ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Security Awareness Audit Checklist

Security Awareness Audit Checklist

Assessing Whether Employees Understand and Apply Information Security

A Security Awareness Audit Checklist provides a structured method for reviewing whether an organization’s security-awareness program is properly established, implemented, communicated, measured, and improved.

The audit should not only verify whether employees completed training. It should determine whether personnel understand their security responsibilities and whether awareness activities are producing the expected security behavior.

The assessment should consider training records, quizzes, phishing simulations, incident reporting, policy awareness, role-based training, audit findings, and other evidence.

Define → Communicate → Train → Test → Observe → Verify → Identify Gaps → Improve


1. Purpose

The purpose of this checklist is to assess whether the organization’s security-awareness program:

  • Is formally established
  • Has defined ownership
  • Covers relevant personnel
  • Addresses applicable security risks
  • Provides appropriate training
  • Communicates security responsibilities
  • Measures knowledge
  • Measures behavioral effectiveness
  • Maintains appropriate evidence
  • Addresses identified weaknesses
  • Is periodically reviewed and improved

2. Scope

The audit may cover:

☐ Employees

☐ Contractors

☐ Interns

☐ Temporary personnel

☐ Remote workers

☐ Privileged users

☐ Developers

☐ IT personnel

☐ Cloud administrators

☐ Security personnel

☐ Personnel handling customer information

☐ Personnel handling personal data

☐ Other relevant third parties


3. Audit Information

FieldDetails
Audit ID
Organization
Audit Date
Audit Period
Auditor
Security Awareness Owner
HR Owner
Scope
Business Units
Locations
Number of Personnel
Training Platform
Previous Assessment
Overall Result

4. Audit Methodology

The assessment should use appropriate methods such as:

☐ Document review

☐ Training-record review

☐ Employee sampling

☐ Interviews

☐ Knowledge testing

☐ Security awareness quiz review

☐ Phishing simulation review

☐ Practical assessment

☐ Incident review

☐ Audit finding review

☐ Policy compliance testing

☐ Management interview

☐ Observation

The audit method should be proportionate to the organization’s size, risk, and ISMS scope.


5. Security Awareness Governance

Verify:

☐ Security awareness responsibilities are defined

☐ Security awareness has an accountable owner

☐ Management supports the awareness program

☐ Security awareness requirements are documented

☐ Relevant policies are approved

☐ Awareness objectives are defined

☐ Training requirements are established

☐ Role-based training requirements are identified

☐ Awareness activities are planned

☐ Awareness performance is monitored

☐ Security awareness is reviewed periodically

Evidence


6. Security Awareness Policy

Verify:

☐ Information Security Awareness Policy exists

☐ Policy is approved

☐ Policy owner is identified

☐ Policy scope is defined

☐ Security responsibilities are communicated

☐ Awareness requirements are documented

☐ Training expectations are defined

☐ Incident-reporting responsibilities are addressed

☐ Policy acknowledgement requirements are defined where appropriate

☐ Policy is reviewed periodically

☐ Policy reflects current business and security risks

Evidence


7. Training Needs Assessment

Verify that the organization identifies training needs based on:

☐ Job role

☐ Information handled

☐ System access

☐ Privileged access

☐ Security responsibilities

☐ Regulatory requirements

☐ Customer requirements

☐ Business risks

☐ Technology changes

☐ Security incidents

☐ Audit findings

☐ Changes in threat landscape

Key Question

Is security training based on risk and responsibility rather than simply job title?


8. Security Awareness Training Program

Verify:

☐ Security awareness training program exists

☐ Training objectives are defined

☐ Training topics are identified

☐ Training materials are approved

☐ Training frequency is defined

☐ New employees receive appropriate training

☐ Periodic refresher training is provided

☐ Role-based training is provided where required

☐ Training is updated when risks change

☐ Training completion is monitored

☐ Overdue training is followed up

☐ Training exceptions are documented


9. New Employee Security Awareness

Verify:

☐ Security awareness is included in onboarding

☐ New employees receive security training

☐ Security policies are communicated

☐ Incident-reporting procedures are explained

☐ Information classification is explained

☐ Password and MFA requirements are explained

☐ Acceptable-use requirements are explained

☐ Privacy requirements are explained where relevant

☐ Remote-working requirements are explained where relevant

☐ AI-security requirements are explained where relevant

☐ Training completion is recorded


10. Annual Security Awareness Training

Verify:

☐ Annual training requirement is defined

☐ Annual training plan exists

☐ Required employees are identified

☐ Training is assigned

☐ Completion is monitored

☐ Overdue training is escalated

☐ Assessment is performed

☐ Results are recorded

☐ Effectiveness is reviewed

☐ Training content is updated where necessary


11. Role-Based Security Training

Verify whether additional training is provided for higher-risk roles.

Developers

☐ Secure coding

☐ Source-code protection

☐ Secrets management

☐ Dependency security

☐ Vulnerability management

☐ Secure development lifecycle

☐ AI-assisted development security

Cloud/IT Administrators

☐ IAM

☐ Privileged access

☐ MFA

☐ Cloud configuration

☐ Logging and monitoring

☐ Incident response

Security Personnel

☐ Incident response

☐ Evidence handling

☐ Threat detection

☐ Vulnerability management

☐ Security monitoring

Finance

☐ Payment fraud

☐ Business email compromise

☐ Supplier verification

☐ Financial-data protection

HR

☐ Employee information protection

☐ Confidentiality

☐ Privacy

☐ Personnel security

☐ Joiner-mover-leaver responsibilities


12. Security Awareness Topics

Determine whether appropriate awareness is provided for:

☐ Password security

☐ MFA

☐ Phishing

☐ Social engineering

☐ Malware

☐ Ransomware

☐ Business email compromise

☐ Information classification

☐ Customer data protection

☐ Personal data protection

☐ Incident reporting

☐ Remote working

☐ Endpoint security

☐ Physical security

☐ Acceptable use

☐ Cloud security

☐ Secure development

☐ Vulnerability awareness

☐ Third-party security

☐ Business continuity

☐ AI security

☐ Security policy requirements

The topics should be based on organizational risk rather than treated as a mandatory universal list.


13. Phishing Awareness

Verify:

☐ Phishing awareness training is provided

☐ Employees understand common phishing indicators

☐ Employees understand suspicious-link risks

☐ Employees understand attachment risks

☐ Employees understand credential-phishing risks

☐ Employees understand MFA-fatigue attacks

☐ Employees understand business email compromise

☐ Employees know how to report phishing

☐ Phishing simulations are conducted where appropriate

☐ Simulation results are analyzed

☐ Repeat failures receive additional awareness


14. Security Awareness Quiz

Verify:

☐ Security awareness quiz exists

☐ Questions reflect current threats

☐ Questions cover relevant policies

☐ Role-specific questions are used where appropriate

☐ Passing criteria are defined

☐ Results are recorded

☐ Failed assessments are identified

☐ Additional training is provided where appropriate

☐ Retesting is performed where required

☐ Quiz effectiveness is reviewed


15. Training Effectiveness

Verify that the organization evaluates whether training actually works.

Consider:

☐ Quiz results

☐ Phishing simulation results

☐ Incident-reporting behavior

☐ Security incidents

☐ Policy violations

☐ Audit findings

☐ Repeat security mistakes

☐ Employee feedback

☐ Practical assessments

☐ Training completion

☐ Trend analysis

Key Question

Does the organization measure behavior and outcomes, rather than only training attendance?


16. Incident Reporting Awareness

Verify that personnel understand:

☐ What constitutes a security incident

☐ What constitutes a security event

☐ When to report

☐ How to report

☐ Who to contact

☐ What information to provide

☐ How quickly to report

☐ How to handle suspicious messages

☐ How to report lost devices

☐ How to report suspected credential compromise


17. Information Classification Awareness

Verify that personnel understand:

☐ Organizational classification scheme

☐ Public information

☐ Internal information

☐ Confidential information

☐ Restricted information

☐ Handling requirements

☐ Sharing requirements

☐ Storage requirements

☐ Transfer requirements

☐ Disposal requirements

☐ Customer information requirements

☐ Personal-data requirements


18. Password and Authentication Awareness

Verify:

☐ Employees understand password requirements

☐ Employees understand MFA

☐ Employees understand authentication-code protection

☐ Employees understand password-reset risks

☐ Employees understand MFA-fatigue attacks

☐ Employees know not to approve unexpected MFA requests

☐ Employees know not to share credentials

☐ Employees know how to report suspected compromise


19. Remote Working Awareness

Verify:

☐ Remote-working security requirements are communicated

☐ Approved devices are explained

☐ Secure connectivity requirements are explained

☐ MFA is understood

☐ Public Wi-Fi risks are understood

☐ Confidential information handling is understood

☐ Physical privacy is addressed

☐ Lost-device reporting is understood

☐ Remote incident reporting is understood


20. AI Security Awareness

Where AI tools are used, verify:

☐ Approved AI tools are identified

☐ Employees understand prohibited information sharing

☐ Confidential information restrictions are communicated

☐ Personal-data restrictions are communicated

☐ Source-code restrictions are communicated

☐ AI-generated content risks are understood

☐ Human review requirements are understood

☐ AI-related phishing risks are covered

☐ Employees know how to report AI-related security concerns


21. Security Policy Awareness

Verify:

☐ Employees can access relevant security policies

☐ Policies are communicated

☐ Policy changes are communicated

☐ Employees understand relevant responsibilities

☐ Policy acknowledgements are tracked where required

☐ Employees receive awareness following significant policy changes

☐ Obsolete policy versions are controlled


22. Security Awareness Communications

Review whether the organization uses appropriate awareness communications.

Examples:

☐ Email communications

☐ Security newsletters

☐ Awareness campaigns

☐ Posters

☐ Security tips

☐ Phishing alerts

☐ Incident communications

☐ Policy updates

☐ Security reminders

☐ Management communications

☐ Security awareness events

Communications should be relevant and proportionate rather than creating excessive notification fatigue.


23. Security Awareness Records

Verify that appropriate records are maintained.

☐ Training register

☐ Employee training records

☐ Training completion

☐ Assessment results

☐ Quiz results

☐ Phishing simulation results

☐ Awareness campaigns

☐ Training exceptions

☐ Failed assessments

☐ Retesting

☐ Corrective actions

☐ Effectiveness assessments

☐ Management reports

Records should be protected from unauthorized access and retained according to applicable requirements.


24. Training Exceptions

Verify:

☐ Training exceptions are documented

☐ Reason is recorded

☐ Risk is assessed

☐ Compensating measures are considered

☐ Exception is approved

☐ Expiry/review date is defined

☐ Exception is monitored

☐ Exception is closed when no longer required


25. Third-Party Awareness

Where relevant, determine whether contractors and third parties receive appropriate security awareness.

Verify:

☐ Security responsibilities communicated

☐ Confidentiality requirements communicated

☐ Access requirements communicated

☐ Incident-reporting requirements communicated

☐ Information-handling requirements communicated

☐ Relevant policy requirements communicated

☐ Training evidence retained where required


26. Training Content Review

Verify:

☐ Training material has an owner

☐ Training content is approved

☐ Content is periodically reviewed

☐ Threats are updated

☐ Policy changes are incorporated

☐ Technology changes are incorporated

☐ Incident lessons are incorporated

☐ Audit findings are incorporated

☐ Regulatory requirements are considered

☐ Outdated content is removed


27. Security Awareness Effectiveness

Assess whether there is evidence of improvement.

Review:

IndicatorResultTrendAssessment
Training completion
Quiz pass rate
Average score
Phishing reporting rate
Phishing failure rate
Incident reporting
Awareness-related incidents
Repeat failures
Training-related findings

28. Employee Interviews

Interview a sample of employees to determine whether they understand:

☐ How to report an incident

☐ How to report phishing

☐ How to protect credentials

☐ How to use MFA

☐ Information classification

☐ Customer information handling

☐ Personal-data handling

☐ Remote-working requirements

☐ Acceptable-use requirements

☐ AI-security requirements

☐ Their specific security responsibilities

Interview Notes


29. Practical Testing

Where appropriate, perform controlled testing.

Examples:

☐ Simulated phishing

☐ Incident-reporting exercise

☐ Information-classification exercise

☐ Social-engineering awareness exercise

☐ Lost-device scenario

☐ MFA-fatigue scenario

☐ Business-email-compromise scenario

☐ AI-data-sharing scenario

The testing must be authorized, controlled, and designed to improve security rather than punish employees.


30. Training Effectiveness Findings

Record identified weaknesses.

Finding IDAreaRequirementEvidenceFindingRiskAction

31. Risk Assessment

For significant awareness weaknesses, consider:

  • Information affected
  • Employees affected
  • System access
  • Privileged access
  • Customer impact
  • Personal-data exposure
  • Likelihood
  • Potential business impact
  • Existing controls
  • Residual risk

Risk Treatment

☐ Reduce

☐ Avoid

☐ Share/Transfer

☐ Accept

Risk acceptance should follow the organization’s approved risk-management process.


32. Corrective Actions

For each significant weakness:

Identify → Analyze → Correct → Assign → Implement → Verify → Close

Action IDFindingRoot CauseCorrective ActionOwnerDue DateStatusVerification

Training should not automatically be selected as the corrective action. Where the root cause is a technical or process weakness, appropriate technical or process controls should also be considered.


33. Evidence Sampling

During the audit, sample evidence such as:

☐ Employee training records

☐ New employee records

☐ Annual training

☐ Role-based training

☐ Quiz results

☐ Phishing simulations

☐ Training exceptions

☐ Awareness communications

☐ Security incidents

☐ Audit findings

☐ Corrective actions

☐ Training effectiveness reports

Sample Size

Population: __________________

Sample Selected: __________________

Sampling Method: __________________


34. Audit Conclusion

Overall Assessment

☐ Effective

☐ Mostly Effective

☐ Partially Effective

☐ Ineffective

☐ Further Assessment Required

Summary

Positive Practices

Key Weaknesses

Key Recommendations


35. Management Review Inputs

Security-awareness audit results may provide management with information regarding:

  • Training performance
  • Awareness gaps
  • Phishing trends
  • Security behavior
  • Incident trends
  • Policy compliance
  • Audit findings
  • Corrective actions
  • Resource requirements
  • Training effectiveness
  • Emerging awareness risks

36. AWS SaaS Startup Example

Consider a SaaS startup using:

  • AWS
  • GitHub
  • Microsoft 365
  • Customer data
  • Remote employees
  • AI development tools

The security-awareness audit may verify:

Governance

☐ Awareness policy approved

☐ Security training owner assigned

Employees

☐ Onboarding training completed

☐ Annual training completed

☐ Security quiz completed

Developers

☐ Secure-development training completed

☐ Secrets-management awareness provided

☐ AI coding risks covered

Cloud Administrators

☐ AWS IAM awareness

☐ Privileged-access training

☐ Cloud incident-response awareness

Effectiveness

☐ Phishing simulation conducted

☐ Reporting rate measured

☐ Repeat failures identified

☐ Corrective training performed

Audit Trail

Risk → Training Requirement → Training → Quiz → Simulation → Results → Gap → Corrective Action → Retest → Improvement


37. Startup-Friendly Audit Model

A startup can perform a practical security-awareness audit without creating unnecessary bureaucracy.

Monthly

Review:

  • Security incidents
  • Phishing reports
  • Awareness questions
  • Significant security mistakes

Quarterly

Review:

  • Training completion
  • Quiz results
  • Phishing results
  • Open training actions

Annually

Perform:

  • Security awareness audit
  • Training effectiveness assessment
  • Role-based training review
  • Awareness content review
  • Management reporting

Event-Driven

Perform additional assessment following:

Incident → Audit Finding → Major Policy Change → Technology Change → Threat Change


38. Common Audit Mistakes

Avoid:

  • Checking only whether employees completed training.
  • Treating attendance as evidence of effectiveness.
  • Using one training program for every role.
  • Ignoring contractors and temporary personnel.
  • Not testing employee understanding.
  • Ignoring phishing results.
  • Ignoring incident-reporting behavior.
  • Automatically blaming employees for incidents.
  • Using training instead of technical controls.
  • Not reviewing repeat failures.
  • Not updating training material.
  • Not tracking corrective actions.
  • Not verifying corrective-action effectiveness.
  • Collecting unnecessary personal information.
  • Creating excessive awareness communications.

39. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness requirements
Security Awareness and Training ProcedureDefines training process
Annual Security Awareness PlanDefines planned activities
Security Awareness Training RegisterRecords training
Security Awareness QuizMeasures knowledge
Security Training Effectiveness AssessmentMeasures effectiveness
Role-Based Security Training MatrixDefines role-specific requirements
Phishing Awareness ProcedureDefines phishing awareness
Phishing Simulation RegisterRecords simulations
Incident Response ProcedureProvides incident-related awareness inputs
Corrective Action TrackerTracks awareness weaknesses
Security Incident RegisterProvides incident trends
Policy Compliance Review ChecklistVerifies policy awareness
Internal Audit ProcedureProvides audit methodology
Management ReviewReviews awareness performance

40. ISO 27001 Connection

Security awareness auditing supports the organization’s ability to verify that personnel understand and apply information-security responsibilities.

It can provide evidence related to areas such as:

  • Competence
  • Information-security awareness
  • Security responsibilities
  • Information protection
  • Access security
  • Incident reporting
  • Policy compliance
  • Continual improvement

The Security Awareness Audit Checklist is not itself a universally prescribed ISO 27001 form. The organization should determine the appropriate audit scope, frequency, sampling, evidence, and assessment methods based on its ISMS scope, risks, security objectives, applicable controls, contractual obligations, and legal/regulatory requirements.

The audit should also distinguish between:

Training completion → Knowledge → Behavior → Control effectiveness

These are related but not identical.


41. Final Audit Checklist

☐ Awareness policy established

☐ Awareness owner assigned

☐ Training needs assessed

☐ Risk-based training requirements defined

☐ New employee training implemented

☐ Annual training implemented

☐ Role-based training implemented

☐ Phishing awareness implemented

☐ Security quiz implemented

☐ Training effectiveness assessed

☐ Incident-reporting awareness verified

☐ Information-classification awareness verified

☐ Password/MFA awareness verified

☐ Remote-working awareness verified

☐ AI-security awareness verified where applicable

☐ Third-party awareness considered

☐ Training records maintained

☐ Training exceptions controlled

☐ Training content reviewed

☐ Employee interviews performed where appropriate

☐ Practical testing performed where appropriate

☐ Effectiveness metrics reviewed

☐ Findings documented

☐ Risks assessed

☐ Corrective actions assigned

☐ Corrective actions verified

☐ Management reporting performed

☐ Continual improvement identified


42. Final Audit Trail

For the security-awareness program, the organization should be able to demonstrate:

What security risks require employee awareness?
Who needs training?
What training is provided?
How is employee understanding tested?
How is security behavior evaluated?
What evidence demonstrates effectiveness?
What weaknesses were identified?
What corrective actions were taken?
Were improvements verified?
How are awareness requirements updated when risks change?

Final Principle

A Security Awareness Audit should not simply verify that employees completed training. It should determine whether the organization has reasonable evidence that personnel understand their security responsibilities and are applying them in practice.

Security Awareness Audit Lifecycle:

Define → Assess Risk → Train → Test → Observe → Verify → Identify Gaps → Correct → Reassess → Improve