What is ISO 27001 Annex A 6.3?
ISO 27001 Annex A 6.3 requires the organization to provide appropriate information security awareness, education and training to personnel and, where relevant, other interested parties.
The objective is to ensure that people understand:
- The organization’s information security expectations.
- The security risks relevant to their work.
- Their individual security responsibilities.
- How to identify and report security events.
- How to securely use organizational information and systems.
- The security requirements applicable to their roles.
Simple explanation
Security policies tell people what is required. A.6.3 makes sure people understand what those requirements mean and how to follow them.
Having an Information Security Policy is not enough.
An organization should be able to demonstrate that people are actually being made aware of their security responsibilities.
Why is Annex A 6.3 Important?
People are involved in almost every information security process.
Even strong technical controls can be undermined by:
- Phishing.
- Weak passwords.
- Credential sharing.
- Accidental data disclosure.
- Unauthorized software.
- Misuse of cloud services.
- Lost devices.
- Poor handling of confidential information.
- Failure to report suspicious activity.
- Unsafe remote working.
- Social engineering.
For example:
A company may have MFA enabled for all employees.
But if an employee receives a convincing phishing message and approves a fraudulent MFA request, the technical control alone may not prevent compromise.
Security awareness helps employees recognize and respond to such situations.
Benefits of A.6.3
- Reduces human-related security risks.
- Improves security culture.
- Helps employees understand policies.
- Improves incident reporting.
- Supports phishing and social-engineering resistance.
- Helps protect customer and company information.
- Supports compliance requirements.
- Provides evidence of ongoing security awareness.
- Reinforces the organization’s ISMS.
Simple principle
You cannot expect people to follow security requirements that they do not understand.
What Does Annex A 6.3 Require?
The organization should establish an appropriate process for:
- Identifying security awareness and training needs.
- Providing appropriate education and training.
- Making personnel aware of relevant security policies.
- Providing role-specific security training where necessary.
- Maintaining evidence of training and awareness.
- Conducting training at appropriate intervals.
- Updating training when risks, technologies, regulations or responsibilities change.
The training should be appropriate to the organization’s size, risks and personnel responsibilities.
A 20-person startup does not necessarily need the same training program as a multinational bank.
Awareness vs. Education vs. Training
These terms are related but can be treated differently.
Awareness
Makes people conscious of security risks and expectations.
Examples:
- Phishing awareness.
- Security reminders.
- Security newsletters.
- Posters.
- Security alerts.
- Short awareness videos.
Education
Builds broader understanding of security concepts.
Examples:
- Understanding data classification.
- Understanding privacy obligations.
- Understanding social engineering.
- Understanding secure remote working.
Training
Provides practical knowledge needed to perform a role securely.
Examples:
- Secure coding training for developers.
- Cloud security training for administrators.
- Incident response training for security teams.
- PII handling training for HR.
- Privileged-access training for system administrators.
Simple distinction
Awareness creates attention. Education creates understanding. Training creates practical capability.
Activities Required to Implement A.6.3
Step 1 — Identify Training Requirements
First identify who needs training and what they need to know.
For example:
| Personnel | Security Awareness / Training |
|---|---|
| All employees | Security awareness |
| Developers | Secure development |
| IT administrators | Privileged access and system security |
| HR | Employee PII protection |
| Finance | Financial information security |
| Customer support | Customer information handling |
| Executives | Security responsibilities and incident escalation |
| Security team | Incident response and security operations |
| Contractors | Relevant organizational security requirements |
Step 2 — Define a Security Awareness and Training Program
Create a simple annual or periodic security awareness plan.
For example:
| Topic | Audience | Frequency |
|---|---|---|
| General security awareness | All personnel | Annually |
| Phishing awareness | All personnel | Periodically |
| Password and MFA security | All personnel | Annually |
| Incident reporting | All personnel | Annually |
| Data classification | Relevant personnel | Annually |
| Privacy/PII protection | Relevant personnel | Annually |
| Secure coding | Developers | Role-based |
| Cloud security | Administrators | Role-based |
| Incident response | Security team | Role-based |
| Remote working security | Remote personnel | Annually |
The frequency should be based on organizational risk rather than simply creating a schedule for audit purposes.
Step 3 — Provide Security Awareness During Onboarding
New employees should receive appropriate security awareness as part of onboarding.
A practical sequence is:
Join organization
↓
Understand security responsibilities
↓
Receive security policies
↓
Complete security awareness training
↓
Acknowledge requirements
↓
Receive appropriate system access
This connects A.6.3 with:
- A.6.2 — Terms and Conditions of Employment.
- A.5.15 — Access Control.
- A.5.16 — Identity Management.
- A.5.18 — Access Rights.
Step 4 — Provide Role-Based Training
Not everyone needs the same training.
For example, a developer may need training on:
- Secure coding.
- Secrets management.
- Source-code protection.
- Dependency security.
- Code review.
- Secure deployment.
A system administrator may need:
- Privileged access.
- MFA.
- Logging.
- Secure configuration.
- Backup security.
- Emergency access.
HR may need:
- PII handling.
- Confidentiality.
- Secure document handling.
- Phishing awareness.
This makes the training program more practical.
Step 5 — Cover Security Policies
Employees should understand the policies relevant to their responsibilities.
Important topics may include:
- Information Security Policy.
- Acceptable Use Policy.
- Access Control Policy.
- Data Classification Policy.
- Password/MFA requirements.
- Incident Management Procedure.
- Remote Working Policy.
- Privacy Policy.
- Asset Management Policy.
- Clear Desk/Clear Screen requirements where applicable.
Training does not necessarily mean employees must memorize every policy.
The objective is to ensure they understand the requirements relevant to their work and know where to find the detailed rules.
Step 6 — Train Employees to Report Security Events
One of the most important elements of awareness is knowing what to report and how to report it.
Employees should understand examples such as:
- Phishing emails.
- Suspicious login notifications.
- Lost laptops.
- Lost mobile phones.
- Accidental data sharing.
- Malware warnings.
- Unauthorized access.
- Suspicious calls.
- Customer data sent to the wrong recipient.
- Unusual system behavior.
They should also know:
Who do I contact?
How do I report it?
How quickly should I report it?
This connects A.6.3 with A.6.8 — Information Security Event Reporting.
Step 7 — Use Practical Awareness Methods
Training does not always need to be a long classroom session.
A startup can use:
- Short online courses.
- Recorded videos.
- Security newsletters.
- Security awareness emails.
- Short quizzes.
- Phishing simulations.
- Security workshops.
- Team discussions.
- Posters/reminders.
- Security tips in collaboration tools.
- Incident-based awareness sessions.
The method should match the organization’s risk and workforce.
Step 8 — Test Understanding
Where appropriate, organizations can verify whether training is effective.
Examples:
- Short quizzes.
- Phishing simulations.
- Scenario-based exercises.
- Tabletop exercises.
- Practical demonstrations.
- Knowledge assessments.
For example:
After phishing awareness training, the organization may conduct a controlled phishing simulation and measure:
- Who reported the message.
- Who interacted with it.
- Reporting time.
- Recurring problem areas.
The purpose should be learning and improvement, not simply punishing employees.
Step 9 — Maintain Training Records
The organization should maintain evidence that training occurred.
A training record may include:
| Employee | Training | Date | Method | Result | Status |
|---|---|---|---|---|---|
| EMP-001 | Security Awareness | 10-Jan-2026 | Online | Passed | Complete |
| EMP-002 | Security Awareness | 11-Jan-2026 | Online | Passed | Complete |
| EMP-003 | Secure Coding | 15-Feb-2026 | Workshop | Completed | Complete |
Sensitive employee information should itself be appropriately protected.
Step 10 — Refresh Training
Training should not be treated as a one-time activity.
Refresh awareness when:
- Major security incidents occur.
- New threats emerge.
- New systems are introduced.
- Employees change roles.
- New regulations apply.
- Policies change.
- Customer security requirements change.
- Significant technology changes occur.
For example:
If the organization moves from on-premises infrastructure to AWS, administrators may need additional cloud-security training.
Startup Example
Consider a 40-person SaaS startup with:
- Developers.
- Customer support.
- Sales.
- Finance.
- HR.
- IT administrators.
The startup creates a basic security awareness program.
All Employees
Annual training covers:
- Phishing.
- Passwords and MFA.
- Incident reporting.
- Confidential information.
- Acceptable use.
- Remote working.
- Data protection.
Developers
Additional training covers:
- Secure coding.
- Secrets management.
- Dependency security.
- Source-code protection.
IT Administrators
Additional training covers:
- Privileged access.
- Cloud security.
- Logging.
- Backup security.
- Incident response.
HR
Additional training covers:
- Employee PII.
- Confidential HR information.
- Secure document handling.
Security Program
Onboarding training
↓
Annual awareness
↓
Role-specific training
↓
Phishing/knowledge testing
↓
Incident-based refreshers
↓
Training records
↓
Program review
This is a practical A.6.3 implementation for a growing startup.
Startup-Focused Quick Summary
A startup can start with a simple three-layer model.
Layer 1 — Everyone
Train everyone on:
- Phishing.
- Passwords/MFA.
- Confidential information.
- Incident reporting.
- Acceptable use.
- Remote working.
- Privacy.
Layer 2 — Role-Specific
Provide additional training to:
- Developers.
- Administrators.
- HR.
- Finance.
- Security personnel.
- Customer support.
Layer 3 — Ongoing Awareness
Use:
- Short reminders.
- Security updates.
- Phishing simulations.
- Incident lessons.
- Refresher training.
Simple startup principle
Train everyone on the basics, train high-risk roles more deeply, and keep security awareness active throughout the year.
Example Security Training Matrix
| Role | General Awareness | Phishing | Privacy | Secure Development | Cloud Security | Incident Response |
|---|---|---|---|---|---|---|
| All Employees | ✓ | ✓ | Where applicable | — | — | Basic |
| Developer | ✓ | ✓ | Where applicable | ✓ | Where applicable | Basic |
| IT Admin | ✓ | ✓ | Where applicable | — | ✓ | ✓ |
| HR | ✓ | ✓ | ✓ | — | — | Basic |
| Finance | ✓ | ✓ | ✓ | — | — | Basic |
| Customer Support | ✓ | ✓ | ✓ | — | — | Basic |
| Security Team | ✓ | ✓ | ✓ | Where applicable | ✓ | ✓ |
| Executive Management | ✓ | ✓ | High-level | — | High-level | High-level |
Example Annual Security Awareness Plan
A startup can structure its program throughout the year.
| Period | Topic |
|---|---|
| Q1 | General Information Security Awareness |
| Q1 | Password and MFA Security |
| Q2 | Phishing and Social Engineering |
| Q2 | Data Classification and Information Handling |
| Q3 | Privacy and PII Protection |
| Q3 | Secure Remote Working |
| Q4 | Incident Reporting and Response |
| Q4 | Refresher / Security Knowledge Assessment |
This is only an example. The actual schedule should reflect the organization’s risk profile.
Security Awareness Metrics
The organization may track meaningful metrics such as:
Training Completion
Completed training ÷ required personnel × 100
Phishing Simulation
Track:
- Click rate.
- Reporting rate.
- Reporting time.
- Repeat interactions.
Incident Reporting
Track:
- Number of employee-reported events.
- Time to report.
- Common reporting categories.
Training Effectiveness
Compare results over time.
For example:
Before training
30% of simulated phishing emails were reported.
↓
After training
70% were reported.
The purpose is to identify whether awareness activities are improving behavior.
What Not to Do
Avoid treating A.6.3 as:
“We uploaded one security awareness PDF and asked employees to read it.”
That may demonstrate communication, but it does not necessarily demonstrate an effective awareness and training program.
Similarly, avoid:
- Training only before the ISO audit.
- One generic course for every role.
- No onboarding training.
- No training records.
- No role-specific training.
- No incident reporting awareness.
- No refresher training.
- No evaluation of effectiveness.
- Training content that does not reflect actual company risks.
Audit Evidence for A.6.3
An auditor may request:
Policies and Procedures
- Information Security Awareness Policy.
- Security Awareness and Training Procedure.
- Employee Onboarding Procedure.
- Security Training Procedure.
Training Program
- Annual training plan.
- Security awareness calendar.
- Training curriculum.
- Role-based training matrix.
- Training materials.
Training Records
- Employee training records.
- Course completion reports.
- Attendance records.
- Quiz results.
- Certificates where applicable.
Awareness Activities
- Security awareness emails.
- Security newsletters.
- Security reminders.
- Phishing simulation results.
- Security workshops.
Role-Specific Training
- Secure coding training.
- Cloud security training.
- Incident response training.
- Privacy training.
- Administrator training.
Effectiveness
- Quiz results.
- Phishing simulation metrics.
- Training feedback.
- Incident reporting metrics.
- Corrective actions.
- Management review of training results.
Audit Checklist for A.6.3
Before an ISO 27001 audit, ask:
- Is there a documented security awareness and training process?
- Are security training requirements identified?
- Do new employees receive security awareness training?
- Is training provided periodically?
- Are relevant policies communicated?
- Do employees understand incident reporting?
- Is phishing/social-engineering awareness addressed?
- Is privacy/PII awareness provided where relevant?
- Are role-specific training needs identified?
- Are developers provided secure-development training where appropriate?
- Are administrators provided appropriate security training?
- Are training completion records maintained?
- Are training gaps followed up?
- Is training updated when risks or responsibilities change?
- Is training effectiveness evaluated where appropriate?
- Can the organization demonstrate evidence of the program?
Common Mistakes in Implementing A.6.3
1. Training only before the certification audit
A.6.3 should operate as an ongoing program.
2. One course for everyone
Different roles have different security risks.
3. No onboarding training
New employees may receive system access before understanding security responsibilities.
4. No evidence
The company conducts informal training but cannot demonstrate:
- Who attended.
- What was covered.
- When it occurred.
- Whether it was completed.
5. Ignoring contractors
Relevant contractors may also require awareness or role-specific training.
6. No phishing awareness
Phishing and social engineering are common attack vectors, so organizations should consider whether they are relevant to their risk profile.
7. Training content is outdated
Security training should reflect the organization’s current:
- Technology.
- Policies.
- Threats.
- Regulations.
- Business processes.
8. No role-based training
A developer, HR employee and cloud administrator should not necessarily receive identical training.
9. Training completion is the only metric
100% completion does not automatically mean employees understand security.
Where appropriate, use quizzes, simulations, exercises or other measures to evaluate effectiveness.
10. Training is disconnected from incidents
Real incidents and near misses can provide valuable learning opportunities.
For example:
A phishing incident occurs.
↓
Analyze what happened.
↓
Identify the awareness gap.
↓
Update training.
↓
Communicate the lesson.
↓
Monitor improvement.
Practical Startup Implementation Model
A simple model is:
Identify
Identify security risks and training needs.
↓
Define
Define general and role-specific training requirements.
↓
Train
Provide onboarding, periodic and role-specific training.
↓
Reinforce
Use reminders, simulations and awareness activities.
↓
Test
Evaluate understanding where appropriate.
↓
Record
Maintain training and awareness evidence.
↓
Improve
Update the program based on incidents, risks and changes.
Simple formula
Identify → Train → Reinforce → Test → Record → Improve
Policy vs. Process vs. Evidence
| Category | Example |
|---|---|
| Policy | Information Security Awareness Policy |
| Policy | Security Training Policy |
| Process | Employee Security Training Procedure |
| Process | New Employee Security Onboarding |
| Process | Role-Based Training Process |
| Process | Phishing Simulation Process |
| Evidence | Annual Training Plan |
| Evidence | Training Attendance |
| Evidence | LMS Completion Report |
| Evidence | Quiz Results |
| Evidence | Security Awareness Emails |
| Evidence | Phishing Simulation Results |
| Evidence | Training Certificates |
| Evidence | Training Gap Tracker |
| Evidence | Role-Based Training Matrix |
Simple rule
Policy defines the expectation.
Training teaches the expectation.
Testing checks understanding.
Records prove that training occurred.
Improvement ensures the program remains relevant.
Relationship with Other ISO 27001 Controls
A.6.3 connects with many controls across the ISMS.
| Control | Relationship |
|---|---|
| A.6.1 | Screening before employment |
| A.6.2 | Security responsibilities in employment terms |
| A.6.3 | Awareness, education and training |
| A.6.4 | Disciplinary process |
| A.6.5 | Responsibilities after termination/change |
| A.6.6 | Confidentiality/NDA requirements |
| A.6.7 | Remote working security |
| A.6.8 | Security event reporting |
| A.5.10 | Acceptable use |
| A.5.12 | Information classification |
| A.5.14 | Information transfer |
| A.5.15 | Access control |
| A.5.34 | Privacy and PII protection |
| A.5.36 | Compliance with security policies |
| A.5.37 | Documented operating procedures |
A.6.2 vs. A.6.3
These controls are closely related but have different purposes.
A.6.2 — Terms and Conditions of Employment
Focus:
What security responsibilities have been established for the person?
Examples:
- Confidentiality.
- Policy compliance.
- Incident reporting.
- Asset protection.
A.6.3 — Awareness, Education and Training
Focus:
Does the person understand how to meet those security responsibilities?
Examples:
- Phishing awareness.
- Policy training.
- Secure coding.
- Privacy training.
- Incident reporting training.
Simple lifecycle
Establish responsibility → Educate → Train → Apply → Review
A.6.3 vs. A.6.8
These controls also work together.
A.6.3
Teaches employees:
“What security events should I recognize and report?”
A.6.8
Establishes:
“How should I report them?”
For example:
An employee receives a suspicious phishing email.
A.6.3: Employee recognizes it as suspicious.
↓
A.6.8: Employee knows where and how to report it.
↓
A.5.24–A.5.26: Organization assesses and responds to the event/incident.
Useful Documents for A.6.3
Organizations may create:
- [Insert Draft Document Link] — Information Security Awareness Policy
- [Insert Draft Document Link] — Security Awareness and Training Procedure
- [Insert Draft Document Link] — Annual Security Awareness Plan
- [Insert Draft Document Link] — Employee Security Training Checklist
- [Insert Draft Document Link] — New Employee Security Onboarding Checklist
- [Insert Draft Document Link] — Role-Based Security Training Matrix
- [Insert Draft Document Link] — Security Awareness Training Register
- [Insert Draft Document Link] — Phishing Awareness Procedure
- [Insert Draft Document Link] — Security Awareness Quiz
- [Insert Draft Document Link] — Security Training Effectiveness Assessment
- [Insert Draft Document Link] — Security Awareness Audit Checklist
Questions an Auditor May Ask
General
“How do you make employees aware of information security responsibilities?”
“How frequently is security awareness training provided?”
New Employees
“When does a new employee receive security awareness training?”
“Is training completed before access is provided?”
Role-Based
“How do you identify additional training requirements for privileged users?”
“What security training do developers receive?”
Effectiveness
“How do you know employees understand the training?”
“Have you conducted any phishing simulations or knowledge assessments?”
Evidence
“Show me the training records for a sample of employees.”
“Can you demonstrate your annual security awareness plan?”
Continuous Improvement
“How have security incidents or emerging threats influenced your training program?”
Startup-Focused Final Takeaway
ISO 27001 Annex A 6.3 is not simply about conducting an annual training course.
It is about creating a security-aware workforce that understands the organization’s expectations and can apply them in day-to-day work.
A practical startup approach is:
Identify risks
↓
Identify training needs
↓
Train new employees
↓
Provide periodic security awareness
↓
Provide role-specific training
↓
Reinforce through practical activities
↓
Test understanding where appropriate
↓
Maintain evidence
↓
Improve based on incidents and changing risks
The key question for A.6.3 is:
“Can we demonstrate that our people understand the security risks relevant to their work, know their responsibilities, and receive appropriate ongoing awareness, education and training?”
For startups, the goal should not be to create the largest training program.
The goal should be to create a relevant, measurable and repeatable security-awareness program that changes employee behavior and reduces real security risk.
