Security awareness and training policy
Who is trained in what, how often, how it is recorded and how its effect is measured, for staff and for the management body.
How the register reads it
| Also called | awareness programme, security training |
|---|---|
| Family | People |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or NIS2 or ISO 22301 is ticked and no line resolves to it (ISO 27701, ISO 42001 require it too, inside a parent document, so they do not list it separately). |
| Template | Security awareness training policy. |
Which standards require it, and what each expects it to contain
7 requiring clauses, 5 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 7.3named Awareness.
ISO 27001 6.3 Information security awareness, education and trainingGive personnel and relevant parties appropriate, current security training for their role.
What the ISO 27002 guidance expects the document to say: Requires personnel and relevant interested parties to receive appropriate information security awareness, education and training, plus regular updates on the security policy, topic specific policies and procedures relevant to their job function. Supporting SME guidance separates merely informing people from making them aware and from training those holding specific roles, and treats repetition as necessary because objectives, threats and available measures keep changing.
Common gap: Training not aligned to specific job functions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 7.3 AwarenessPersons doing work under the organization's control shall be aware of the privacy policy, of their contribution to the effectiveness of the privacy information management system including the benefits of improved privacy performance, and of the implications of not conforming with the PIMS requirements. The implications the first edition spelled out are carried into the guidance: consequences to the organization, to the person, and to the PII principal of breaching privacy rules, and awareness of how to report an incident involving PII.
Common gap: Awareness limited to annual e-learning that never mentions PII principals or the reporting route
Source: ISO/IEC 27701:2025
ISO/IEC 42001:2023
ISO 42001 A.4.6 Human resourcesThe organization shall document information about the human resources and their competencies utilized.
Common gap: Are dependencies on individual experts identified as key-person risks?
Source: ISO/IEC 42001:2023
ISO 22301:2019
ISO 22301 7.3 AwarenessPeople doing work under the organization's control must be aware of the business continuity policy, of how they contribute to BCMS effectiveness and what better continuity performance delivers, of the implications of not conforming, and of their own role and responsibilities before, during and after a disruption.
Common gap: Awareness content covering the policy only, silent on individual roles during a disruption
Source: ISO 22301:2019
The NIS2 Directive
NIS2 Art. 21(2)(g) Basic cyber hygiene practices and cybersecurity trainingCyber hygiene is the common baseline the Directive expects everywhere: keeping software and hardware updated, managing configuration of devices, controlling and limiting administrator-level accounts, managing new installations, changing credentials, segmenting networks and backing up data. The recitals also point at zero-trust principles and user awareness as part of the same baseline. Training here is the workforce limb, distinct from the management body training in Article 20(2), and it needs to reach the roles that actually handle the risk rather than being one annual module for everyone. The value of this category to an auditor is that it is measurable: patch currency, privileged account counts and training completion are all countable, and a claim of good hygiene that cannot produce those numbers is not evidenced.
Common gap: Hygiene asserted for servers while endpoints, network devices and operational technology are unmeasured
Source: NIS2 Directive
NIS2 Art. 20(2) Train the management body, and offer equivalent training to staff on a regular basisMembers of the management body are required to follow training, and the entity is expected to put comparable training in front of its employees regularly. The stated purpose sets the standard: the training has to leave the body able to identify risks and to assess cybersecurity risk-management practices and the effect those practices have on the services the entity provides. That is a judgement bar, not an attendance bar. Generic awareness content aimed at all staff will not reach it, because a board member is being asked to challenge a risk treatment decision rather than avoid a phishing email. Training also needs refreshing as the body changes; a director appointed after the last session is untrained for the purposes of this Article. The employee limb is expressed as an encouragement on Member States to require, so its national transposition is worth reading, but the entity-level expectation is regular and repeated rather than on induction only.
Common gap: Board members given the same awareness module as all staff
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register