ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Security Awareness and Training Procedure

Security Awareness and Training Procedure

1. Purpose

The Security Awareness and Training Procedure defines how the organization plans, delivers, records, evaluates, and improves information-security awareness and training.

The procedure ensures that personnel receive security knowledge appropriate to their:

  • Role
  • Responsibilities
  • Information access
  • System access
  • Privilege level
  • Business activities
  • Security risk

The procedure applies throughout the personnel lifecycle.

Core Principle

Identify Training Need → Plan → Assign → Deliver → Assess → Record → Monitor → Improve


2. Scope

This procedure applies to:

☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary personnel
☐ Remote workers
☐ Third-party personnel where applicable
☐ Privileged users
☐ Security personnel
☐ Personnel with production access
☐ Personnel handling customer or restricted information


3. Training and Awareness Information

FieldDetails
Program Owner
Training Period
Training Year
Applicable Personnel
Business Units
Training Platform
Security Owner
HR Owner
Review Date

4. Objectives

The security awareness and training program shall aim to:

  • Communicate security responsibilities
  • Improve security knowledge
  • Reduce human-related security risks
  • Improve threat recognition
  • Improve incident reporting
  • Support secure use of systems
  • Protect organizational information
  • Protect customer information
  • Support privacy requirements
  • Support compliance requirements
  • Provide role-specific security knowledge
  • Evaluate awareness effectiveness

5. Roles and Responsibilities

5.1 Management

Management shall:

  • Support the program
  • Provide appropriate resources
  • Review significant training risks
  • Support corrective actions

5.2 Information Security

Information Security shall:

  • Define security training requirements
  • Identify security awareness risks
  • Develop or approve security content
  • Monitor completion
  • Evaluate effectiveness
  • Maintain security awareness metrics
  • Report significant issues

5.3 HR

HR shall:

  • Integrate training into onboarding
  • Maintain applicable personnel training records
  • Support training scheduling
  • Coordinate with managers
  • Support role-change requirements

5.4 Managers

Managers shall:

  • Ensure personnel complete required training
  • Identify role-specific training needs
  • Support training attendance
  • Address overdue training
  • Escalate repeated non-compliance

5.5 IT

IT may support:

  • Technical-security training
  • Phishing awareness
  • MFA awareness
  • Device security
  • Cloud-security awareness

5.6 Personnel

Personnel shall:

  • Complete assigned training
  • Participate in required awareness activities
  • Apply security requirements
  • Report security concerns
  • Ask questions where requirements are unclear

6. Training Needs Assessment

Before establishing the training plan, identify applicable requirements.

Consider:

☐ Job responsibilities
☐ Information handled
☐ System access
☐ Privileged access
☐ Production access
☐ Customer information
☐ Personal data
☐ Regulatory responsibilities
☐ Security responsibilities
☐ Previous incidents
☐ Audit findings
☐ Emerging threats
☐ Technology changes
☐ Customer requirements


7. Training Categories

The organization may classify training into:

Level 1 — General Awareness

For all personnel.

Level 2 — Role-Based Training

For personnel with specific security responsibilities.

Level 3 — Specialized Technical Training

For technical or security-sensitive personnel.

Level 4 — Privileged / High-Risk Training

For personnel with significant administrative, production, security, or sensitive-data access.


8. General Security Awareness

General awareness may cover:

☐ Information security policy
☐ Acceptable use
☐ Password security
☐ MFA
☐ Phishing
☐ Social engineering
☐ Malware
☐ Ransomware
☐ Incident reporting
☐ Information classification
☐ Data protection
☐ Remote working
☐ Device security
☐ Physical security
☐ Cloud/SaaS security
☐ AI and generative AI


9. New Joiner Training

Security training shall be incorporated into employee onboarding.

Before or shortly after access is granted, as appropriate to risk:

☐ Security responsibilities communicated
☐ Information-security policies provided
☐ Confidentiality requirements communicated
☐ Acceptable-use requirements communicated
☐ Incident-reporting process explained
☐ MFA requirements explained
☐ Information classification explained
☐ Required security training assigned
☐ Completion recorded

Higher-risk access may require training before access is granted.


10. Role-Based Training

Training shall be tailored where the employee’s role creates additional security responsibilities.

Developers

Possible topics:

  • Secure coding
  • OWASP risks
  • Dependency management
  • Secrets management
  • Source-code protection
  • Secure code review
  • Vulnerability remediation
  • Secure deployment

DevOps / Cloud

Possible topics:

  • IAM
  • MFA
  • Privileged access
  • AWS/cloud security
  • Logging
  • Infrastructure security
  • Secrets management
  • Production security

Security Personnel

Possible topics:

  • Incident response
  • Threat detection
  • Vulnerability management
  • Security testing
  • Evidence handling
  • Security monitoring

Finance

Possible topics:

  • Business email compromise
  • Payment fraud
  • Phishing
  • Financial information protection
  • Supplier impersonation

HR

Possible topics:

  • Employee personal data
  • Confidential information
  • Access control
  • Privacy
  • Phishing

11. Privileged User Training

Personnel with privileged access should receive enhanced training appropriate to their responsibilities.

Topics may include:

☐ Privileged access
☐ Least privilege
☐ MFA
☐ Administrative accounts
☐ Secure administration
☐ Cloud security
☐ Production security
☐ Logging and monitoring
☐ Secrets management
☐ Incident reporting
☐ Emergency access


12. Production Access Training

Personnel with production access shall understand:

  • Production security requirements
  • Approved access methods
  • Change management
  • Deployment requirements
  • Incident escalation
  • Logging
  • Credential protection
  • Data protection
  • Emergency access

13. Security Awareness Schedule

Establish an appropriate schedule.

ActivityFrequencyAudienceOwner
New-joiner awarenessAt onboardingNew personnelHR/Security
General awarenessPeriodicAll personnelSecurity
Role-based trainingRisk-basedRelevant personnelFunctional Owner
Privileged-user trainingRisk-basedPrivileged usersSecurity/IT
Phishing awarenessPeriodicRelevant personnelSecurity
Security campaignsPeriodicAll/relevant personnelSecurity
Refresher trainingRisk-basedPersonnelSecurity

The organization should adjust frequency based on risk rather than relying only on an annual training cycle.


14. Annual Security Training

At an appropriate interval, the organization may provide refresher training covering:

☐ Security responsibilities
☐ Phishing
☐ Social engineering
☐ Password/MFA
☐ Incident reporting
☐ Information classification
☐ Data protection
☐ Remote working
☐ Cloud/SaaS
☐ AI security
☐ Physical security
☐ Recent security incidents
☐ Lessons learned


15. Security Awareness Campaigns

Security awareness can be reinforced through:

  • Security newsletters
  • Email alerts
  • Posters
  • Short videos
  • Team briefings
  • Security tips
  • Threat alerts
  • Security campaigns
  • Lessons learned
  • Knowledge quizzes

Campaigns should focus on relevant risks and avoid unnecessary communication overload.


16. Phishing Awareness

The organization shall provide awareness regarding:

  • Suspicious emails
  • Malicious links
  • Unexpected attachments
  • Fake login pages
  • Credential requests
  • Executive impersonation
  • Supplier impersonation
  • Payment fraud
  • Social engineering
  • Malicious QR codes

Personnel shall know how to report suspected phishing.


17. Phishing Simulation

Where appropriate, authorized phishing simulations may be performed.

Before the simulation:

☐ Objective defined
☐ Scope defined
☐ Authorization obtained
☐ Target population identified
☐ Privacy considerations assessed
☐ Reporting mechanism defined
☐ Results-handling process defined

After the simulation:

☐ Results reviewed
☐ Trends identified
☐ Targeted education provided where appropriate
☐ Improvement actions recorded

The purpose should primarily be learning and improving resilience.


18. AI and Generative AI Training

Personnel using AI tools shall receive appropriate awareness regarding:

☐ Approved AI tools
☐ Confidential-data restrictions
☐ Customer-data restrictions
☐ Personal-data restrictions
☐ Source-code restrictions
☐ Prompt security
☐ Data retention
☐ AI-generated content verification
☐ Intellectual-property considerations
☐ AI-related threats
☐ Security incident reporting

Sensitive information shall not be submitted to unauthorized AI services.


19. Cloud Security Training

Personnel responsible for cloud environments should receive training appropriate to their responsibilities.

For AWS environments this may include:

  • IAM
  • MFA
  • Least privilege
  • IAM roles
  • Access keys
  • Root-account protection
  • CloudTrail
  • Security logging
  • Encryption
  • Secrets
  • Network security
  • Production access
  • Secure configuration

20. Secure Development Training

Development personnel should receive training appropriate to their responsibilities.

Topics may include:

☐ Secure coding
☐ Input validation
☐ Authentication
☐ Authorization
☐ Session management
☐ Cryptography
☐ Secrets
☐ Dependency security
☐ Vulnerability management
☐ Security testing
☐ Secure code review
☐ Production security


21. Incident Response Training

Personnel responsible for security incidents shall understand:

  • Incident identification
  • Initial response
  • Escalation
  • Evidence preservation
  • Communication
  • Containment
  • Recovery
  • Documentation
  • Lessons learned

Exercises may be used to validate practical readiness.


22. Security Training Delivery Methods

Training may be delivered through:

☐ Instructor-led training
☐ Online courses
☐ Learning-management system
☐ Workshops
☐ Webinars
☐ Security briefings
☐ Videos
☐ Quizzes
☐ Simulations
☐ Tabletop exercises
☐ Practical demonstrations
☐ Security campaigns

The method should be appropriate to the training objective.


23. Training Content Approval

Security training content shall be reviewed before use where appropriate.

Verify:

☐ Content is accurate
☐ Content is relevant
☐ Content reflects current policies
☐ Technical information is current
☐ Regulatory requirements are considered
☐ Customer requirements are considered
☐ Security examples are appropriate
☐ Content owner identified
☐ Review date defined


24. Training Assignment

Training assignments should identify:

  • Personnel
  • Role
  • Training course
  • Due date
  • Priority
  • Completion requirement

Training Assignment Register

PersonnelRoleCourseAssignedDueStatus

25. Training Completion

For each required course:

☐ Assigned
☐ Personnel notified
☐ Completed
☐ Assessment completed where required
☐ Result recorded
☐ Evidence retained


26. Training Assessment

Where appropriate, training effectiveness may be assessed through:

☐ Quiz
☐ Knowledge test
☐ Practical exercise
☐ Phishing simulation
☐ Tabletop exercise
☐ Interview
☐ Observation
☐ Incident-reporting test
☐ Audit sampling

Completion alone should not automatically be treated as evidence of effective learning.


27. Failed Training Assessment

If personnel do not achieve the required result:

☐ Result recorded
☐ Additional training assigned
☐ Retest performed
☐ Manager notified where appropriate
☐ Security notified where appropriate
☐ Additional support provided
☐ High-risk access reviewed where necessary


28. Overdue Training

Monitor overdue training.

PersonnelTrainingDue DateDays OverdueManagerAction

Escalation may include:

  1. Reminder
  2. Manager notification
  3. Security notification
  4. Additional corrective action
  5. Access restriction where justified by risk

29. Training Exceptions

Where training cannot be completed:

☐ Exception requested
☐ Reason documented
☐ Risk assessed
☐ Compensating control defined
☐ Manager approval
☐ Security approval where required
☐ New completion date defined
☐ Exception monitored

Exceptions should not become indefinite waivers.


30. Training During Role Changes

When personnel change roles:

☐ New responsibilities assessed
☐ Training requirements reassessed
☐ Previous training reviewed
☐ New role-specific training assigned
☐ Privileged-user training assigned where required
☐ Cloud training assigned where required
☐ Security responsibilities updated
☐ Completion recorded


31. Contractor and Third-Party Training

Where relevant, third-party personnel shall receive or acknowledge security requirements.

Consider:

☐ Confidentiality
☐ Information handling
☐ Access control
☐ Incident reporting
☐ Customer requirements
☐ Security testing restrictions
☐ Cloud security
☐ Data protection
☐ Acceptable use

Supplier contracts should define applicable responsibilities.


32. Security Awareness Communications

Security communications may be issued when:

☐ New threat identified
☐ Security incident occurs
☐ Major vulnerability identified
☐ Policy changes
☐ New technology introduced
☐ New AI tool introduced
☐ Regulatory requirement changes
☐ Customer requirement changes
☐ Phishing activity increases


33. Incident-Based Training

Following a significant security incident:

  1. Identify human-related contributing factors.
  2. Determine whether training contributed to the issue.
  3. Identify affected personnel/groups.
  4. Provide targeted awareness.
  5. Update training content where necessary.
  6. Test understanding.
  7. Record corrective actions.
  8. Monitor for recurrence.

34. Audit-Finding-Based Training

Where an audit identifies a personnel-related weakness:

☐ Finding reviewed
☐ Training requirement assessed
☐ Root cause considered
☐ Training assigned where appropriate
☐ Corrective action recorded
☐ Effectiveness assessed
☐ Finding closure evidence retained

Training should not be used as a substitute for technical or process controls when the root cause requires a control change.


35. Training Records

Maintain appropriate evidence such as:

☐ Course name
☐ Training date
☐ Personnel name/identifier
☐ Role
☐ Completion status
☐ Assessment result
☐ Trainer/provider
☐ Training version
☐ Exceptions
☐ Retest results


36. Training Record Protection

Training records shall be protected against:

  • Unauthorized access
  • Unauthorized modification
  • Unauthorized disclosure
  • Accidental loss

Access shall be limited to personnel with a legitimate business need.


37. Training Record Retention

Define appropriate retention based on:

  • Legal requirements
  • Regulatory requirements
  • Customer requirements
  • Employment requirements
  • Audit requirements
  • Organizational policy

Do not retain personnel information longer than necessary.


38. Training Effectiveness

The program owner shall periodically evaluate whether training is effective.

Consider:

☐ Completion rates
☐ Assessment scores
☐ Phishing results
☐ Incident trends
☐ Security violations
☐ Audit findings
☐ Repeat failures
☐ Employee feedback
☐ Security behavior
☐ Emerging threats


39. Security Awareness Metrics

Possible metrics include:

MetricTargetActualTrend
Training completion
Overdue training
Phishing reporting
Phishing failure rate
Assessment pass rate
Role-based training
Privileged-user training
Security incidents

Metrics should be interpreted in context rather than treated as security performance by themselves.


40. Training Program Review

Review the training program periodically.

Review:

☐ Training content
☐ Target audience
☐ Training frequency
☐ Completion rates
☐ Effectiveness
☐ Threat environment
☐ Security incidents
☐ Audit findings
☐ Technology changes
☐ Regulatory requirements
☐ Customer requirements


41. Training Content Change

Training content should be updated when:

☐ Security policy changes
☐ New technology introduced
☐ New cloud platform introduced
☐ New AI technology introduced
☐ Significant incident occurs
☐ New threat emerges
☐ Audit identifies weakness
☐ Regulatory requirements change
☐ Customer requirements change


42. Security Awareness and Training Register

Maintain a consolidated register where appropriate.

Training IDTopicAudienceOwnerFrequencyStatusLast Review

43. Training Provider Management

Where external providers are used:

☐ Provider identified
☐ Provider competence assessed
☐ Content reviewed
☐ Contract reviewed
☐ Confidentiality requirements addressed
☐ Personal-data handling assessed
☐ Training evidence obtained
☐ Provider performance reviewed


44. Training Tool and Platform Security

For LMS or training platforms:

☐ Approved platform
☐ Access controls
☐ MFA where appropriate
☐ Personnel data protection
☐ Administrator access restricted
☐ Records protected
☐ Data retention defined
☐ Supplier security assessed


45. Management Reporting

The program owner shall provide appropriate reporting to management.

Reports may include:

  • Completion
  • Overdue training
  • Awareness trends
  • Phishing results
  • Significant failures
  • High-risk personnel
  • Exceptions
  • Incidents
  • Corrective actions
  • Improvement activities

46. Corrective Actions

Where training weaknesses are identified:

☐ Root cause assessed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Training updated
☐ Additional training delivered
☐ Effectiveness tested
☐ Residual risk assessed
☐ Action closed after verification


47. Security Awareness During Business Disruption

Critical personnel shall remain aware of security requirements during:

  • Disaster recovery
  • Major outages
  • Cyber incidents
  • Emergency changes
  • Remote operations
  • Crisis management

Emergency training or briefings may be conducted where necessary.


48. Evidence and Audit Trail

The organization should be able to demonstrate:

Requirement → Training Need → Assignment → Delivery → Completion → Assessment → Effectiveness → Corrective Action

Evidence should be proportionate to risk and should not contain unnecessary sensitive information.


49. AWS SaaS Startup Example

An AWS SaaS startup has 30 employees.

General Training

All employees receive:

  • Phishing awareness
  • MFA
  • Password security
  • Incident reporting
  • Information classification
  • Remote working
  • AI security

Developers

Receive:

  • Secure coding
  • Secrets management
  • Dependency security
  • Source-code security

DevOps

Receive:

  • AWS IAM
  • Privileged access
  • Cloud security
  • Production security
  • Logging
  • Secrets management

Finance

Receive:

  • Business email compromise
  • Payment fraud
  • Supplier impersonation

Customer Support

Receive:

  • Customer-data protection
  • Identity verification
  • Secure information sharing

Evidence

The startup can demonstrate:

Training Requirement → Assignment → Completion → Assessment → Security Behavior → Review


50. Startup-Friendly Training Model

A small startup can operate the following model:

New Joiner

Security Orientation → Policy Review → Training → Acknowledgement

Monthly

Security Tip / Threat Alert

Quarterly

Focused Security Awareness Campaign

Annually

Security Refresher + Effectiveness Assessment

After Incidents

Lessons Learned → Targeted Training → Verification

High-Risk Roles

Add:

  • Role-specific training
  • Privileged-user training
  • Technical security training
  • Periodic assessment

51. Common Mistakes

Avoid:

  • Treating annual training as the entire awareness program.
  • Training everyone identically.
  • Measuring only completion.
  • Ignoring contractors.
  • Ignoring privileged users.
  • Giving sensitive access before required training without risk assessment.
  • Failing to train new joiners.
  • Failing to update training after incidents.
  • Using training as the only response to technical security weaknesses.
  • Ignoring AI security.
  • Failing to track overdue training.
  • Keeping excessive personnel information in training records.
  • Not testing whether personnel actually understand requirements.
  • Failing to record corrective actions.
  • Allowing training exceptions to remain open indefinitely.

52. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness requirements
Information Security PolicyEstablishes overall security expectations
Security Awareness and Training RegisterTracks training
Employee Onboarding ChecklistIntroduces new personnel to security
Employee Role Change ChecklistIdentifies new training needs
Employee Security AcknowledgementRecords policy communication
Employee Security ResponsibilitiesDefines personnel obligations
Phishing Awareness ProcedureSupports phishing awareness
Incident Management ProcedureProvides incident-related training requirements
Access Management ProcedureDefines access responsibilities
Cloud Security PolicyDefines cloud-security training needs
Secure Development ProcedureDefines developer training needs
AI Security PolicyDefines AI awareness requirements
Personnel Security Audit ChecklistTests whether training controls operate

53. ISO/IEC 27001 Connection

Security awareness and training supports the organization’s risk-based management of personnel security, information-security responsibilities, awareness, competence, access, information protection, and operational security.

The Security Awareness and Training Procedure is not itself a universally prescribed ISO/IEC 27001 document or mandatory template.

The organization should determine training content, frequency, audience, evidence, and effectiveness requirements based on:

  • ISMS scope
  • Risk assessment
  • Statement of Applicability
  • Personnel responsibilities
  • Information and systems accessed
  • Legal/regulatory requirements
  • Customer requirements
  • Contractual requirements
  • Security incidents
  • Audit findings
  • Threat environment

The key audit objective is not simply to show that training was delivered. The organization should be able to demonstrate that personnel received appropriate awareness and training and that the organization evaluates whether it is effective.


54. Audit Evidence Checklist

☐ Approved awareness policy
☐ Training procedure
☐ Training needs assessment
☐ Training plan
☐ Training schedule
☐ Training materials
☐ Training assignments
☐ Completion records
☐ Assessment results
☐ Phishing simulation results where applicable
☐ Role-based training records
☐ Privileged-user training records
☐ Training exceptions
☐ Awareness communications
☐ Effectiveness assessments
☐ Training metrics
☐ Corrective actions
☐ Management reporting


55. Procedure Review

This procedure shall be reviewed periodically and when significant changes occur.

Review triggers include:

☐ Major security incident
☐ Significant audit finding
☐ New technology
☐ New cloud service
☐ New AI technology
☐ Regulatory change
☐ Customer requirement change
☐ Organizational change
☐ Significant change in threat environment
☐ Changes to the ISMS

Procedure Owner

Name/Role: ______________________________

Approved By

Name/Role: ______________________________

Approval Date


Next Review Date



56. Final Security Awareness and Training Audit Trail

For significant training requirements, the organization should be able to demonstrate:

What security knowledge is required?
Who requires it?
Why does the person require it?
Was the training assigned?
Was the training completed?
Was understanding or effectiveness assessed?
What happened when training was overdue or unsuccessful?
Was additional training provided after incidents or audit findings?
How are role changes reflected in training requirements?
How does management know whether the awareness program is effective?

Final Principle

Security awareness and training is not a checkbox exercise. The objective is to ensure that people understand the security risks associated with their roles, know what is expected of them, can recognize and report threats, and demonstrate through appropriate evidence that the organization continually improves security awareness.