ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 3. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 6.3 Information security awareness, education and training

ISO 27001 Annex A 6.3 Information security awareness, education and training

What is ISO 27001 Annex A 6.3?

ISO 27001 Annex A 6.3 requires the organization to provide appropriate information security awareness, education and training to personnel and, where relevant, other interested parties.

The objective is to ensure that people understand:

  • The organization’s information security expectations.
  • The security risks relevant to their work.
  • Their individual security responsibilities.
  • How to identify and report security events.
  • How to securely use organizational information and systems.
  • The security requirements applicable to their roles.

Simple explanation

Security policies tell people what is required. A.6.3 makes sure people understand what those requirements mean and how to follow them.

Having an Information Security Policy is not enough.

An organization should be able to demonstrate that people are actually being made aware of their security responsibilities.


Why is Annex A 6.3 Important?

People are involved in almost every information security process.

Even strong technical controls can be undermined by:

  • Phishing.
  • Weak passwords.
  • Credential sharing.
  • Accidental data disclosure.
  • Unauthorized software.
  • Misuse of cloud services.
  • Lost devices.
  • Poor handling of confidential information.
  • Failure to report suspicious activity.
  • Unsafe remote working.
  • Social engineering.

For example:

A company may have MFA enabled for all employees.

But if an employee receives a convincing phishing message and approves a fraudulent MFA request, the technical control alone may not prevent compromise.

Security awareness helps employees recognize and respond to such situations.

Benefits of A.6.3

  • Reduces human-related security risks.
  • Improves security culture.
  • Helps employees understand policies.
  • Improves incident reporting.
  • Supports phishing and social-engineering resistance.
  • Helps protect customer and company information.
  • Supports compliance requirements.
  • Provides evidence of ongoing security awareness.
  • Reinforces the organization’s ISMS.

Simple principle

You cannot expect people to follow security requirements that they do not understand.


What Does Annex A 6.3 Require?

The organization should establish an appropriate process for:

  1. Identifying security awareness and training needs.
  2. Providing appropriate education and training.
  3. Making personnel aware of relevant security policies.
  4. Providing role-specific security training where necessary.
  5. Maintaining evidence of training and awareness.
  6. Conducting training at appropriate intervals.
  7. Updating training when risks, technologies, regulations or responsibilities change.

The training should be appropriate to the organization’s size, risks and personnel responsibilities.

A 20-person startup does not necessarily need the same training program as a multinational bank.


Awareness vs. Education vs. Training

These terms are related but can be treated differently.

Awareness

Makes people conscious of security risks and expectations.

Examples:

  • Phishing awareness.
  • Security reminders.
  • Security newsletters.
  • Posters.
  • Security alerts.
  • Short awareness videos.

Education

Builds broader understanding of security concepts.

Examples:

  • Understanding data classification.
  • Understanding privacy obligations.
  • Understanding social engineering.
  • Understanding secure remote working.

Training

Provides practical knowledge needed to perform a role securely.

Examples:

  • Secure coding training for developers.
  • Cloud security training for administrators.
  • Incident response training for security teams.
  • PII handling training for HR.
  • Privileged-access training for system administrators.

Simple distinction

Awareness creates attention. Education creates understanding. Training creates practical capability.


Activities Required to Implement A.6.3

Step 1 — Identify Training Requirements

First identify who needs training and what they need to know.

For example:

PersonnelSecurity Awareness / Training
All employeesSecurity awareness
DevelopersSecure development
IT administratorsPrivileged access and system security
HREmployee PII protection
FinanceFinancial information security
Customer supportCustomer information handling
ExecutivesSecurity responsibilities and incident escalation
Security teamIncident response and security operations
ContractorsRelevant organizational security requirements

Step 2 — Define a Security Awareness and Training Program

Create a simple annual or periodic security awareness plan.

For example:

TopicAudienceFrequency
General security awarenessAll personnelAnnually
Phishing awarenessAll personnelPeriodically
Password and MFA securityAll personnelAnnually
Incident reportingAll personnelAnnually
Data classificationRelevant personnelAnnually
Privacy/PII protectionRelevant personnelAnnually
Secure codingDevelopersRole-based
Cloud securityAdministratorsRole-based
Incident responseSecurity teamRole-based
Remote working securityRemote personnelAnnually

The frequency should be based on organizational risk rather than simply creating a schedule for audit purposes.


Step 3 — Provide Security Awareness During Onboarding

New employees should receive appropriate security awareness as part of onboarding.

A practical sequence is:

Join organization

↓

Understand security responsibilities

↓

Receive security policies

↓

Complete security awareness training

↓

Acknowledge requirements

↓

Receive appropriate system access

This connects A.6.3 with:

  • A.6.2 — Terms and Conditions of Employment.
  • A.5.15 — Access Control.
  • A.5.16 — Identity Management.
  • A.5.18 — Access Rights.

Step 4 — Provide Role-Based Training

Not everyone needs the same training.

For example, a developer may need training on:

  • Secure coding.
  • Secrets management.
  • Source-code protection.
  • Dependency security.
  • Code review.
  • Secure deployment.

A system administrator may need:

  • Privileged access.
  • MFA.
  • Logging.
  • Secure configuration.
  • Backup security.
  • Emergency access.

HR may need:

  • PII handling.
  • Confidentiality.
  • Secure document handling.
  • Phishing awareness.

This makes the training program more practical.


Step 5 — Cover Security Policies

Employees should understand the policies relevant to their responsibilities.

Important topics may include:

  • Information Security Policy.
  • Acceptable Use Policy.
  • Access Control Policy.
  • Data Classification Policy.
  • Password/MFA requirements.
  • Incident Management Procedure.
  • Remote Working Policy.
  • Privacy Policy.
  • Asset Management Policy.
  • Clear Desk/Clear Screen requirements where applicable.

Training does not necessarily mean employees must memorize every policy.

The objective is to ensure they understand the requirements relevant to their work and know where to find the detailed rules.


Step 6 — Train Employees to Report Security Events

One of the most important elements of awareness is knowing what to report and how to report it.

Employees should understand examples such as:

  • Phishing emails.
  • Suspicious login notifications.
  • Lost laptops.
  • Lost mobile phones.
  • Accidental data sharing.
  • Malware warnings.
  • Unauthorized access.
  • Suspicious calls.
  • Customer data sent to the wrong recipient.
  • Unusual system behavior.

They should also know:

Who do I contact?

How do I report it?

How quickly should I report it?

This connects A.6.3 with A.6.8 — Information Security Event Reporting.


Step 7 — Use Practical Awareness Methods

Training does not always need to be a long classroom session.

A startup can use:

  • Short online courses.
  • Recorded videos.
  • Security newsletters.
  • Security awareness emails.
  • Short quizzes.
  • Phishing simulations.
  • Security workshops.
  • Team discussions.
  • Posters/reminders.
  • Security tips in collaboration tools.
  • Incident-based awareness sessions.

The method should match the organization’s risk and workforce.


Step 8 — Test Understanding

Where appropriate, organizations can verify whether training is effective.

Examples:

  • Short quizzes.
  • Phishing simulations.
  • Scenario-based exercises.
  • Tabletop exercises.
  • Practical demonstrations.
  • Knowledge assessments.

For example:

After phishing awareness training, the organization may conduct a controlled phishing simulation and measure:

  • Who reported the message.
  • Who interacted with it.
  • Reporting time.
  • Recurring problem areas.

The purpose should be learning and improvement, not simply punishing employees.


Step 9 — Maintain Training Records

The organization should maintain evidence that training occurred.

A training record may include:

EmployeeTrainingDateMethodResultStatus
EMP-001Security Awareness10-Jan-2026OnlinePassedComplete
EMP-002Security Awareness11-Jan-2026OnlinePassedComplete
EMP-003Secure Coding15-Feb-2026WorkshopCompletedComplete

Sensitive employee information should itself be appropriately protected.


Step 10 — Refresh Training

Training should not be treated as a one-time activity.

Refresh awareness when:

  • Major security incidents occur.
  • New threats emerge.
  • New systems are introduced.
  • Employees change roles.
  • New regulations apply.
  • Policies change.
  • Customer security requirements change.
  • Significant technology changes occur.

For example:

If the organization moves from on-premises infrastructure to AWS, administrators may need additional cloud-security training.


Startup Example

Consider a 40-person SaaS startup with:

  • Developers.
  • Customer support.
  • Sales.
  • Finance.
  • HR.
  • IT administrators.

The startup creates a basic security awareness program.

All Employees

Annual training covers:

  • Phishing.
  • Passwords and MFA.
  • Incident reporting.
  • Confidential information.
  • Acceptable use.
  • Remote working.
  • Data protection.

Developers

Additional training covers:

  • Secure coding.
  • Secrets management.
  • Dependency security.
  • Source-code protection.

IT Administrators

Additional training covers:

  • Privileged access.
  • Cloud security.
  • Logging.
  • Backup security.
  • Incident response.

HR

Additional training covers:

  • Employee PII.
  • Confidential HR information.
  • Secure document handling.

Security Program

Onboarding training

↓

Annual awareness

↓

Role-specific training

↓

Phishing/knowledge testing

↓

Incident-based refreshers

↓

Training records

↓

Program review

This is a practical A.6.3 implementation for a growing startup.


Startup-Focused Quick Summary

A startup can start with a simple three-layer model.

Layer 1 — Everyone

Train everyone on:

  • Phishing.
  • Passwords/MFA.
  • Confidential information.
  • Incident reporting.
  • Acceptable use.
  • Remote working.
  • Privacy.

Layer 2 — Role-Specific

Provide additional training to:

  • Developers.
  • Administrators.
  • HR.
  • Finance.
  • Security personnel.
  • Customer support.

Layer 3 — Ongoing Awareness

Use:

  • Short reminders.
  • Security updates.
  • Phishing simulations.
  • Incident lessons.
  • Refresher training.

Simple startup principle

Train everyone on the basics, train high-risk roles more deeply, and keep security awareness active throughout the year.


Example Security Training Matrix

RoleGeneral AwarenessPhishingPrivacySecure DevelopmentCloud SecurityIncident Response
All Employees✓✓Where applicable——Basic
Developer✓✓Where applicable✓Where applicableBasic
IT Admin✓✓Where applicable—✓✓
HR✓✓✓——Basic
Finance✓✓✓——Basic
Customer Support✓✓✓——Basic
Security Team✓✓✓Where applicable✓✓
Executive Management✓✓High-level—High-levelHigh-level

Example Annual Security Awareness Plan

A startup can structure its program throughout the year.

PeriodTopic
Q1General Information Security Awareness
Q1Password and MFA Security
Q2Phishing and Social Engineering
Q2Data Classification and Information Handling
Q3Privacy and PII Protection
Q3Secure Remote Working
Q4Incident Reporting and Response
Q4Refresher / Security Knowledge Assessment

This is only an example. The actual schedule should reflect the organization’s risk profile.


Security Awareness Metrics

The organization may track meaningful metrics such as:

Training Completion

Completed training ÷ required personnel × 100

Phishing Simulation

Track:

  • Click rate.
  • Reporting rate.
  • Reporting time.
  • Repeat interactions.

Incident Reporting

Track:

  • Number of employee-reported events.
  • Time to report.
  • Common reporting categories.

Training Effectiveness

Compare results over time.

For example:

Before training

30% of simulated phishing emails were reported.

↓

After training

70% were reported.

The purpose is to identify whether awareness activities are improving behavior.


What Not to Do

Avoid treating A.6.3 as:

“We uploaded one security awareness PDF and asked employees to read it.”

That may demonstrate communication, but it does not necessarily demonstrate an effective awareness and training program.

Similarly, avoid:

  • Training only before the ISO audit.
  • One generic course for every role.
  • No onboarding training.
  • No training records.
  • No role-specific training.
  • No incident reporting awareness.
  • No refresher training.
  • No evaluation of effectiveness.
  • Training content that does not reflect actual company risks.

Audit Evidence for A.6.3

An auditor may request:

Policies and Procedures

  • Information Security Awareness Policy.
  • Security Awareness and Training Procedure.
  • Employee Onboarding Procedure.
  • Security Training Procedure.

Training Program

  • Annual training plan.
  • Security awareness calendar.
  • Training curriculum.
  • Role-based training matrix.
  • Training materials.

Training Records

  • Employee training records.
  • Course completion reports.
  • Attendance records.
  • Quiz results.
  • Certificates where applicable.

Awareness Activities

  • Security awareness emails.
  • Security newsletters.
  • Security reminders.
  • Phishing simulation results.
  • Security workshops.

Role-Specific Training

  • Secure coding training.
  • Cloud security training.
  • Incident response training.
  • Privacy training.
  • Administrator training.

Effectiveness

  • Quiz results.
  • Phishing simulation metrics.
  • Training feedback.
  • Incident reporting metrics.
  • Corrective actions.
  • Management review of training results.

Audit Checklist for A.6.3

Before an ISO 27001 audit, ask:

  • Is there a documented security awareness and training process?
  • Are security training requirements identified?
  • Do new employees receive security awareness training?
  • Is training provided periodically?
  • Are relevant policies communicated?
  • Do employees understand incident reporting?
  • Is phishing/social-engineering awareness addressed?
  • Is privacy/PII awareness provided where relevant?
  • Are role-specific training needs identified?
  • Are developers provided secure-development training where appropriate?
  • Are administrators provided appropriate security training?
  • Are training completion records maintained?
  • Are training gaps followed up?
  • Is training updated when risks or responsibilities change?
  • Is training effectiveness evaluated where appropriate?
  • Can the organization demonstrate evidence of the program?

Common Mistakes in Implementing A.6.3

1. Training only before the certification audit

A.6.3 should operate as an ongoing program.


2. One course for everyone

Different roles have different security risks.


3. No onboarding training

New employees may receive system access before understanding security responsibilities.


4. No evidence

The company conducts informal training but cannot demonstrate:

  • Who attended.
  • What was covered.
  • When it occurred.
  • Whether it was completed.

5. Ignoring contractors

Relevant contractors may also require awareness or role-specific training.


6. No phishing awareness

Phishing and social engineering are common attack vectors, so organizations should consider whether they are relevant to their risk profile.


7. Training content is outdated

Security training should reflect the organization’s current:

  • Technology.
  • Policies.
  • Threats.
  • Regulations.
  • Business processes.

8. No role-based training

A developer, HR employee and cloud administrator should not necessarily receive identical training.


9. Training completion is the only metric

100% completion does not automatically mean employees understand security.

Where appropriate, use quizzes, simulations, exercises or other measures to evaluate effectiveness.


10. Training is disconnected from incidents

Real incidents and near misses can provide valuable learning opportunities.

For example:

A phishing incident occurs.

↓

Analyze what happened.

↓

Identify the awareness gap.

↓

Update training.

↓

Communicate the lesson.

↓

Monitor improvement.


Practical Startup Implementation Model

A simple model is:

Identify

Identify security risks and training needs.

↓

Define

Define general and role-specific training requirements.

↓

Train

Provide onboarding, periodic and role-specific training.

↓

Reinforce

Use reminders, simulations and awareness activities.

↓

Test

Evaluate understanding where appropriate.

↓

Record

Maintain training and awareness evidence.

↓

Improve

Update the program based on incidents, risks and changes.

Simple formula

Identify → Train → Reinforce → Test → Record → Improve


Policy vs. Process vs. Evidence

CategoryExample
PolicyInformation Security Awareness Policy
PolicySecurity Training Policy
ProcessEmployee Security Training Procedure
ProcessNew Employee Security Onboarding
ProcessRole-Based Training Process
ProcessPhishing Simulation Process
EvidenceAnnual Training Plan
EvidenceTraining Attendance
EvidenceLMS Completion Report
EvidenceQuiz Results
EvidenceSecurity Awareness Emails
EvidencePhishing Simulation Results
EvidenceTraining Certificates
EvidenceTraining Gap Tracker
EvidenceRole-Based Training Matrix

Simple rule

Policy defines the expectation.

Training teaches the expectation.

Testing checks understanding.

Records prove that training occurred.

Improvement ensures the program remains relevant.


Relationship with Other ISO 27001 Controls

A.6.3 connects with many controls across the ISMS.

ControlRelationship
A.6.1Screening before employment
A.6.2Security responsibilities in employment terms
A.6.3Awareness, education and training
A.6.4Disciplinary process
A.6.5Responsibilities after termination/change
A.6.6Confidentiality/NDA requirements
A.6.7Remote working security
A.6.8Security event reporting
A.5.10Acceptable use
A.5.12Information classification
A.5.14Information transfer
A.5.15Access control
A.5.34Privacy and PII protection
A.5.36Compliance with security policies
A.5.37Documented operating procedures

A.6.2 vs. A.6.3

These controls are closely related but have different purposes.

A.6.2 — Terms and Conditions of Employment

Focus:

What security responsibilities have been established for the person?

Examples:

  • Confidentiality.
  • Policy compliance.
  • Incident reporting.
  • Asset protection.

A.6.3 — Awareness, Education and Training

Focus:

Does the person understand how to meet those security responsibilities?

Examples:

  • Phishing awareness.
  • Policy training.
  • Secure coding.
  • Privacy training.
  • Incident reporting training.

Simple lifecycle

Establish responsibility → Educate → Train → Apply → Review


A.6.3 vs. A.6.8

These controls also work together.

A.6.3

Teaches employees:

“What security events should I recognize and report?”

A.6.8

Establishes:

“How should I report them?”

For example:

An employee receives a suspicious phishing email.

A.6.3: Employee recognizes it as suspicious.

↓

A.6.8: Employee knows where and how to report it.

↓

A.5.24–A.5.26: Organization assesses and responds to the event/incident.


Useful Documents for A.6.3

Organizations may create:

  • [Insert Draft Document Link] — Information Security Awareness Policy
  • [Insert Draft Document Link] — Security Awareness and Training Procedure
  • [Insert Draft Document Link] — Annual Security Awareness Plan
  • [Insert Draft Document Link] — Employee Security Training Checklist
  • [Insert Draft Document Link] — New Employee Security Onboarding Checklist
  • [Insert Draft Document Link] — Role-Based Security Training Matrix
  • [Insert Draft Document Link] — Security Awareness Training Register
  • [Insert Draft Document Link] — Phishing Awareness Procedure
  • [Insert Draft Document Link] — Security Awareness Quiz
  • [Insert Draft Document Link] — Security Training Effectiveness Assessment
  • [Insert Draft Document Link] — Security Awareness Audit Checklist

Questions an Auditor May Ask

General

“How do you make employees aware of information security responsibilities?”

“How frequently is security awareness training provided?”

New Employees

“When does a new employee receive security awareness training?”

“Is training completed before access is provided?”

Role-Based

“How do you identify additional training requirements for privileged users?”

“What security training do developers receive?”

Effectiveness

“How do you know employees understand the training?”

“Have you conducted any phishing simulations or knowledge assessments?”

Evidence

“Show me the training records for a sample of employees.”

“Can you demonstrate your annual security awareness plan?”

Continuous Improvement

“How have security incidents or emerging threats influenced your training program?”


Startup-Focused Final Takeaway

ISO 27001 Annex A 6.3 is not simply about conducting an annual training course.

It is about creating a security-aware workforce that understands the organization’s expectations and can apply them in day-to-day work.

A practical startup approach is:

Identify risks

↓

Identify training needs

↓

Train new employees

↓

Provide periodic security awareness

↓

Provide role-specific training

↓

Reinforce through practical activities

↓

Test understanding where appropriate

↓

Maintain evidence

↓

Improve based on incidents and changing risks

The key question for A.6.3 is:

“Can we demonstrate that our people understand the security risks relevant to their work, know their responsibilities, and receive appropriate ongoing awareness, education and training?”

For startups, the goal should not be to create the largest training program.

The goal should be to create a relevant, measurable and repeatable security-awareness program that changes employee behavior and reduces real security risk.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *