Security Questionnaire Mapper
People and HR security ยท question family

Security awareness training: the clause the question tests

Whether everyone is trained on joining and on a cycle, and whether completion is recorded.

How the customer usually asks it

example

"Do all staff complete security awareness training when they join and every year after?"

Read this question

Anchor clauses

2 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20226.3 Information security awareness, education and training
SIG (Shared Assessments)domain E Human Resources Security

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The training programme outline, completion records for the last cycle, and the phishing exercise results if any are run.

The clauses, with what an assessor asks for

ISO 27001 6.3 Information security awareness, education and training

Give personnel and relevant parties appropriate, current security training for their role.

Evidence an assessor expects: Training program plan; Role based training records; Attendance logs; Training effectiveness reports
Where answers usually fall short: Training not aligned to specific job functions; Content not updated on a regular basis
Source: ISO/IEC 27001:2022
SIG domain E Human Resources Security

What it asks for, in one line (the standard's own text is not quoted here):

Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.

Evidence an assessor expects: Background check policy and records; Annual security awareness training completion logs; Sanctions policy; Termination checklists and access removal records
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)

Other families in people and hr security