviewStatus

Where appropriate, evaluate third-party training providers based on:

☐ Competence

☐ Security

☐ Privacy

☐ Content quality

☐ Relevance

☐ Reliability


26. Training Material Register

Maintain the current version of training content.

Material IDTopicVersionOwnerApproval DateReview DateStatus

Verify:

☐ Content approved

☐ Current version used

☐ Outdated material retired

☐ Relevant threats included

☐ Applicable policies reflected

☐ Role requirements reflected


27. Training Completion Dashboard

MetricTargetActualStatus
General Awareness Completion
Annual Training Completion
Role-Based Training Completion
Privileged User Training
Developer Training
Cloud Training
Privacy Training
AI Security Training
Overdue Training
Failed Assessments

28. Training Effectiveness Dashboard

Completion alone does not demonstrate effectiveness.

Track:

MetricCurrentPreviousTrendAction
Assessment Pass Rate
Phishing Click Rate
Phishing Reporting Rate
Security Incidents Related to Awareness
Repeat Security Mistakes
Policy Violations
Training-Related Audit Findings

29. Annual Training Summary

At the end of the year, summarize:

Training Delivered

Employees Covered

Completion Rate

Assessment Results

Phishing Results

Significant Gaps

Incidents Influencing Training

Audit Findings Influencing Training

Improvement Actions


30. Management Reporting

Management reporting should focus on risk and effectiveness.

Suggested Reporting

  • Training completion
  • High-risk training outstanding
  • Privileged-user training
  • Security incidents
  • Phishing results
  • Repeat failures
  • Major awareness gaps
  • Training exceptions
  • Corrective actions
  • Improvement trends

Management Review

☐ Reviewed

☐ Actions identified

☐ Resources required

☐ Risk accepted where applicable


31. Training Record Protection

Training records may contain employee information and should be appropriately protected.

☐ Access restricted

☐ Appropriate permissions applied

☐ Unauthorized modification prevented

☐ Retention period defined

☐ Secure storage used

☐ Personal information minimized

☐ Records securely disposed of when no longer required


32. Data Quality Checks

Periodically verify:

☐ Employee list is current

☐ Departed employees removed/inactivated appropriately

☐ Role information is current

☐ Training assignments are correct

☐ Completion dates are accurate

☐ Assessment scores are accurate

☐ Evidence links work

☐ Overdue records are followed up

☐ Duplicate records are addressed

☐ Training modules are current


33. Register Review

Review the register periodically.

Review Triggers

☐ Annual review

☐ New employee

☐ Employee role change

☐ New training requirement

☐ New technology

☐ Security incident

☐ Audit finding

☐ Policy change

☐ Regulatory change

☐ Customer requirement

Review Result

☐ No Change

☐ Training Updated

☐ Records Corrected

☐ Additional Training Required

☐ Management Action Required


34. AWS SaaS Startup Example

Consider a SaaS startup with:

  • 30 employees
  • AWS infrastructure
  • GitHub
  • Customer data
  • Remote workforce
  • 8 developers
  • 2 cloud administrators
  • 2 privileged administrators

Register Example

Employee/RoleTrainingStatus
All EmployeesSecurity AwarenessCompleted
All EmployeesPhishingCompleted
DevelopersSecure DevelopmentCompleted
DevelopersSecrets ManagementCompleted
Cloud AdminsAWS SecurityCompleted
Cloud AdminsPrivileged AccessCompleted
Security TeamIncident ResponseCompleted
All EmployeesAI SecurityCompleted

Audit Evidence

The organization can demonstrate:

Training Requirement → Assignment → Completion → Assessment → Evidence → Effectiveness → Improvement


35. Startup-Friendly Model

A small organization does not need a complicated training-management system.

A spreadsheet or controlled register can initially track:

Minimum Fields

  • Employee
  • Role
  • Training
  • Training date
  • Due date
  • Completion
  • Assessment result
  • Evidence
  • Status
  • Next training date

As the organization grows, the register can be integrated with an HR or learning-management platform.


36. Common Mistakes

Avoid:

  • Maintaining training records in disconnected spreadsheets.
  • Failing to track new joiners.
  • Failing to track role changes.
  • Recording completion without evidence.
  • Recording attendance without assessing understanding.
  • Ignoring failed assessments.
  • Ignoring overdue training.
  • Not tracking privileged-user training.
  • Not tracking role-specific training.
  • Not using incidents to identify training needs.
  • Not updating training after policy or technology changes.
  • Retaining excessive personal information.
  • Not reviewing the register periodically.
  • Treating training completion as the only effectiveness metric.

37. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness requirements
Security Awareness and Training ProcedureDefines how training is performed
Annual Security Awareness PlanDefines annual training activities
Role-Based Security Training MatrixDefines training requirements by role
Employee Security Training ChecklistVerifies individual training
New Employee Security Onboarding ChecklistDefines initial security training
Employee Role Change ChecklistTriggers training reassessment
Incident Response ProcedureSupports incident-driven training
Corrective Action TrackerTracks training corrective actions
Policy Compliance Review ChecklistVerifies policy awareness
Security Compliance Monitoring ProcedureMonitors training compliance

38. ISO 27001 Connection

The training register provides evidence that the organization’s security-awareness and competence activities are being implemented.

Training requirements should be determined based on:

  • Roles and responsibilities
  • Information-security risks
  • Information handled
  • System access
  • Privileged access
  • Required competencies
  • Security policies
  • Security incidents
  • Audit findings
  • Legal/regulatory requirements
  • Customer requirements
  • Technology changes

The Security Awareness Training Register is not itself a universally prescribed ISO 27001 form. It is an operational record that can provide useful evidence that the organization’s defined awareness and training processes are being implemented.


39. Final Audit Checklist

☐ Register owner assigned

☐ Training requirements defined

☐ Employees recorded

☐ Roles recorded

☐ Training modules recorded

☐ New joiner training tracked

☐ Annual training tracked

☐ Role-based training tracked

☐ Privileged-user training tracked

☐ Developer training tracked

☐ Cloud training tracked

☐ Privacy training tracked

☐ AI security training tracked where applicable

☐ Assessment results recorded

☐ Failed training tracked

☐ Overdue training tracked

☐ Exceptions recorded

☐ Incident-driven training tracked

☐ Audit-finding-driven training tracked

☐ Training evidence retained

☐ Effectiveness monitored

☐ Management reporting completed

☐ Register periodically reviewed


40. Final Audit Trail

For each significant training requirement, the organization should be able to demonstrate:

Why was this training required?
Who needed it?
What training was assigned?
When was it due?
Was it completed?
Did the employee pass the assessment?
Was additional training required?
Was overdue training followed up?
What evidence supports completion?
Was the training effective?
Did an incident or audit finding result in additional training?
Was the training updated when risks or responsibilities changed?

Final Principle

The Security Awareness Training Register is the evidence trail connecting the organization’s security-training requirements to actual employee participation, assessment, follow-up, and continual improvement.

Training evidence lifecycle:

Requirement → Assign → Train → Assess → Record → Verify → Monitor → Improve