Policy Register

Security awareness and training policy

Who is trained in what, how often, how it is recorded and how its effect is measured, for staff and for the management body.

How the register reads it

Also calledawareness programme, security training
FamilyPeople
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or NIS2 or ISO 22301 is ticked and no line resolves to it (ISO 27701, ISO 42001 require it too, inside a parent document, so they do not list it separately).
TemplateSecurity awareness training policy.

Which standards require it, and what each expects it to contain

7 requiring clauses, 5 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.

ISO/IEC 27001:2022

Named, not quoted: 7.3named Awareness.

ISO 27001 6.3 Information security awareness, education and training

Give personnel and relevant parties appropriate, current security training for their role.

What the ISO 27002 guidance expects the document to say: Requires personnel and relevant interested parties to receive appropriate information security awareness, education and training, plus regular updates on the security policy, topic specific policies and procedures relevant to their job function. Supporting SME guidance separates merely informing people from making them aware and from training those holding specific roles, and treats repetition as necessary because objectives, threats and available measures keep changing.

Evidence an auditor accepts: The awareness and training programme, distinguishing general awareness from role specific training for those with defined security duties; completion records per individual, with coverage measured against the full population including contractors; content evidence showing the material reflects current policy, current threats and the organisation's own procedures
Common gap: Training not aligned to specific job functions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 7.3 Awareness

Persons doing work under the organization's control shall be aware of the privacy policy, of their contribution to the effectiveness of the privacy information management system including the benefits of improved privacy performance, and of the implications of not conforming with the PIMS requirements. The implications the first edition spelled out are carried into the guidance: consequences to the organization, to the person, and to the PII principal of breaching privacy rules, and awareness of how to report an incident involving PII.

Evidence an auditor accepts: Awareness communications and their reach across everyone who handles PII; evidence personnel know the consequences of non-conformity and how to report a PII incident; awareness checks such as survey or test results
Common gap: Awareness limited to annual e-learning that never mentions PII principals or the reporting route
Source: ISO/IEC 27701:2025

ISO/IEC 42001:2023

ISO 42001 A.4.6 Human resources

The organization shall document information about the human resources and their competencies utilized.

Evidence an auditor accepts: Skills matrix; competence records; roles, expertise, certifications
Common gap: Are dependencies on individual experts identified as key-person risks?
Source: ISO/IEC 42001:2023

ISO 22301:2019

ISO 22301 7.3 Awareness

People doing work under the organization's control must be aware of the business continuity policy, of how they contribute to BCMS effectiveness and what better continuity performance delivers, of the implications of not conforming, and of their own role and responsibilities before, during and after a disruption.

Evidence an auditor accepts: Awareness material covering all four required points; delivery records covering staff, contractors and new starters; a test of awareness, such as a spot check or survey, rather than delivery evidence alone
Common gap: Awareness content covering the policy only, silent on individual roles during a disruption
Source: ISO 22301:2019

The NIS2 Directive

NIS2 Art. 21(2)(g) Basic cyber hygiene practices and cybersecurity training

Cyber hygiene is the common baseline the Directive expects everywhere: keeping software and hardware updated, managing configuration of devices, controlling and limiting administrator-level accounts, managing new installations, changing credentials, segmenting networks and backing up data. The recitals also point at zero-trust principles and user awareness as part of the same baseline. Training here is the workforce limb, distinct from the management body training in Article 20(2), and it needs to reach the roles that actually handle the risk rather than being one annual module for everyone. The value of this category to an auditor is that it is measurable: patch currency, privileged account counts and training completion are all countable, and a claim of good hygiene that cannot produce those numbers is not evidenced.

Evidence an auditor accepts: Patch and update currency reporting across the in-scope estate, including exceptions; secure configuration baselines and compliance measurement against them; the privileged account inventory with justification and periodic review
Common gap: Hygiene asserted for servers while endpoints, network devices and operational technology are unmeasured
Source: NIS2 Directive
NIS2 Art. 20(2) Train the management body, and offer equivalent training to staff on a regular basis

Members of the management body are required to follow training, and the entity is expected to put comparable training in front of its employees regularly. The stated purpose sets the standard: the training has to leave the body able to identify risks and to assess cybersecurity risk-management practices and the effect those practices have on the services the entity provides. That is a judgement bar, not an attendance bar. Generic awareness content aimed at all staff will not reach it, because a board member is being asked to challenge a risk treatment decision rather than avoid a phishing email. Training also needs refreshing as the body changes; a director appointed after the last session is untrained for the purposes of this Article. The employee limb is expressed as an encouragement on Member States to require, so its national transposition is worth reading, but the entity-level expectation is regular and repeated rather than on induction only.

Evidence an auditor accepts: The training curriculum put to the management body, showing it addresses risk identification and assessment of risk-management practices; attendance records per member, with dates, including members appointed since the last session; the regular employee training schedule and its completion rates
Common gap: Board members given the same awareness module as all staff
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Remote working policy · Access control policy