1. Purpose
The Security Awareness and Training Procedure defines how the organization plans, delivers, records, evaluates, and improves information-security awareness and training.
The procedure ensures that personnel receive security knowledge appropriate to their:
- Role
- Responsibilities
- Information access
- System access
- Privilege level
- Business activities
- Security risk
The procedure applies throughout the personnel lifecycle.
Core Principle
Identify Training Need → Plan → Assign → Deliver → Assess → Record → Monitor → Improve
2. Scope
This procedure applies to:
☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary personnel
☐ Remote workers
☐ Third-party personnel where applicable
☐ Privileged users
☐ Security personnel
☐ Personnel with production access
☐ Personnel handling customer or restricted information
3. Training and Awareness Information
| Field | Details |
|---|---|
| Program Owner | |
| Training Period | |
| Training Year | |
| Applicable Personnel | |
| Business Units | |
| Training Platform | |
| Security Owner | |
| HR Owner | |
| Review Date |
4. Objectives
The security awareness and training program shall aim to:
- Communicate security responsibilities
- Improve security knowledge
- Reduce human-related security risks
- Improve threat recognition
- Improve incident reporting
- Support secure use of systems
- Protect organizational information
- Protect customer information
- Support privacy requirements
- Support compliance requirements
- Provide role-specific security knowledge
- Evaluate awareness effectiveness
5. Roles and Responsibilities
5.1 Management
Management shall:
- Support the program
- Provide appropriate resources
- Review significant training risks
- Support corrective actions
5.2 Information Security
Information Security shall:
- Define security training requirements
- Identify security awareness risks
- Develop or approve security content
- Monitor completion
- Evaluate effectiveness
- Maintain security awareness metrics
- Report significant issues
5.3 HR
HR shall:
- Integrate training into onboarding
- Maintain applicable personnel training records
- Support training scheduling
- Coordinate with managers
- Support role-change requirements
5.4 Managers
Managers shall:
- Ensure personnel complete required training
- Identify role-specific training needs
- Support training attendance
- Address overdue training
- Escalate repeated non-compliance
5.5 IT
IT may support:
- Technical-security training
- Phishing awareness
- MFA awareness
- Device security
- Cloud-security awareness
5.6 Personnel
Personnel shall:
- Complete assigned training
- Participate in required awareness activities
- Apply security requirements
- Report security concerns
- Ask questions where requirements are unclear
6. Training Needs Assessment
Before establishing the training plan, identify applicable requirements.
Consider:
☐ Job responsibilities
☐ Information handled
☐ System access
☐ Privileged access
☐ Production access
☐ Customer information
☐ Personal data
☐ Regulatory responsibilities
☐ Security responsibilities
☐ Previous incidents
☐ Audit findings
☐ Emerging threats
☐ Technology changes
☐ Customer requirements
7. Training Categories
The organization may classify training into:
Level 1 — General Awareness
For all personnel.
Level 2 — Role-Based Training
For personnel with specific security responsibilities.
Level 3 — Specialized Technical Training
For technical or security-sensitive personnel.
Level 4 — Privileged / High-Risk Training
For personnel with significant administrative, production, security, or sensitive-data access.
8. General Security Awareness
General awareness may cover:
☐ Information security policy
☐ Acceptable use
☐ Password security
☐ MFA
☐ Phishing
☐ Social engineering
☐ Malware
☐ Ransomware
☐ Incident reporting
☐ Information classification
☐ Data protection
☐ Remote working
☐ Device security
☐ Physical security
☐ Cloud/SaaS security
☐ AI and generative AI
9. New Joiner Training
Security training shall be incorporated into employee onboarding.
Before or shortly after access is granted, as appropriate to risk:
☐ Security responsibilities communicated
☐ Information-security policies provided
☐ Confidentiality requirements communicated
☐ Acceptable-use requirements communicated
☐ Incident-reporting process explained
☐ MFA requirements explained
☐ Information classification explained
☐ Required security training assigned
☐ Completion recorded
Higher-risk access may require training before access is granted.
10. Role-Based Training
Training shall be tailored where the employee’s role creates additional security responsibilities.
Developers
Possible topics:
- Secure coding
- OWASP risks
- Dependency management
- Secrets management
- Source-code protection
- Secure code review
- Vulnerability remediation
- Secure deployment
DevOps / Cloud
Possible topics:
- IAM
- MFA
- Privileged access
- AWS/cloud security
- Logging
- Infrastructure security
- Secrets management
- Production security
Security Personnel
Possible topics:
- Incident response
- Threat detection
- Vulnerability management
- Security testing
- Evidence handling
- Security monitoring
Finance
Possible topics:
- Business email compromise
- Payment fraud
- Phishing
- Financial information protection
- Supplier impersonation
HR
Possible topics:
- Employee personal data
- Confidential information
- Access control
- Privacy
- Phishing
11. Privileged User Training
Personnel with privileged access should receive enhanced training appropriate to their responsibilities.
Topics may include:
☐ Privileged access
☐ Least privilege
☐ MFA
☐ Administrative accounts
☐ Secure administration
☐ Cloud security
☐ Production security
☐ Logging and monitoring
☐ Secrets management
☐ Incident reporting
☐ Emergency access
12. Production Access Training
Personnel with production access shall understand:
- Production security requirements
- Approved access methods
- Change management
- Deployment requirements
- Incident escalation
- Logging
- Credential protection
- Data protection
- Emergency access
13. Security Awareness Schedule
Establish an appropriate schedule.
| Activity | Frequency | Audience | Owner |
|---|---|---|---|
| New-joiner awareness | At onboarding | New personnel | HR/Security |
| General awareness | Periodic | All personnel | Security |
| Role-based training | Risk-based | Relevant personnel | Functional Owner |
| Privileged-user training | Risk-based | Privileged users | Security/IT |
| Phishing awareness | Periodic | Relevant personnel | Security |
| Security campaigns | Periodic | All/relevant personnel | Security |
| Refresher training | Risk-based | Personnel | Security |
The organization should adjust frequency based on risk rather than relying only on an annual training cycle.
14. Annual Security Training
At an appropriate interval, the organization may provide refresher training covering:
☐ Security responsibilities
☐ Phishing
☐ Social engineering
☐ Password/MFA
☐ Incident reporting
☐ Information classification
☐ Data protection
☐ Remote working
☐ Cloud/SaaS
☐ AI security
☐ Physical security
☐ Recent security incidents
☐ Lessons learned
15. Security Awareness Campaigns
Security awareness can be reinforced through:
- Security newsletters
- Email alerts
- Posters
- Short videos
- Team briefings
- Security tips
- Threat alerts
- Security campaigns
- Lessons learned
- Knowledge quizzes
Campaigns should focus on relevant risks and avoid unnecessary communication overload.
16. Phishing Awareness
The organization shall provide awareness regarding:
- Suspicious emails
- Malicious links
- Unexpected attachments
- Fake login pages
- Credential requests
- Executive impersonation
- Supplier impersonation
- Payment fraud
- Social engineering
- Malicious QR codes
Personnel shall know how to report suspected phishing.
17. Phishing Simulation
Where appropriate, authorized phishing simulations may be performed.
Before the simulation:
☐ Objective defined
☐ Scope defined
☐ Authorization obtained
☐ Target population identified
☐ Privacy considerations assessed
☐ Reporting mechanism defined
☐ Results-handling process defined
After the simulation:
☐ Results reviewed
☐ Trends identified
☐ Targeted education provided where appropriate
☐ Improvement actions recorded
The purpose should primarily be learning and improving resilience.
18. AI and Generative AI Training
Personnel using AI tools shall receive appropriate awareness regarding:
☐ Approved AI tools
☐ Confidential-data restrictions
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ Source-code restrictions
☐ Prompt security
☐ Data retention
☐ AI-generated content verification
☐ Intellectual-property considerations
☐ AI-related threats
☐ Security incident reporting
Sensitive information shall not be submitted to unauthorized AI services.
19. Cloud Security Training
Personnel responsible for cloud environments should receive training appropriate to their responsibilities.
For AWS environments this may include:
- IAM
- MFA
- Least privilege
- IAM roles
- Access keys
- Root-account protection
- CloudTrail
- Security logging
- Encryption
- Secrets
- Network security
- Production access
- Secure configuration
20. Secure Development Training
Development personnel should receive training appropriate to their responsibilities.
Topics may include:
☐ Secure coding
☐ Input validation
☐ Authentication
☐ Authorization
☐ Session management
☐ Cryptography
☐ Secrets
☐ Dependency security
☐ Vulnerability management
☐ Security testing
☐ Secure code review
☐ Production security
21. Incident Response Training
Personnel responsible for security incidents shall understand:
- Incident identification
- Initial response
- Escalation
- Evidence preservation
- Communication
- Containment
- Recovery
- Documentation
- Lessons learned
Exercises may be used to validate practical readiness.
22. Security Training Delivery Methods
Training may be delivered through:
☐ Instructor-led training
☐ Online courses
☐ Learning-management system
☐ Workshops
☐ Webinars
☐ Security briefings
☐ Videos
☐ Quizzes
☐ Simulations
☐ Tabletop exercises
☐ Practical demonstrations
☐ Security campaigns
The method should be appropriate to the training objective.
23. Training Content Approval
Security training content shall be reviewed before use where appropriate.
Verify:
☐ Content is accurate
☐ Content is relevant
☐ Content reflects current policies
☐ Technical information is current
☐ Regulatory requirements are considered
☐ Customer requirements are considered
☐ Security examples are appropriate
☐ Content owner identified
☐ Review date defined
24. Training Assignment
Training assignments should identify:
- Personnel
- Role
- Training course
- Due date
- Priority
- Completion requirement
Training Assignment Register
| Personnel | Role | Course | Assigned | Due | Status |
|---|---|---|---|---|---|
25. Training Completion
For each required course:
☐ Assigned
☐ Personnel notified
☐ Completed
☐ Assessment completed where required
☐ Result recorded
☐ Evidence retained
26. Training Assessment
Where appropriate, training effectiveness may be assessed through:
☐ Quiz
☐ Knowledge test
☐ Practical exercise
☐ Phishing simulation
☐ Tabletop exercise
☐ Interview
☐ Observation
☐ Incident-reporting test
☐ Audit sampling
Completion alone should not automatically be treated as evidence of effective learning.
27. Failed Training Assessment
If personnel do not achieve the required result:
☐ Result recorded
☐ Additional training assigned
☐ Retest performed
☐ Manager notified where appropriate
☐ Security notified where appropriate
☐ Additional support provided
☐ High-risk access reviewed where necessary
28. Overdue Training
Monitor overdue training.
| Personnel | Training | Due Date | Days Overdue | Manager | Action |
|---|---|---|---|---|---|
Escalation may include:
- Reminder
- Manager notification
- Security notification
- Additional corrective action
- Access restriction where justified by risk
29. Training Exceptions
Where training cannot be completed:
☐ Exception requested
☐ Reason documented
☐ Risk assessed
☐ Compensating control defined
☐ Manager approval
☐ Security approval where required
☐ New completion date defined
☐ Exception monitored
Exceptions should not become indefinite waivers.
30. Training During Role Changes
When personnel change roles:
☐ New responsibilities assessed
☐ Training requirements reassessed
☐ Previous training reviewed
☐ New role-specific training assigned
☐ Privileged-user training assigned where required
☐ Cloud training assigned where required
☐ Security responsibilities updated
☐ Completion recorded
31. Contractor and Third-Party Training
Where relevant, third-party personnel shall receive or acknowledge security requirements.
Consider:
☐ Confidentiality
☐ Information handling
☐ Access control
☐ Incident reporting
☐ Customer requirements
☐ Security testing restrictions
☐ Cloud security
☐ Data protection
☐ Acceptable use
Supplier contracts should define applicable responsibilities.
32. Security Awareness Communications
Security communications may be issued when:
☐ New threat identified
☐ Security incident occurs
☐ Major vulnerability identified
☐ Policy changes
☐ New technology introduced
☐ New AI tool introduced
☐ Regulatory requirement changes
☐ Customer requirement changes
☐ Phishing activity increases
33. Incident-Based Training
Following a significant security incident:
- Identify human-related contributing factors.
- Determine whether training contributed to the issue.
- Identify affected personnel/groups.
- Provide targeted awareness.
- Update training content where necessary.
- Test understanding.
- Record corrective actions.
- Monitor for recurrence.
34. Audit-Finding-Based Training
Where an audit identifies a personnel-related weakness:
☐ Finding reviewed
☐ Training requirement assessed
☐ Root cause considered
☐ Training assigned where appropriate
☐ Corrective action recorded
☐ Effectiveness assessed
☐ Finding closure evidence retained
Training should not be used as a substitute for technical or process controls when the root cause requires a control change.
35. Training Records
Maintain appropriate evidence such as:
☐ Course name
☐ Training date
☐ Personnel name/identifier
☐ Role
☐ Completion status
☐ Assessment result
☐ Trainer/provider
☐ Training version
☐ Exceptions
☐ Retest results
36. Training Record Protection
Training records shall be protected against:
- Unauthorized access
- Unauthorized modification
- Unauthorized disclosure
- Accidental loss
Access shall be limited to personnel with a legitimate business need.
37. Training Record Retention
Define appropriate retention based on:
- Legal requirements
- Regulatory requirements
- Customer requirements
- Employment requirements
- Audit requirements
- Organizational policy
Do not retain personnel information longer than necessary.
38. Training Effectiveness
The program owner shall periodically evaluate whether training is effective.
Consider:
☐ Completion rates
☐ Assessment scores
☐ Phishing results
☐ Incident trends
☐ Security violations
☐ Audit findings
☐ Repeat failures
☐ Employee feedback
☐ Security behavior
☐ Emerging threats
39. Security Awareness Metrics
Possible metrics include:
| Metric | Target | Actual | Trend |
|---|---|---|---|
| Training completion | |||
| Overdue training | |||
| Phishing reporting | |||
| Phishing failure rate | |||
| Assessment pass rate | |||
| Role-based training | |||
| Privileged-user training | |||
| Security incidents |
Metrics should be interpreted in context rather than treated as security performance by themselves.
40. Training Program Review
Review the training program periodically.
Review:
☐ Training content
☐ Target audience
☐ Training frequency
☐ Completion rates
☐ Effectiveness
☐ Threat environment
☐ Security incidents
☐ Audit findings
☐ Technology changes
☐ Regulatory requirements
☐ Customer requirements
41. Training Content Change
Training content should be updated when:
☐ Security policy changes
☐ New technology introduced
☐ New cloud platform introduced
☐ New AI technology introduced
☐ Significant incident occurs
☐ New threat emerges
☐ Audit identifies weakness
☐ Regulatory requirements change
☐ Customer requirements change
42. Security Awareness and Training Register
Maintain a consolidated register where appropriate.
| Training ID | Topic | Audience | Owner | Frequency | Status | Last Review |
|---|---|---|---|---|---|---|
43. Training Provider Management
Where external providers are used:
☐ Provider identified
☐ Provider competence assessed
☐ Content reviewed
☐ Contract reviewed
☐ Confidentiality requirements addressed
☐ Personal-data handling assessed
☐ Training evidence obtained
☐ Provider performance reviewed
44. Training Tool and Platform Security
For LMS or training platforms:
☐ Approved platform
☐ Access controls
☐ MFA where appropriate
☐ Personnel data protection
☐ Administrator access restricted
☐ Records protected
☐ Data retention defined
☐ Supplier security assessed
45. Management Reporting
The program owner shall provide appropriate reporting to management.
Reports may include:
- Completion
- Overdue training
- Awareness trends
- Phishing results
- Significant failures
- High-risk personnel
- Exceptions
- Incidents
- Corrective actions
- Improvement activities
46. Corrective Actions
Where training weaknesses are identified:
☐ Root cause assessed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Training updated
☐ Additional training delivered
☐ Effectiveness tested
☐ Residual risk assessed
☐ Action closed after verification
47. Security Awareness During Business Disruption
Critical personnel shall remain aware of security requirements during:
- Disaster recovery
- Major outages
- Cyber incidents
- Emergency changes
- Remote operations
- Crisis management
Emergency training or briefings may be conducted where necessary.
48. Evidence and Audit Trail
The organization should be able to demonstrate:
Requirement → Training Need → Assignment → Delivery → Completion → Assessment → Effectiveness → Corrective Action
Evidence should be proportionate to risk and should not contain unnecessary sensitive information.
49. AWS SaaS Startup Example
An AWS SaaS startup has 30 employees.
General Training
All employees receive:
- Phishing awareness
- MFA
- Password security
- Incident reporting
- Information classification
- Remote working
- AI security
Developers
Receive:
- Secure coding
- Secrets management
- Dependency security
- Source-code security
DevOps
Receive:
- AWS IAM
- Privileged access
- Cloud security
- Production security
- Logging
- Secrets management
Finance
Receive:
- Business email compromise
- Payment fraud
- Supplier impersonation
Customer Support
Receive:
- Customer-data protection
- Identity verification
- Secure information sharing
Evidence
The startup can demonstrate:
Training Requirement → Assignment → Completion → Assessment → Security Behavior → Review
50. Startup-Friendly Training Model
A small startup can operate the following model:
New Joiner
Security Orientation → Policy Review → Training → Acknowledgement
Monthly
Security Tip / Threat Alert
Quarterly
Focused Security Awareness Campaign
Annually
Security Refresher + Effectiveness Assessment
After Incidents
Lessons Learned → Targeted Training → Verification
High-Risk Roles
Add:
- Role-specific training
- Privileged-user training
- Technical security training
- Periodic assessment
51. Common Mistakes
Avoid:
- Treating annual training as the entire awareness program.
- Training everyone identically.
- Measuring only completion.
- Ignoring contractors.
- Ignoring privileged users.
- Giving sensitive access before required training without risk assessment.
- Failing to train new joiners.
- Failing to update training after incidents.
- Using training as the only response to technical security weaknesses.
- Ignoring AI security.
- Failing to track overdue training.
- Keeping excessive personnel information in training records.
- Not testing whether personnel actually understand requirements.
- Failing to record corrective actions.
- Allowing training exceptions to remain open indefinitely.
52. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness requirements |
| Information Security Policy | Establishes overall security expectations |
| Security Awareness and Training Register | Tracks training |
| Employee Onboarding Checklist | Introduces new personnel to security |
| Employee Role Change Checklist | Identifies new training needs |
| Employee Security Acknowledgement | Records policy communication |
| Employee Security Responsibilities | Defines personnel obligations |
| Phishing Awareness Procedure | Supports phishing awareness |
| Incident Management Procedure | Provides incident-related training requirements |
| Access Management Procedure | Defines access responsibilities |
| Cloud Security Policy | Defines cloud-security training needs |
| Secure Development Procedure | Defines developer training needs |
| AI Security Policy | Defines AI awareness requirements |
| Personnel Security Audit Checklist | Tests whether training controls operate |
53. ISO/IEC 27001 Connection
Security awareness and training supports the organization’s risk-based management of personnel security, information-security responsibilities, awareness, competence, access, information protection, and operational security.
The Security Awareness and Training Procedure is not itself a universally prescribed ISO/IEC 27001 document or mandatory template.
The organization should determine training content, frequency, audience, evidence, and effectiveness requirements based on:
- ISMS scope
- Risk assessment
- Statement of Applicability
- Personnel responsibilities
- Information and systems accessed
- Legal/regulatory requirements
- Customer requirements
- Contractual requirements
- Security incidents
- Audit findings
- Threat environment
The key audit objective is not simply to show that training was delivered. The organization should be able to demonstrate that personnel received appropriate awareness and training and that the organization evaluates whether it is effective.
54. Audit Evidence Checklist
☐ Approved awareness policy
☐ Training procedure
☐ Training needs assessment
☐ Training plan
☐ Training schedule
☐ Training materials
☐ Training assignments
☐ Completion records
☐ Assessment results
☐ Phishing simulation results where applicable
☐ Role-based training records
☐ Privileged-user training records
☐ Training exceptions
☐ Awareness communications
☐ Effectiveness assessments
☐ Training metrics
☐ Corrective actions
☐ Management reporting
55. Procedure Review
This procedure shall be reviewed periodically and when significant changes occur.
Review triggers include:
☐ Major security incident
☐ Significant audit finding
☐ New technology
☐ New cloud service
☐ New AI technology
☐ Regulatory change
☐ Customer requirement change
☐ Organizational change
☐ Significant change in threat environment
☐ Changes to the ISMS
Procedure Owner
Name/Role: ______________________________
Approved By
Name/Role: ______________________________
Approval Date
Next Review Date
56. Final Security Awareness and Training Audit Trail
For significant training requirements, the organization should be able to demonstrate:
What security knowledge is required?
Who requires it?
Why does the person require it?
Was the training assigned?
Was the training completed?
Was understanding or effectiveness assessed?
What happened when training was overdue or unsuccessful?
Was additional training provided after incidents or audit findings?
How are role changes reflected in training requirements?
How does management know whether the awareness program is effective?
Final Principle
Security awareness and training is not a checkbox exercise. The objective is to ensure that people understand the security risks associated with their roles, know what is expected of them, can recognize and report threats, and demonstrate through appropriate evidence that the organization continually improves security awareness.
