A.6.3
Information security awareness, education and training
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Ensure personnel and relevant parties receive appropriate information security awareness, education, and training.
Points of focus
- Deliver general security awareness to all personnel at onboarding and on a recurring cadence
- Layer role-based training for engineering, support, and privileged-access roles beyond the general track
- Track individual completion with dates, not just that a session occurred
- Refresh content when incidents, new tooling, or policy changes make the existing material stale
Implementation notes
Run two tracks. General awareness covers phishing recognition, acceptable use, data classification basics, and how to report a suspected incident — assign it at onboarding within a defined window (commonly 30 days) and refresh annually. Role-based training goes further: secure coding and dependency hygiene for engineers, PII handling and support-tooling scope for customer-facing staff, and privileged-access procedures for anyone with production or admin rights. Use an LMS or training platform that timestamps completion per person rather than tracking attendance at a live session, since auditors sample individual records, not attendance sheets. Run periodic phishing simulations and route repeat clickers into targeted follow-up rather than treating the simulation as a one-time exercise. Update content after material incidents or when new tooling changes what "safe" looks like — training that hasn't changed in three years despite a platform migration reads as stale to an assessor.
Audit tip: Pull a random sample of five to eight employees across different roles and show completion dates for both the general track and any role-specific module. Gaps between hire date and first completed training are a routine finding.
Evidence auditors typically request:
- LMS or training-platform completion report by employee, course, and date
- Role-based curriculum showing distinct content for engineering, support, and general staff
- Phishing simulation results with click rates and follow-up training for repeat clicks
- Onboarding checklist showing security training assigned within a defined window of start date
Common gaps
- Engineers complete the same generic annual training as sales, with no secure coding, secrets handling, or SDLC-specific content
- Training assignment records exist, but completion status was never pulled to confirm anyone actually finished the course
- New hires start production work before the onboarding security module is even assigned
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.3 | This control |
| HIPAA | 164.308(a)(5) | 164.308(a)(5) requires a security awareness and training program for the workforce, including periodic reminders and protection-from-malicious-software training — largely parallel to A.6.3 but scoped specifically to ePHI-handling staff. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.3)