ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Phishing Awareness Procedure

Phishing Awareness Procedure

1. Purpose

The Phishing Awareness Procedure defines how the organization identifies, communicates, trains, tests, monitors, and improves employee awareness against phishing and social-engineering attacks.

The procedure is designed to reduce the likelihood that personnel will:

  • Click malicious links
  • Open malicious attachments
  • Disclose credentials
  • Approve fraudulent authentication requests
  • Transfer sensitive information to unauthorized parties
  • Install malicious software
  • Respond to fraudulent payment or business requests
  • Bypass security controls
  • Become victims of social-engineering attacks

Core Principle

Identify → Educate → Simulate → Report → Analyze → Reinforce → Improve


2. Scope

This procedure applies to:

  • Employees
  • Contractors
  • Interns
  • Temporary personnel
  • Consultants
  • Privileged users
  • Remote workers
  • Personnel handling customer information
  • Personnel handling personal information
  • Other users with organizational accounts

The organization may apply enhanced awareness activities to higher-risk roles.


3. Phishing Awareness Objectives

The organization should ensure personnel can:

☐ Recognize common phishing indicators

☐ Identify suspicious emails

☐ Identify suspicious links

☐ Identify malicious attachments

☐ Recognize credential-harvesting attempts

☐ Recognize MFA fatigue attacks

☐ Recognize business-email-compromise attempts

☐ Recognize social-engineering techniques

☐ Verify unusual requests

☐ Report suspected phishing

☐ Avoid interacting with suspicious content

☐ Respond appropriately after accidental interaction


4. Phishing Threat Categories

Awareness activities should cover relevant attack types.

Email Phishing

Fraudulent emails designed to trick users into clicking, opening, replying, or providing information.

Credential Phishing

Attempts to obtain:

  • Passwords
  • MFA codes
  • Session tokens
  • Authentication information

Spear Phishing

Highly targeted phishing directed at a specific employee, role, or organization.

Business Email Compromise

Fraudulent messages impersonating:

  • Executives
  • Customers
  • Suppliers
  • Finance personnel
  • Business partners

MFA Fatigue

Repeated authentication requests intended to pressure users into approving an unauthorized login.

Smishing

Phishing through SMS or messaging applications.

Vishing

Social engineering through voice or telephone calls.

QR Phishing

Malicious QR codes directing users to fraudulent websites.

Attachment-Based Phishing

Malicious or unexpected files designed to compromise a system or obtain information.

AI-Assisted Phishing

Highly convincing messages generated or enhanced using AI.


5. Roles and Responsibilities

RoleResponsibility
Senior ManagementSupport awareness program and provide resources
Information SecurityOwn phishing awareness program
HRSupport employee communication and onboarding
ITSupport technical controls and reporting mechanisms
ManagersSupport completion and follow-up
EmployeesComplete training, identify and report suspicious activity
Security TeamAnalyze reported phishing and coordinate response
Incident Response TeamHandle confirmed security incidents
Training OwnerMaintain training content and records

6. Phishing Awareness Program

The organization should maintain a risk-based phishing awareness program consisting of:

  1. Initial awareness training
  2. New-employee training
  3. Periodic refresher training
  4. Security communications
  5. Phishing simulations where appropriate
  6. Reporting mechanisms
  7. Incident-driven awareness
  8. Measurement and analysis
  9. Targeted reinforcement
  10. Continual improvement

7. New Employee Awareness

Phishing awareness should be included in security onboarding.

Before or shortly after receiving organizational access, personnel should understand:

☐ How to identify suspicious messages

☐ How to report phishing

☐ How to verify unusual requests

☐ How to handle attachments

☐ How to handle links

☐ MFA security

☐ Password protection

☐ Incident reporting

☐ Business-email-compromise risks

☐ Social-engineering risks


8. Periodic Awareness Training

Phishing awareness should be refreshed periodically based on risk.

Training may include:

  • Email examples
  • Real-world scenarios
  • Short videos
  • Interactive exercises
  • Quizzes
  • Simulations
  • Security alerts
  • Case studies
  • Incident lessons learned

Training frequency should be determined based on organizational risk, threat exposure, incidents, regulatory/customer requirements, and previous training results.


9. Phishing Indicators

Employees should be trained to consider:

Sender

☐ Unexpected sender

☐ Similar-looking domain

☐ Unknown external sender

☐ Unexpected internal sender

☐ Display-name impersonation

Message

☐ Urgent request

☐ Threatening language

☐ Unexpected payment request

☐ Unexpected password-reset request

☐ Request for confidential information

☐ Unusual business request

☐ Suspicious grammar or formatting

Link

☐ Unexpected link

☐ Mismatched displayed URL

☐ Suspicious domain

☐ URL-shortening service used unexpectedly

☐ Unexpected login page

Attachment

☐ Unexpected attachment

☐ Unexpected document

☐ Executable file

☐ Macro-enabled document

☐ Password-protected archive from an unknown source


10. Verify Before Acting

Personnel should be trained to independently verify unusual or high-risk requests.

Examples:

“Please transfer this payment immediately.”

“Send me the customer database.”

“Reset my password.”

“Approve this MFA request.”

“Download this urgent document.”

“Share the security report.”

The employee should verify the request using an independent communication channel where appropriate.


11. Reporting Procedure

Personnel should have a simple mechanism for reporting suspected phishing.

Possible mechanisms:

  • Phishing-report button
  • Security email address
  • Helpdesk
  • Security ticket
  • Incident-management platform
  • Approved reporting channel

Employee Reporting Process

Stop → Do Not Interact Further → Report → Follow Instructions

Employees should not be discouraged from reporting because they believe they may have made a mistake.


12. What Employees Should Do

If a suspicious message is received:

If Not Opened

  1. Do not click links.
  2. Do not open attachments.
  3. Report the message.
  4. Follow the organization’s instructions.
  5. Delete or quarantine it when authorized.

If a Link Was Clicked

  1. Stop interacting with the website.
  2. Do not enter credentials.
  3. Close the browser if appropriate.
  4. Report the event immediately.
  5. Follow security-team instructions.

If Credentials Were Entered

  1. Report immediately.
  2. Do not attempt to hide the event.
  3. Follow password-reset instructions.
  4. Follow MFA/security instructions.
  5. Cooperate with the investigation.

If a Malicious Attachment Was Opened

  1. Stop interacting with the file.
  2. Disconnect from the network if instructed.
  3. Report immediately.
  4. Do not delete evidence unless instructed.
  5. Follow incident-response instructions.

13. Phishing Simulation Program

Where appropriate, the organization may conduct controlled phishing simulations.

The objective is to measure and improve awareness, not to punish employees.

Simulation Lifecycle

Plan → Approve → Configure → Send → Monitor → Analyze → Reinforce → Report → Improve


14. Simulation Planning

Before conducting a simulation:

☐ Objective defined

☐ Scope defined

☐ Target audience defined

☐ Simulation type defined

☐ Risk assessed

☐ Approval obtained

☐ Communication approach defined

☐ Privacy considerations assessed

☐ Emergency stop mechanism established

☐ Results handling defined


15. Simulation Rules

Simulations should be designed responsibly.

Avoid unnecessary:

  • Personal humiliation
  • Public naming and shaming
  • Highly distressing content
  • Excessive frequency
  • Collection of real passwords
  • Collection of unnecessary personal information
  • Real malware
  • Actual credential harvesting

Simulation systems should not collect real passwords.


16. Phishing Simulation Scenarios

Examples:

Scenario 1 — Password Expiry

A simulated message claims that the user’s password will expire.

Scenario 2 — Document Sharing

A simulated notification asks the user to review a document.

Scenario 3 — Executive Request

A simulated executive requests urgent action.

Scenario 4 — Supplier Invoice

A simulated supplier sends an invoice requiring review.

Scenario 5 — MFA Request

A simulated authentication notification attempts to create urgency.

Scenario 6 — Cloud Login

A simulated cloud-service notification asks the user to sign in.


17. Simulation Metrics

Track appropriate metrics.

Click Rate

Users who clicked ÷ Users tested × 100

Reporting Rate

Users who reported ÷ Users tested × 100

Credential Submission Rate

Where safely simulated without collecting real credentials:

Users who reached the simulated credential page ÷ Users tested × 100

Repeat Failure Rate

Users failing multiple simulations ÷ Users tested × 100

Metrics should be interpreted carefully rather than used as standalone measures of employee performance.


18. Phishing Simulation Register

Simulation IDDateAudienceUsers TestedClickedReportedClick RateReport RateFollow-Up

19. Targeted Awareness

Additional awareness may be provided to higher-risk groups.

Examples:

Finance

Focus on:

  • Payment fraud
  • Invoice fraud
  • Executive impersonation
  • Supplier impersonation

HR

Focus on:

  • Employee-data requests
  • Resume attachments
  • Identity fraud
  • Payroll fraud

IT

Focus on:

  • Credential theft
  • Privileged access
  • MFA attacks
  • Technical impersonation

Developers

Focus on:

  • Repository notifications
  • Package/repository phishing
  • Developer credential theft
  • Secrets exposure

Executives

Focus on:

  • Executive impersonation
  • Business-email compromise
  • Targeted spear phishing

20. Business Email Compromise Awareness

Personnel should be trained to recognize unusual requests involving:

  • Payments
  • Bank-account changes
  • Supplier details
  • Customer information
  • Confidential information
  • Urgent approvals
  • Gift cards
  • Password resets
  • Executive requests

Verification Principle

Urgency does not replace verification.

High-risk financial or information requests should follow the organization’s approved authorization process.


21. MFA Awareness

Personnel should understand that MFA does not eliminate phishing risk.

Awareness should cover:

☐ Unexpected MFA requests

☐ MFA fatigue

☐ Authentication-code requests

☐ Push-notification abuse

☐ Fake authentication pages

☐ Never approving an unexpected login

Rule

Never approve an authentication request that you did not initiate.


22. AI-Enabled Phishing Awareness

Personnel should be aware that AI can make phishing messages:

  • Grammatically correct
  • Highly personalized
  • Professionally formatted
  • Contextually convincing
  • Multilingual

Therefore, employees should not rely only on spelling mistakes or poor grammar to identify phishing.

Focus on:

  • Unexpected requests
  • Identity verification
  • Link destination
  • Context
  • Urgency
  • Authorization
  • Independent verification

23. Phishing Reporting and Incident Escalation

A reported phishing message should be assessed.

Process

Report → Triage → Analyze → Determine Severity → Contain → Investigate → Recover → Learn

Potential outcomes:

☐ Spam

☐ Phishing attempt

☐ Credential theft attempt

☐ Malware attempt

☐ Business-email compromise

☐ Confirmed compromise

☐ Security incident

☐ False positive


24. Security Team Responsibilities

The security team should, where appropriate:

  • Review reported messages
  • Analyze sender information
  • Analyze URLs
  • Analyze attachments
  • Check authentication logs
  • Check endpoint alerts
  • Search for similar messages
  • Identify affected users
  • Block malicious domains
  • Block malicious indicators
  • Reset compromised credentials
  • Revoke sessions/tokens where necessary
  • Escalate confirmed incidents
  • Preserve evidence
  • Update awareness content

25. Incident-Driven Awareness

When phishing results in a security incident, evaluate whether additional awareness is required.

Example

Phishing email → Employee clicks → Credentials compromised → Account secured → Root cause analysis → Targeted training → Simulation → Effectiveness review

The objective should be to address the underlying risk rather than simply blame the individual.


26. Security Controls Supporting Awareness

Phishing awareness should be supported by technical controls where appropriate.

Examples:

☐ Email filtering

☐ Anti-malware

☐ URL protection

☐ Attachment scanning

☐ SPF

☐ DKIM

☐ DMARC

☐ MFA

☐ Conditional access

☐ Endpoint protection

☐ DNS filtering

☐ Security monitoring

☐ Browser protection

Awareness training should not be treated as a substitute for appropriate technical controls.


27. Phishing Training Content

Training content should cover:

Basic Awareness

  • What is phishing?
  • Why phishing works
  • Common attack types
  • Warning signs
  • Reporting

Authentication

  • Password protection
  • MFA
  • MFA fatigue
  • Credential phishing

Information Protection

  • Customer information
  • Personal data
  • Confidential information
  • Financial information
  • Source code

Social Engineering

  • Authority
  • Urgency
  • Fear
  • Curiosity
  • Trust
  • Familiarity

Response

  • Stop
  • Report
  • Verify
  • Escalate

28. Awareness Communications

Security communications may be issued following:

☐ New phishing campaign

☐ Significant threat

☐ Security incident

☐ New attack technique

☐ Technology change

☐ Regulatory/customer requirement

☐ Repeated simulation failures

Communications should be concise and actionable.


29. Phishing Awareness Records

Maintain appropriate evidence such as:

  • Training assignments
  • Training completion
  • Training materials
  • Assessment results
  • Phishing simulation records
  • Campaign communications
  • Reporting statistics
  • Incident-driven training
  • Management reports
  • Corrective actions
  • Improvement records

Avoid retaining unnecessary sensitive employee information.


30. Privacy and Employee Data

Phishing awareness activities should respect employee privacy.

The organization should:

☐ Collect only necessary information

☐ Restrict access to simulation results

☐ Define retention

☐ Protect employee records

☐ Avoid unnecessary public disclosure

☐ Apply applicable privacy requirements

☐ Define appropriate management reporting


31. Training Effectiveness

Effectiveness should be evaluated using multiple indicators.

Consider:

  • Training completion
  • Assessment results
  • Phishing simulation results
  • Reporting rate
  • Click rate
  • Repeat behavior
  • Security incidents
  • Near misses
  • Employee feedback
  • Audit findings

Effectiveness Principle

Completion demonstrates participation. Behavior demonstrates effectiveness.


32. Corrective Actions

Where weaknesses are identified:

FindingCauseActionOwnerDue DateEvidenceStatus

Actions may include:

  • Refresher training
  • Targeted training
  • Additional simulations
  • Technical controls
  • Process changes
  • Access restrictions
  • Management communication
  • Incident-response improvements

33. Exceptions

Where a person cannot complete required training:

☐ Reason documented

☐ Risk assessed

☐ Alternative arrangement defined

☐ Compensating control considered

☐ Approval obtained

☐ Expiry date defined

☐ Follow-up scheduled


34. Management Reporting

Management reporting may include:

MetricCurrentPreviousTargetStatus
Training Completion
Phishing Click Rate
Phishing Reporting Rate
Repeat Failure Rate
Phishing Incidents
Overdue Training

Reports should emphasize security risk and trends rather than individual employee performance.


35. Review Frequency

The procedure should be reviewed:

☐ At least annually

☐ Following a significant phishing incident

☐ Following significant changes in threats

☐ Following major technology changes

☐ Following significant audit findings

☐ Following changes to applicable requirements


36. AWS SaaS Startup Example

Consider a SaaS startup with:

  • AWS production environment
  • GitHub
  • Microsoft 365 or Google Workspace
  • Remote employees
  • Customer data
  • Cloud administrators
  • Developers
  • Finance personnel

Awareness Program

All Employees

  • Phishing awareness
  • MFA
  • Password security
  • Incident reporting

Developers

  • GitHub phishing
  • Repository notifications
  • Credential theft
  • Secrets protection

Cloud Administrators

  • AWS credential phishing
  • Privileged access
  • MFA fatigue
  • Cloud-console impersonation

Finance

  • Invoice fraud
  • Executive impersonation
  • Bank-account-change verification

Audit Trail

Threat → Awareness Requirement → Training → Simulation → Reporting → Measurement → Corrective Action → Improvement


37. Startup-Friendly Model

A small startup can implement an effective phishing program without a large security team.

Minimum Program

Monthly

  • One short awareness message

Quarterly

  • One focused phishing awareness activity

Periodically

  • Controlled phishing simulation where appropriate

Annually

  • Formal security-awareness training

After Incidents

  • Targeted awareness and corrective action

Minimum Evidence

Maintain:

  • Training register
  • Simulation register
  • Campaign records
  • Assessment results
  • Incident records
  • Corrective actions

38. Common Mistakes

Avoid:

  • Treating phishing awareness as a once-a-year presentation.
  • Relying only on employees to stop phishing.
  • Ignoring MFA-fatigue attacks.
  • Focusing only on spelling mistakes.
  • Failing to provide an easy reporting mechanism.
  • Punishing employees for reporting mistakes.
  • Collecting real passwords during simulations.
  • Publicly shaming employees.
  • Ignoring business-email compromise.
  • Ignoring AI-assisted phishing.
  • Failing to analyze repeat behavior.
  • Not updating training after incidents.
  • Measuring only training completion.
  • Failing to integrate phishing reporting with incident response.

39. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness requirements
Security Awareness and Training ProcedureDefines the broader training process
Security Awareness Training RegisterRecords training completion
Role-Based Security Training MatrixDefines role-specific training
Employee Security Training ChecklistVerifies individual training
Incident Response ProcedureHandles confirmed phishing incidents
Security Incident Reporting ProcedureDefines incident reporting
Incident RegisterRecords confirmed incidents
Corrective Action TrackerTracks corrective actions
Security Awareness Campaign RegisterRecords awareness campaigns
Phishing Simulation RegisterRecords phishing simulations
Access Management ProcedureSupports protection after credential compromise
MFA StandardSupports authentication security

40. ISO 27001 Connection

Phishing awareness supports the organization’s information-security awareness, competence, access-control, incident-management, and information-protection objectives.

The procedure should be aligned with:

  • Information-security roles and responsibilities
  • Awareness and training requirements
  • Authentication controls
  • Access management
  • Incident management
  • Malware protection
  • Technical vulnerability management
  • Information protection
  • Security monitoring
  • Business continuity where relevant

The Phishing Awareness Procedure is not itself a universally prescribed ISO 27001 document. The organization should determine its need, scope, frequency, and evidence based on its risk assessment, threat environment, ISMS scope, applicable controls, contractual requirements, and legal/regulatory obligations.


41. Final Audit Checklist

☐ Phishing awareness owner assigned

☐ Procedure approved

☐ Phishing threats identified

☐ New-employee awareness defined

☐ Annual awareness defined

☐ Role-based awareness defined

☐ Reporting mechanism established

☐ Employees trained

☐ Phishing simulations approved where applicable

☐ Simulation rules defined

☐ Real credentials not collected

☐ Simulation results protected

☐ Phishing metrics tracked

☐ Incident escalation defined

☐ Incident-driven training defined

☐ MFA phishing risks addressed

☐ Business-email compromise addressed

☐ AI-enabled phishing addressed

☐ Technical controls considered

☐ Corrective actions tracked

☐ Training effectiveness measured

☐ Management reporting performed

☐ Procedure reviewed periodically


42. Final Audit Trail

For a phishing-awareness program, the organization should be able to demonstrate:

What phishing threats affect us?
Who is at risk?
What awareness is required?
Who received training?
How was understanding assessed?
How can employees report phishing?
Are simulations performed where appropriate?
What do the results show?
What happens when someone reports a suspicious message?
How are confirmed incidents handled?
What additional training follows an incident?
How is effectiveness measured?
How does the program improve over time?

Final Principle

Phishing awareness is not simply about teaching employees to recognize suspicious emails. It is a continuous security process that combines awareness, reporting, technical protection, incident response, measurement, and continual improvement.

Phishing Awareness Lifecycle:

Identify Threat → Educate → Simulate → Report → Analyze → Respond → Reinforce → Measure → Improve