ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Information Security Awareness Policy

Information Security Awareness Policy

1. Purpose

The Information Security Awareness Policy establishes the organization’s requirements for ensuring that employees, contractors, consultants, interns, temporary workers, and relevant third-party personnel understand their information-security responsibilities.

The objective is to ensure that personnel:

  • Understand the organization’s security expectations
  • Recognize common security threats
  • Protect organizational and customer information
  • Use systems and information securely
  • Understand their access responsibilities
  • Report security incidents and weaknesses promptly
  • Understand applicable policies and procedures
  • Receive security awareness appropriate to their role and risk
  • Maintain security awareness throughout their engagement

Core Principle

Communicate → Train → Understand → Apply → Test → Monitor → Reinforce → Improve


2. Scope

This policy applies to:

☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Remote workers
☐ Third-party personnel with organizational access
☐ Privileged users
☐ Personnel with access to customer information
☐ Personnel with access to confidential or restricted information
☐ Personnel with security-sensitive responsibilities

The policy applies to information handled through:

  • Applications
  • Cloud services
  • SaaS platforms
  • Company devices
  • Email
  • Collaboration platforms
  • Source-code repositories
  • Production systems
  • Databases
  • Physical records
  • Remote-working environments

3. Policy Statement

The organization shall provide information-security awareness appropriate to the responsibilities, access, information exposure, and risk of personnel.

Personnel shall:

  • Understand applicable security policies
  • Protect information entrusted to them
  • Use organizational systems responsibly
  • Protect passwords and credentials
  • Use MFA where required
  • Recognize and report suspicious activity
  • Report security incidents and weaknesses
  • Follow access-control requirements
  • Protect customer and personal information
  • Follow applicable security procedures
  • Participate in required security awareness activities

Security awareness shall be treated as an ongoing activity rather than a one-time training event.


4. Security Awareness Objectives

The security awareness program should aim to:

☐ Reduce security-related human error
☐ Improve threat recognition
☐ Improve incident reporting
☐ Protect confidential information
☐ Protect customer information
☐ Protect personal data
☐ Improve password and authentication practices
☐ Improve phishing resistance
☐ Support secure remote working
☐ Support secure use of cloud and SaaS services
☐ Support compliance obligations
☐ Reinforce security responsibilities
☐ Improve security culture


5. Roles and Responsibilities

5.1 Management

Management shall:

  • Support the security awareness program
  • Provide appropriate resources
  • Promote security accountability
  • Review significant awareness risks
  • Support corrective actions

5.2 Information Security

Information Security shall:

  • Define awareness requirements
  • Develop or coordinate awareness content
  • Identify security-awareness risks
  • Coordinate security campaigns
  • Monitor awareness metrics
  • Review effectiveness
  • Report significant issues to management

5.3 HR / People Team

HR shall:

  • Integrate awareness into onboarding
  • Maintain relevant personnel records
  • Coordinate required training
  • Support role-change training
  • Support offboarding requirements

5.4 Managers

Managers shall:

  • Ensure personnel complete required training
  • Identify role-specific training needs
  • Reinforce security responsibilities
  • Escalate repeated non-compliance
  • Ensure employees understand security expectations

5.5 IT

IT shall support:

  • Technical security awareness
  • Phishing simulations where approved
  • MFA awareness
  • Secure device practices
  • Access-related awareness
  • Security communications

5.6 Employees and Contractors

Personnel shall:

  • Complete required training
  • Follow security policies
  • Protect credentials
  • Protect information
  • Report suspicious activity
  • Participate in awareness activities
  • Cooperate with security investigations
  • Ask for clarification when security requirements are unclear

6. Security Awareness Requirements

Personnel shall receive awareness appropriate to their role and responsibilities.

Awareness may cover:

☐ Information security policies
☐ Acceptable use
☐ Password security
☐ MFA
☐ Phishing
☐ Social engineering
☐ Malware
☐ Ransomware
☐ Business email compromise
☐ Data protection
☐ Information classification
☐ Secure information sharing
☐ Remote working
☐ Device security
☐ Cloud security
☐ SaaS security
☐ Incident reporting
☐ Physical security
☐ Privacy
☐ AI and generative AI
☐ Customer-specific security requirements


7. Security Awareness Before Access

Where appropriate, security awareness shall be completed before personnel receive access to sensitive systems or information.

Before access is granted, verify applicable requirements such as:

☐ Security responsibilities communicated
☐ Relevant policies provided
☐ Confidentiality requirements completed
☐ Basic security awareness completed
☐ MFA requirements understood
☐ Incident reporting process communicated

Higher-risk access may require additional role-specific training.


8. New Joiner Awareness

Security awareness shall be incorporated into employee onboarding.

New personnel should understand:

  • Information-security responsibilities
  • Acceptable use
  • Password and MFA requirements
  • Information classification
  • Confidentiality
  • Phishing
  • Incident reporting
  • Device security
  • Remote working
  • Customer-data protection
  • Personal-data protection
  • AI usage requirements

Evidence may include:

  • Training record
  • Learning-management record
  • Security acknowledgement
  • Onboarding checklist

9. Annual Security Awareness

Personnel shall receive periodic security awareness appropriate to organizational risk.

Annual awareness may include:

☐ Security policy refresher
☐ Phishing awareness
☐ Social engineering
☐ Password/MFA security
☐ Data protection
☐ Incident reporting
☐ Remote working
☐ Device security
☐ Cloud/SaaS security
☐ AI security
☐ Physical security
☐ Recent organizational security incidents
☐ Emerging threats

The frequency should be based on risk and organizational requirements rather than treating annual training as the only possible awareness activity.


10. Role-Based Security Awareness

Personnel with specialized responsibilities shall receive additional training appropriate to their role.

Developers

Training may include:

  • Secure coding
  • Dependency security
  • Secrets management
  • Source-code protection
  • Secure code review
  • Vulnerability management
  • Production security

DevOps / Cloud Administrators

Training may include:

  • IAM
  • MFA
  • Privileged access
  • Cloud configuration
  • Logging
  • Secrets
  • Infrastructure security
  • Production access

Security Personnel

Training may include:

  • Incident response
  • Threat detection
  • Security monitoring
  • Evidence handling
  • Vulnerability management
  • Security testing

Finance Personnel

Training may include:

  • Business email compromise
  • Payment fraud
  • Phishing
  • Financial information protection
  • Social engineering

HR Personnel

Training may include:

  • Employee personal data
  • Confidential records
  • Access control
  • Phishing
  • Privacy requirements

11. Security Policy Awareness

Personnel shall be made aware of policies relevant to their responsibilities.

These may include:

☐ Information Security Policy
☐ Acceptable Use Policy
☐ Access Control Policy
☐ Password/MFA requirements
☐ Remote Working Policy
☐ Information Classification Policy
☐ Incident Management Policy
☐ Data Protection/Privacy Policy
☐ Cloud Security Policy
☐ Secure Development Policy
☐ AI Security Policy
☐ Business Continuity Policy
☐ Physical Security Policy

Policy communication may occur through:

  • Training
  • Employee portals
  • Email
  • Security campaigns
  • Team meetings
  • Learning platforms
  • Policy acknowledgements

12. Security Acknowledgement

Where required, personnel shall acknowledge applicable security policies.

☐ Policy communicated
☐ Policy made available
☐ Employee reviewed policy
☐ Acknowledgement completed
☐ Overdue acknowledgements tracked
☐ Exceptions documented

Acknowledgement demonstrates communication and review. It does not by itself demonstrate that personnel understand or comply with every requirement.


13. Phishing Awareness

The organization shall promote awareness of phishing and social engineering.

Personnel should understand how to identify:

  • Suspicious links
  • Unexpected attachments
  • Fake login pages
  • Urgent payment requests
  • Credential requests
  • Impersonation
  • Executive fraud
  • Supplier impersonation
  • Fake support requests
  • Malicious QR codes

Personnel shall know how to report suspected phishing.


14. Phishing Simulations

Where appropriate and proportionate, the organization may conduct controlled phishing simulations.

Before conducting simulations:

☐ Objective defined
☐ Scope defined
☐ Appropriate authorization obtained
☐ Privacy considerations assessed
☐ Personnel impact considered
☐ Reporting process defined
☐ Results handling defined

Simulation results should be used primarily for education and improvement rather than unnecessary embarrassment or punitive treatment.


15. Password and Authentication Awareness

Personnel shall understand:

  • Password protection
  • MFA requirements
  • Credential confidentiality
  • Password reuse risks
  • Password-manager use where approved
  • Phishing-resistant authentication where available
  • Account compromise reporting

Personnel shall not:

  • Share passwords
  • Share MFA codes
  • Store credentials insecurely
  • Bypass authentication controls
  • Approve unexpected MFA requests

16. Information Classification Awareness

Personnel shall understand how to identify and handle:

Public

Information approved for public disclosure.

Internal

Information intended for internal organizational use.

Confidential

Information requiring controlled access and sharing.

Restricted

Highly sensitive information requiring enhanced protection.

Training shall explain applicable:

  • Access requirements
  • Sharing restrictions
  • Storage requirements
  • Transmission requirements
  • Disposal requirements

17. Customer Information Awareness

Personnel handling customer information shall understand:

☐ Customer confidentiality
☐ Authorized access
☐ Data minimization
☐ Secure sharing
☐ Customer-specific requirements
☐ Incident reporting
☐ Retention requirements
☐ Deletion/return requirements

Customer contractual requirements shall be incorporated into awareness where relevant.


18. Personal Data and Privacy Awareness

Personnel who handle personal data shall understand:

  • Appropriate use
  • Access restrictions
  • Data minimization
  • Secure transfer
  • Retention
  • Deletion
  • Privacy incidents
  • Unauthorized disclosure
  • Data-subject considerations where applicable

Privacy awareness shall be aligned with applicable legal and regulatory requirements.


19. Secure Remote Working Awareness

Remote personnel shall understand:

☐ Secure Wi-Fi/network use
☐ MFA
☐ Device security
☐ Screen locking
☐ Confidential conversations
☐ Secure information handling
☐ Public/shared environment risks
☐ VPN/secure access where required
☐ Lost-device reporting
☐ Phishing risks


20. Cloud and SaaS Awareness

Personnel using cloud and SaaS services shall understand:

  • Approved cloud services
  • Approved SaaS applications
  • Access control
  • MFA
  • Data sharing
  • Shadow IT risks
  • File-sharing security
  • Cloud credentials
  • Secure configuration responsibilities

Personnel shall not introduce unapproved cloud services to process organizational or customer information where prohibited.


21. AI and Generative AI Awareness

Personnel using AI or generative AI tools shall understand:

☐ Approved AI tools
☐ Prohibited information
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ Confidential information restrictions
☐ Source-code restrictions
☐ Security risks
☐ Hallucination risks
☐ Output verification
☐ Intellectual-property considerations
☐ AI incident reporting

Sensitive organizational information shall not be submitted to AI services unless the use is authorized and appropriate safeguards are in place.


22. Security Incident Awareness

Personnel shall know how to report:

  • Phishing
  • Malware
  • Lost devices
  • Credential compromise
  • Unauthorized access
  • Accidental data disclosure
  • Suspicious activity
  • Security weaknesses
  • Privacy incidents
  • Suspected ransomware
  • Unauthorized software
  • Misuse of information

Personnel should be encouraged to report suspected incidents promptly rather than delay reporting because they are uncertain.


23. Security Weakness Reporting

Personnel should be encouraged to report security weaknesses such as:

  • Misconfigured systems
  • Exposed information
  • Unprotected files
  • Excessive access
  • Security-control failures
  • Vulnerabilities
  • Suspicious applications
  • Unusual system behavior

A defined reporting channel shall be available.


24. Physical Security Awareness

Where applicable, personnel shall understand:

☐ Visitor controls
☐ Badge protection
☐ Secure-area access
☐ Clean desk
☐ Clear screen
☐ Document protection
☐ Device protection
☐ Secure disposal
☐ Tailgating risks
☐ Lost access cards


25. Security Awareness Communications

Awareness may be reinforced through periodic communications.

Examples:

  • Security newsletters
  • Security tips
  • Phishing alerts
  • Threat advisories
  • Short videos
  • Posters
  • Team briefings
  • Security campaigns
  • Incident lessons learned
  • Security reminders

Communications should focus on relevant risks rather than generating excessive notification fatigue.


26. Security Awareness Campaigns

The organization may conduct focused campaigns such as:

January

Password and MFA security

February

Phishing awareness

March

Data protection

April

Secure remote working

May

Cloud security

June

Incident reporting

July

Social engineering

August

Secure development

September

Physical security

October

Cybersecurity awareness

November

AI security

December

Security lessons learned

The campaign schedule may be adjusted based on current threats and organizational risk.


27. Security Awareness Testing

Where appropriate, awareness effectiveness may be tested through:

☐ Knowledge assessments
☐ Phishing simulations
☐ Tabletop exercises
☐ Incident-reporting exercises
☐ Short quizzes
☐ Practical demonstrations
☐ Security drills
☐ Interviews
☐ Audit sampling

Testing should assess whether personnel can apply security requirements, not merely remember training content.


28. Security Awareness Metrics

The organization may monitor:

  • Training completion rate
  • Overdue training
  • Policy acknowledgement rate
  • Phishing simulation results
  • Phishing reporting rate
  • Security incident reporting rate
  • Security quiz results
  • Repeat awareness failures
  • Role-specific training completion
  • New-joiner training completion
  • Privileged-user training completion

29. Awareness Effectiveness

The organization shall periodically evaluate whether awareness activities are effective.

Consider:

☐ Training completion
☐ Knowledge assessment
☐ Incident trends
☐ Phishing reporting
☐ Security violations
☐ Audit findings
☐ Access-related incidents
☐ Employee feedback
☐ Repeat failures
☐ Changes in threat environment

Training should be improved where evidence indicates that personnel are not effectively applying security requirements.


30. Security Awareness Exceptions

Where personnel cannot complete required training:

☐ Exception documented
☐ Reason recorded
☐ Risk assessed
☐ Compensating measure defined
☐ Manager approval obtained
☐ Security approval where required
☐ Completion deadline defined
☐ Exception monitored


31. Non-Compliance

Failure to complete required awareness activities may result in:

  • Reminder
  • Additional training
  • Manager escalation
  • Temporary restriction of sensitive access where appropriate
  • Corrective action
  • Disciplinary action where applicable

Any disciplinary action shall follow applicable organizational policy and law.


32. Third-Party Awareness

Relevant third-party personnel shall receive or acknowledge applicable security requirements.

This may include:

☐ Confidentiality
☐ Access requirements
☐ Information handling
☐ Incident reporting
☐ Customer requirements
☐ Acceptable use
☐ Cloud/security requirements
☐ Data protection
☐ Security testing restrictions

Supplier agreements should define responsibilities where appropriate.


33. Security Awareness Records

Appropriate records may include:

☐ Training attendance
☐ Course completion
☐ Assessment results
☐ Policy acknowledgements
☐ Awareness communications
☐ Phishing simulation results
☐ Campaign records
☐ Role-specific training
☐ Exceptions
☐ Corrective actions
☐ Effectiveness reviews

Records shall be protected against unauthorized access or modification.


34. Privacy of Awareness Records

Security awareness records may contain personnel information.

The organization shall:

  • Limit access
  • Collect only necessary information
  • Define retention requirements
  • Protect records
  • Apply appropriate privacy controls
  • Securely dispose of records when no longer required

35. Security Awareness Register

Maintain an appropriate register where needed.

PersonnelRoleTrainingDateStatusAssessmentNext Due

36. Awareness Review

The awareness program shall be reviewed periodically and when significant changes occur.

Review triggers may include:

☐ Major security incident
☐ Phishing increase
☐ New technology
☐ New cloud service
☐ New AI tool
☐ Regulatory change
☐ Customer requirement
☐ Significant audit finding
☐ New threat
☐ Organizational restructuring
☐ Major role changes


37. Security Awareness Governance

The organization shall maintain appropriate governance over the awareness program.

This may include:

  • Program owner
  • Training requirements
  • Target audiences
  • Training schedule
  • Metrics
  • Effectiveness assessment
  • Exceptions
  • Corrective actions
  • Management reporting

38. Management Reporting

Significant awareness results may be reported to management.

Examples:

  • Training completion
  • Phishing trends
  • Security incident trends
  • Repeat awareness failures
  • High-risk personnel training
  • Awareness exceptions
  • Security culture indicators
  • Improvement actions

39. Continual Improvement

The organization shall improve the awareness program based on:

  • Security incidents
  • Audit findings
  • Phishing results
  • Employee feedback
  • Emerging threats
  • Technology changes
  • Regulatory requirements
  • Customer requirements
  • Lessons learned

Improvement Cycle

Measure → Analyze → Improve → Communicate → Test → Reassess


40. AWS SaaS Startup Example

An AWS SaaS startup has:

  • Developers
  • DevOps engineers
  • Sales personnel
  • Customer support
  • Finance
  • HR
  • Remote employees

A common awareness program could include:

All Personnel

  • Phishing
  • MFA
  • Passwords
  • Incident reporting
  • Data classification
  • Remote working
  • AI usage

Developers

  • Secure coding
  • Secrets
  • Source-code protection
  • Dependency security

DevOps

  • AWS IAM
  • Privileged access
  • Production security
  • Cloud logging
  • Secrets management

Finance

  • Business email compromise
  • Payment fraud
  • Supplier impersonation

Customer Support

  • Customer-data protection
  • Identity verification
  • Secure information sharing

HR

  • Employee personal data
  • Confidential information
  • Phishing

Evidence

The startup should be able to demonstrate:

Training Assigned → Training Completed → Knowledge/Behavior Tested → Results Reviewed → Improvements Made


41. Startup-Friendly Awareness Model

A startup can operate a lightweight but effective program.

At Joining

Security Orientation → Policy Review → Acknowledgement → Role Training

Monthly

Security Tip / Threat Alert

Quarterly

Focused Awareness Campaign

Annually

Security Awareness Refresher + Effectiveness Assessment

After Significant Events

Incident Lesson → Targeted Awareness → Control Improvement

For high-risk roles, add role-specific training and periodic testing.


42. Common Mistakes

Avoid:

  • Treating annual training as the entire security-awareness program.
  • Training everyone identically regardless of role.
  • Measuring only training completion.
  • Ignoring contractors and third-party personnel.
  • Failing to train new employees before sensitive access.
  • Not providing incident-reporting instructions.
  • Ignoring phishing and social engineering.
  • Ignoring AI-related security risks.
  • Using excessive security communications that create alert fatigue.
  • Failing to evaluate whether training changed behavior.
  • Retaining unnecessary personal information in training records.
  • Failing to update training after major incidents.
  • Treating acknowledgement as proof of compliance.
  • Not providing role-specific training for privileged personnel.

43. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyEstablishes overall security expectations
Employee Security ResponsibilitiesDefines personnel security obligations
Employee Security AcknowledgementRecords communication and acknowledgement
Employee Onboarding ChecklistIntroduces security requirements
Employee Role Change ChecklistIdentifies new training requirements
Employee Offboarding ProcedureControls security during exit
Security Awareness Training ProcedureDefines operational training process
Security Awareness Training RegisterRecords training
Phishing Awareness ProcedureSupports phishing education/testing
Acceptable Use PolicyDefines acceptable technology use
Information Classification PolicyDefines information handling
Incident Management ProcedureDefines incident reporting
Access Management ProcedureDefines access responsibilities
AI Security PolicyDefines secure AI use
Personnel Security PolicyDefines broader personnel controls

44. ISO/IEC 27001 Connection

Information-security awareness supports the organization’s risk-based management of personnel security, security responsibilities, awareness, training, access, information protection, and related operational controls.

The Information Security Awareness Policy is not itself a universally prescribed ISO/IEC 27001 document title.

The organization should determine the appropriate awareness activities based on:

  • ISMS scope
  • Risk assessment
  • Statement of Applicability
  • Personnel roles
  • Information handled
  • Systems accessed
  • Legal/regulatory requirements
  • Customer requirements
  • Contractual requirements
  • Security incidents
  • Audit findings
  • Threat environment

The awareness program should demonstrate not only that training was delivered, but that relevant personnel received appropriate information and that the organization evaluates whether awareness is effective.


45. Audit Evidence Checklist

The organization should retain appropriate evidence such as:

☐ Approved awareness policy
☐ Awareness plan
☐ Training materials
☐ Training schedule
☐ Training assignments
☐ Training completion records
☐ Security acknowledgements
☐ Knowledge assessments
☐ Phishing simulation results where applicable
☐ Awareness campaigns
☐ Security communications
☐ Role-specific training
☐ Training exceptions
☐ Corrective actions
☐ Effectiveness assessments
☐ Awareness metrics
☐ Management reporting

Evidence should be proportionate to risk and should not contain unnecessary sensitive personnel information.


46. Policy Review

This policy shall be reviewed periodically and when significant changes occur.

Review triggers include:

☐ Major security incident
☐ Significant audit finding
☐ New technology
☐ New regulatory requirement
☐ New customer requirement
☐ Organizational change
☐ Major change in threat environment
☐ Significant changes to the ISMS

Policy Owner

Name/Role: ______________________________

Approval

Approved By: _____________________________

Approval Date: ____________________________

Next Review Date



47. Final Security Awareness Audit Trail

The organization should be able to demonstrate:

Who needs security awareness?
What security knowledge do they need?
Why is that knowledge relevant to their role?
When was the awareness provided?
Did the personnel complete it?
Did they understand the requirements?
Can they recognize and report security threats?
How is awareness effectiveness measured?
What happens when awareness is not effective?
How are lessons from incidents and audits incorporated into future training?

Final Principle

Security awareness is not simply completing a training course. It is an ongoing process of communicating security expectations, developing appropriate knowledge and behavior, testing effectiveness, learning from incidents, and continually improving the organization’s security culture.