1. Purpose
The Security Awareness Training Register provides a centralized record of information-security awareness and training activities performed by the organization.
The register helps demonstrate:
- Who received security training
- What training was provided
- Why the training was required
- When training was assigned and completed
- Whether the training was appropriate to the person’s role
- Whether the employee passed the assessment
- Whether additional training was required
- Whether training was completed on time
- What evidence supports completion
- Whether training was effective
Core Principle
Identify → Assign → Train → Assess → Record → Monitor → Reinforce → Improve
2. Scope
The register may include training for:
- Employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Management
- Developers
- IT personnel
- Cloud administrators
- Security personnel
- Privileged users
- Personnel handling customer data
- Personnel handling personal data
- Other relevant third parties
The level of detail should be proportionate to the organization’s risk and training requirements.
3. Register Ownership
| Field | Details |
|---|---|
| Register Name | Security Awareness Training Register |
| Register Owner | |
| Security Owner | |
| HR Owner | |
| Effective Date | |
| Review Frequency | |
| Retention Period | |
| Approved By | |
| Version |
4. Master Training Register
The following should be the primary tracking table.
| Training ID | Employee | Role | Department | Training | Type | Assigned Date | Due Date | Completion Date | Score | Status | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|---|
Suggested Status Values
- Not Assigned
- Assigned
- In Progress
- Completed
- Passed
- Failed
- Retest Required
- Overdue
- Exempted
- Cancelled
5. Training Activity Register
Track the overall training activity.
| Activity ID | Training Topic | Audience | Training Type | Date | Trainer/Provider | Participants | Result | Evidence |
|---|---|---|---|---|---|---|---|---|
Training Types
☐ New Joiner
☐ Annual Awareness
☐ Role-Based
☐ Refresher
☐ Security Campaign
☐ Phishing Simulation
☐ Incident-Driven
☐ Audit-Finding-Driven
☐ Policy Change
☐ Technology Change
☐ Regulatory/Customer Requirement
☐ Specialized Training
6. Employee Training Record
For individual employee tracking:
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Job Title | |
| Department | |
| Manager | |
| Training Level | |
| Role Risk | |
| Training Required | |
| Training Completed | |
| Assessment Score | |
| Overall Status | |
| Next Review/Training Date |
7. Training Module Register
Maintain a list of approved training modules.
| Module ID | Training Module | Audience | Level | Frequency | Owner | Version | Status |
|---|---|---|---|---|---|---|---|
| SEC-01 | Information Security Fundamentals | All | General | Annual | |||
| SEC-02 | Security Responsibilities | All | General | Annual | |||
| SEC-03 | Passwords and MFA | All | General | Annual | |||
| SEC-04 | Phishing and Social Engineering | All | General | Annual | |||
| SEC-05 | Malware and Ransomware | All | General | Annual | |||
| SEC-06 | Information Classification | All | General | Annual | |||
| SEC-07 | Data Protection and Privacy | Relevant | Role-Based | Annual | |||
| SEC-08 | Incident Reporting | All | General | Annual | |||
| SEC-09 | Acceptable Use | All | General | Annual | |||
| SEC-10 | Remote Working Security | Relevant | General | Annual | |||
| SEC-11 | Endpoint Security | All | General | Annual | |||
| SEC-12 | Physical Security | All | General | Annual | |||
| SEC-13 | AI Security | Relevant | Role-Based | Annual | |||
| SEC-14 | Cloud Security | IT/Cloud | Enhanced | Role-Based | |||
| SEC-15 | Privileged Access Security | Privileged Users | Enhanced | Role-Based | |||
| SEC-16 | Secure Development | Developers | Specialized | Role-Based | |||
| SEC-17 | Vulnerability Management | Technical | Enhanced | Role-Based | |||
| SEC-18 | Security Logging and Monitoring | Technical | Enhanced | Role-Based | |||
| SEC-19 | Incident Response | Security/IT | Specialized | Role-Based | |||
| SEC-20 | Business Continuity and DR | Relevant | Role-Based | Periodic |
8. New Employee Training
For every new employee:
| Employee | Join Date | Training Assigned | Due Date | Completed | Assessment | Status |
|---|---|---|---|---|---|---|
Verify:
☐ Security awareness assigned
☐ Security policies communicated
☐ MFA training completed
☐ Phishing training completed
☐ Incident reporting explained
☐ Information classification explained
☐ Acceptable use explained
☐ Privacy requirements explained where applicable
☐ Role-specific training completed
9. Annual Security Awareness Training
Track annual refresher training.
| Employee | Role | Annual Training | Assigned | Completed | Score | Status |
|---|---|---|---|---|---|---|
Annual Completion Target
Target: __________________ %
Actual: __________________ %
Variance: _______________ %
10. Role-Based Training
Training should be linked to the Role-Based Security Training Matrix.
| Employee | Role | Required Module | Assigned | Completed | Assessment | Status |
|---|---|---|---|---|---|---|
| Developer | Secure Development | |||||
| Cloud Admin | Cloud Security | |||||
| Privileged User | Privileged Access | |||||
| Security | Incident Response |
11. Privileged User Training
Track enhanced training for privileged personnel.
| Employee | Privileged Role | Training | Date | Assessment | Result | Next Review |
|---|---|---|---|---|---|---|
Verify:
☐ Privileged access training completed
☐ Least privilege understood
☐ MFA understood
☐ Administrative security understood
☐ Production security understood
☐ Logging understood
☐ Incident reporting understood
12. Developer Security Training
For software-development personnel:
| Employee | Secure Coding | Source Code | Secrets | Dependency Security | Security Testing | Status |
|---|---|---|---|---|---|---|
Potential modules:
☐ Secure coding
☐ OWASP/security risks
☐ Authentication
☐ Authorization
☐ API security
☐ Secrets management
☐ Dependency management
☐ Vulnerability remediation
☐ Security testing
☐ Code review
☐ Software supply-chain security
☐ AI-assisted development security
13. Cloud Security Training
For cloud personnel:
| Employee | Role | Cloud Training | IAM | Privileged Access | Logging | Assessment | Status |
|---|---|---|---|---|---|---|---|
Potential topics:
- IAM
- MFA
- Least privilege
- Cloud configuration
- Network security
- Encryption
- Logging
- Monitoring
- Backup
- Secrets
- Cloud incident response
14. Security Awareness Campaign Register
Track short awareness campaigns.
| Campaign ID | Topic | Reason | Audience | Date | Communication | Result | Follow-Up |
|---|---|---|---|---|---|---|---|
Common Campaign Topics
- Phishing
- Ransomware
- Passwords
- MFA
- Data protection
- Privacy
- AI security
- Remote working
- USB security
- Social engineering
- Secure file sharing
- Shadow IT
15. Phishing Simulation Register
Where simulations are used:
| Simulation ID | Date | Audience | Users Tested | Clicked | Reported | Click Rate | Report Rate | Follow-Up |
|---|---|---|---|---|---|---|---|---|
Metrics
Click Rate
Users who clicked ÷ Users tested × 100
Reporting Rate
Users who reported ÷ Users tested × 100
The organization should use simulations responsibly and protect employee information.
16. Training Assessment Register
| Assessment ID | Employee | Training | Date | Score | Passing Score | Result | Retest |
|---|---|---|---|---|---|---|---|
Result
☐ Passed
☐ Failed
☐ Retest Required
☐ Additional Training Required
17. Practical Exercise Register
Track practical security exercises.
Examples:
- Phishing identification
- Incident reporting
- Information classification
- Lost-device scenario
- Social-engineering scenario
- AI-security scenario
- Ransomware response
- Tabletop exercise
| Exercise ID | Employee/Team | Scenario | Date | Result | Gap | Action |
|---|---|---|---|---|---|---|
18. Overdue Training Register
Track incomplete training.
| Employee | Training | Due Date | Days Overdue | Manager | Escalation | Resolution |
|---|---|---|---|---|---|---|
Process
Identify → Remind → Escalate → Complete → Verify → Close
19. Failed Training Register
Where an employee does not meet the required assessment threshold:
| Employee | Training | Date | Score | Required Score | Action | Retest | Final Result |
|---|---|---|---|---|---|---|---|
Possible actions:
- Additional training
- Coaching
- Retest
- Manager follow-up
- Security review
- Access-risk assessment for sensitive roles
20. Training Exception Register
| Exception ID | Employee | Training | Reason | Risk | Compensating Control | Approver | Expiry | Status |
|---|---|---|---|---|---|---|---|---|
Exceptions should be time-bound and reviewed.
21. Incident-Driven Training Register
Additional training may result from a security incident.
| Incident ID | Employee/Team | Training Need | Training Assigned | Completed | Effectiveness | Action |
|---|---|---|---|---|---|---|
Example
A phishing incident identifies repeated credential-entry behavior.
Action:
Incident → Root Cause → Training Need → Phishing Refresher → Simulation → Effectiveness Review
22. Audit-Finding-Driven Training
| Finding ID | Area | Training Requirement | Audience | Completed | Evidence | Status |
|---|---|---|---|---|---|---|
Training should be used only where training is an appropriate corrective action. Process, technology, or governance weaknesses may require other controls.
23. Policy Change Training
When a security policy changes:
☐ Change identified
☐ Training requirement assessed
☐ Target audience identified
☐ Training material updated
☐ Training assigned
☐ Training completed
☐ Acknowledgement recorded where required
Register
| Policy | Change Date | Training Required | Audience | Completed | Status |
|---|---|---|---|---|---|
24. Technology Change Training
Training may be required when introducing:
- New cloud platform
- New SaaS
- New security tool
- New authentication technology
- New AI tool
- New development platform
- New production environment
- New security process
| Technology | Change | Affected Roles | Training | Date | Status |
|---|---|---|---|---|---|
25. Training Provider Register
If external providers are used:
| Provider | Training | Audience | Certification | Contract | Security Review | Status |
|---|---|---|---|---|---|---|
Where appropriate, evaluate third-party training providers based on:
☐ Competence
☐ Security
☐ Privacy
☐ Content quality
☐ Relevance
☐ Reliability
26. Training Material Register
Maintain the current version of training content.
| Material ID | Topic | Version | Owner | Approval Date | Review Date | Status |
|---|---|---|---|---|---|---|
Verify:
☐ Content approved
☐ Current version used
☐ Outdated material retired
☐ Relevant threats included
☐ Applicable policies reflected
☐ Role requirements reflected
27. Training Completion Dashboard
| Metric | Target | Actual | Status |
|---|---|---|---|
| General Awareness Completion | |||
| Annual Training Completion | |||
| Role-Based Training Completion | |||
| Privileged User Training | |||
| Developer Training | |||
| Cloud Training | |||
| Privacy Training | |||
| AI Security Training | |||
| Overdue Training | |||
| Failed Assessments |
28. Training Effectiveness Dashboard
Completion alone does not demonstrate effectiveness.
Track:
| Metric | Current | Previous | Trend | Action |
|---|---|---|---|---|
| Assessment Pass Rate | ||||
| Phishing Click Rate | ||||
| Phishing Reporting Rate | ||||
| Security Incidents Related to Awareness | ||||
| Repeat Security Mistakes | ||||
| Policy Violations | ||||
| Training-Related Audit Findings |
29. Annual Training Summary
At the end of the year, summarize:
Training Delivered
Employees Covered
Completion Rate
Assessment Results
Phishing Results
Significant Gaps
Incidents Influencing Training
Audit Findings Influencing Training
Improvement Actions
30. Management Reporting
Management reporting should focus on risk and effectiveness.
Suggested Reporting
- Training completion
- High-risk training outstanding
- Privileged-user training
- Security incidents
- Phishing results
- Repeat failures
- Major awareness gaps
- Training exceptions
- Corrective actions
- Improvement trends
Management Review
☐ Reviewed
☐ Actions identified
☐ Resources required
☐ Risk accepted where applicable
31. Training Record Protection
Training records may contain employee information and should be appropriately protected.
☐ Access restricted
☐ Appropriate permissions applied
☐ Unauthorized modification prevented
☐ Retention period defined
☐ Secure storage used
☐ Personal information minimized
☐ Records securely disposed of when no longer required
32. Data Quality Checks
Periodically verify:
☐ Employee list is current
☐ Departed employees removed/inactivated appropriately
☐ Role information is current
☐ Training assignments are correct
☐ Completion dates are accurate
☐ Assessment scores are accurate
☐ Evidence links work
☐ Overdue records are followed up
☐ Duplicate records are addressed
☐ Training modules are current
33. Register Review
Review the register periodically.
Review Triggers
☐ Annual review
☐ New employee
☐ Employee role change
☐ New training requirement
☐ New technology
☐ Security incident
☐ Audit finding
☐ Policy change
☐ Regulatory change
☐ Customer requirement
Review Result
☐ No Change
☐ Training Updated
☐ Records Corrected
☐ Additional Training Required
☐ Management Action Required
34. AWS SaaS Startup Example
Consider a SaaS startup with:
- 30 employees
- AWS infrastructure
- GitHub
- Customer data
- Remote workforce
- 8 developers
- 2 cloud administrators
- 2 privileged administrators
Register Example
| Employee/Role | Training | Status |
|---|---|---|
| All Employees | Security Awareness | Completed |
| All Employees | Phishing | Completed |
| Developers | Secure Development | Completed |
| Developers | Secrets Management | Completed |
| Cloud Admins | AWS Security | Completed |
| Cloud Admins | Privileged Access | Completed |
| Security Team | Incident Response | Completed |
| All Employees | AI Security | Completed |
Audit Evidence
The organization can demonstrate:
Training Requirement → Assignment → Completion → Assessment → Evidence → Effectiveness → Improvement
35. Startup-Friendly Model
A small organization does not need a complicated training-management system.
A spreadsheet or controlled register can initially track:
Minimum Fields
- Employee
- Role
- Training
- Training date
- Due date
- Completion
- Assessment result
- Evidence
- Status
- Next training date
As the organization grows, the register can be integrated with an HR or learning-management platform.
36. Common Mistakes
Avoid:
- Maintaining training records in disconnected spreadsheets.
- Failing to track new joiners.
- Failing to track role changes.
- Recording completion without evidence.
- Recording attendance without assessing understanding.
- Ignoring failed assessments.
- Ignoring overdue training.
- Not tracking privileged-user training.
- Not tracking role-specific training.
- Not using incidents to identify training needs.
- Not updating training after policy or technology changes.
- Retaining excessive personal information.
- Not reviewing the register periodically.
- Treating training completion as the only effectiveness metric.
37. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness requirements |
| Security Awareness and Training Procedure | Defines how training is performed |
| Annual Security Awareness Plan | Defines annual training activities |
| Role-Based Security Training Matrix | Defines training requirements by role |
| Employee Security Training Checklist | Verifies individual training |
| New Employee Security Onboarding Checklist | Defines initial security training |
| Employee Role Change Checklist | Triggers training reassessment |
| Incident Response Procedure | Supports incident-driven training |
| Corrective Action Tracker | Tracks training corrective actions |
| Policy Compliance Review Checklist | Verifies policy awareness |
| Security Compliance Monitoring Procedure | Monitors training compliance |
38. ISO 27001 Connection
The training register provides evidence that the organization’s security-awareness and competence activities are being implemented.
Training requirements should be determined based on:
- Roles and responsibilities
- Information-security risks
- Information handled
- System access
- Privileged access
- Required competencies
- Security policies
- Security incidents
- Audit findings
- Legal/regulatory requirements
- Customer requirements
- Technology changes
The Security Awareness Training Register is not itself a universally prescribed ISO 27001 form. It is an operational record that can provide useful evidence that the organization’s defined awareness and training processes are being implemented.
39. Final Audit Checklist
☐ Register owner assigned
☐ Training requirements defined
☐ Employees recorded
☐ Roles recorded
☐ Training modules recorded
☐ New joiner training tracked
☐ Annual training tracked
☐ Role-based training tracked
☐ Privileged-user training tracked
☐ Developer training tracked
☐ Cloud training tracked
☐ Privacy training tracked
☐ AI security training tracked where applicable
☐ Assessment results recorded
☐ Failed training tracked
☐ Overdue training tracked
☐ Exceptions recorded
☐ Incident-driven training tracked
☐ Audit-finding-driven training tracked
☐ Training evidence retained
☐ Effectiveness monitored
☐ Management reporting completed
☐ Register periodically reviewed
40. Final Audit Trail
For each significant training requirement, the organization should be able to demonstrate:
Why was this training required?
Who needed it?
What training was assigned?
When was it due?
Was it completed?
Did the employee pass the assessment?
Was additional training required?
Was overdue training followed up?
What evidence supports completion?
Was the training effective?
Did an incident or audit finding result in additional training?
Was the training updated when risks or responsibilities changed?
Final Principle
The Security Awareness Training Register is the evidence trail connecting the organization’s security-training requirements to actual employee participation, assessment, follow-up, and continual improvement.
Training evidence lifecycle:
Requirement → Assign → Train → Assess → Record → Verify → Monitor → Improve
