Skip to content
compliancebase
ISO 27001A.6 — Information security awareness, education and training

A.6.3

Information security awareness, education and training

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Ensure personnel and relevant parties receive appropriate information security awareness, education, and training.

Points of focus

  • Deliver general security awareness to all personnel at onboarding and on a recurring cadence
  • Layer role-based training for engineering, support, and privileged-access roles beyond the general track
  • Track individual completion with dates, not just that a session occurred
  • Refresh content when incidents, new tooling, or policy changes make the existing material stale

Implementation notes

Run two tracks. General awareness covers phishing recognition, acceptable use, data classification basics, and how to report a suspected incident — assign it at onboarding within a defined window (commonly 30 days) and refresh annually. Role-based training goes further: secure coding and dependency hygiene for engineers, PII handling and support-tooling scope for customer-facing staff, and privileged-access procedures for anyone with production or admin rights. Use an LMS or training platform that timestamps completion per person rather than tracking attendance at a live session, since auditors sample individual records, not attendance sheets. Run periodic phishing simulations and route repeat clickers into targeted follow-up rather than treating the simulation as a one-time exercise. Update content after material incidents or when new tooling changes what "safe" looks like — training that hasn't changed in three years despite a platform migration reads as stale to an assessor.

Audit tip: Pull a random sample of five to eight employees across different roles and show completion dates for both the general track and any role-specific module. Gaps between hire date and first completed training are a routine finding.

Evidence auditors typically request:

  • LMS or training-platform completion report by employee, course, and date
  • Role-based curriculum showing distinct content for engineering, support, and general staff
  • Phishing simulation results with click rates and follow-up training for repeat clicks
  • Onboarding checklist showing security training assigned within a defined window of start date

Common gaps

  • Engineers complete the same generic annual training as sales, with no secure coding, secrets handling, or SDLC-specific content
  • Training assignment records exist, but completion status was never pulled to confirm anyone actually finished the course
  • New hires start production work before the onboarding security module is even assigned

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.3This control
HIPAA164.308(a)(5)164.308(a)(5) requires a security awareness and training program for the workforce, including periodic reminders and protection-from-malicious-software training — largely parallel to A.6.3 but scoped specifically to ePHI-handling staff.

Primary sources

Frequently Asked Questions

It covers general awareness but not the role-based half of A.6.3. Engineers, support staff handling PII, and privileged-access holders need training specific to what their role can affect.

ISO 27001 doesn't set a fixed number of days, but auditors expect training to be assigned and completed before — or very shortly after — a new hire gets meaningful system access. Define your own window and stick to it.

If they can access the same systems or data, yes. A contractor with production access who never completed security awareness training is a common Stage 2 sampling finding.

Click-rate trends over time plus documentation that repeat clickers received targeted follow-up training, not just the raw simulation report showing who clicked once.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above