ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. ISO 27001 Security Awareness Policy

ISO 27001 Security Awareness Policy

1. Purpose

The purpose of this Security Awareness Policy is to ensure that employees, contractors, and other relevant personnel understand their information security responsibilities and have the knowledge required to protect the organization’s information, systems, customers, and technology resources.

Security awareness is intended to reduce risks arising from:

  • Phishing and social engineering
  • Credential compromise
  • Accidental data disclosure
  • Malware and malicious activity
  • Inappropriate use of systems
  • Loss or theft of devices
  • Weak security practices
  • Failure to report security incidents
  • Improper handling of confidential information

The organization shall provide security awareness and training appropriate to the individual’s role, responsibilities, and level of access.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Temporary workers
  • Interns
  • Consultants
  • Third-party personnel where relevant
  • Privileged users
  • Developers
  • IT and security personnel
  • Management

The requirements shall be applied proportionately based on the person’s access, responsibilities, and information security risk.


3. Security Awareness Principles

The organization’s awareness program shall be based on the following principles:

3.1 Everyone Has a Security Responsibility

Information security is not limited to the IT or security team.

Every person with access to organizational information or systems has a responsibility to protect them.

3.2 Role-Based Awareness

Training should reflect the individual’s responsibilities.

For example:

  • Developers → Secure coding and secrets management
  • HR → Employee personal information
  • Finance → Payment fraud and phishing
  • IT → Privileged access and administration
  • Executives → Business email compromise and targeted attacks
  • Customer support → Customer information protection

3.3 Practical and Relevant Training

Security awareness should focus on real situations employees may encounter rather than relying solely on theoretical training.

3.4 Continuous Awareness

Security awareness should be an ongoing activity rather than a once-a-year exercise.


4. Security Awareness Program

The organization shall establish an information security awareness program appropriate to its size, risk, and business environment.

The program may include:

  • New-joiner security training
  • Periodic security awareness training
  • Role-specific training
  • Phishing awareness
  • Security newsletters
  • Security alerts
  • Security reminders
  • Incident reporting exercises
  • Security campaigns
  • Tabletop exercises
  • Phishing simulations
  • Secure development training

The organization should select activities based on identified security risks.


5. Security Training Requirements

Personnel shall receive appropriate security training covering relevant topics such as:

  • Information security responsibilities
  • Password and authentication security
  • MFA
  • Phishing and social engineering
  • Data protection
  • Acceptable use
  • Device security
  • Remote working
  • Incident reporting
  • Malware awareness
  • Safe use of email
  • Secure handling of confidential information
  • Physical security
  • Clean desk and clear screen practices where relevant
  • Use of cloud and SaaS applications

Training content should be updated when significant changes occur in the threat environment, technology, business processes, or organizational requirements.


6. New Employee Awareness

New employees should receive security awareness training as part of the onboarding process.

Training should occur within a defined period appropriate to the organization’s risk.

New-joiner training may cover:

  1. Information security policy
  2. Acceptable use
  3. Password and MFA requirements
  4. Phishing
  5. Data classification
  6. Confidentiality
  7. Incident reporting
  8. Device security
  9. Remote working
  10. Employee responsibilities

Completion should be recorded.


7. Periodic Security Awareness Training

Security awareness training shall be provided periodically.

The frequency should be determined based on organizational risk and requirements.

A startup may implement:

Annual mandatory security awareness training + periodic security reminders + targeted training when risks change.

Training should be refreshed when significant security incidents, emerging threats, technology changes, or regulatory requirements indicate a need.


8. Role-Based Security Training

Certain roles require additional security knowledge.

Developers

Training may include:

  • Secure coding
  • Dependency security
  • Secrets management
  • Code review
  • Vulnerability management
  • Secure CI/CD
  • Protection of production credentials

IT/Cloud Administrators

Training may include:

  • Privileged access
  • MFA
  • Secure configuration
  • Logging and monitoring
  • Cloud security
  • Credential management
  • Incident response

HR

Training may include:

  • Employee data protection
  • Secure employee records
  • Joiner/mover/leaver processes
  • Social engineering
  • Confidential information

Finance

Training may include:

  • Business email compromise
  • Payment fraud
  • Phishing
  • Financial information protection
  • Approval procedures

Customer Support

Training may include:

  • Customer information protection
  • Identity verification
  • Social engineering
  • Secure communication
  • Incident escalation

9. Phishing and Social Engineering Awareness

The organization shall educate personnel about common social engineering techniques.

Examples include:

  • Phishing emails
  • Spear phishing
  • Business email compromise
  • Fake login pages
  • Malicious attachments
  • Fraudulent invoices
  • Impersonation
  • Phone-based social engineering
  • Messaging-platform scams
  • QR-code phishing

Personnel should be trained to identify suspicious communications and report them through the organization’s defined reporting channel.


10. Phishing Simulations

Where appropriate, the organization may conduct controlled phishing simulations to measure and improve employee awareness.

Simulations should be:

  • Authorized
  • Controlled
  • Designed for learning
  • Appropriate to organizational risk
  • Conducted without unnecessary collection of personal information

The purpose should be to improve security awareness, not to embarrass or punish employees.

Possible metrics include:

  • Percentage of users who interacted with the simulation
  • Percentage who reported the simulation
  • Training completion
  • Improvement over time
  • Repeat-risk patterns

Results should be used to identify areas requiring additional awareness.


11. Security Incident Reporting

Employees and relevant personnel shall know how and where to report suspected security incidents.

Examples include:

  • Suspicious email
  • Lost or stolen device
  • Suspected credential compromise
  • Accidental data disclosure
  • Malware
  • Unauthorized access
  • Suspicious system activity
  • Customer data exposure
  • Phishing attempt

Employees should be encouraged to report suspected incidents promptly.

The organization should maintain a clear reporting channel, such as:

security@company.com

or an internal security/IT ticketing system.


12. Security Responsibilities

Personnel shall understand their responsibilities for protecting organizational information.

These responsibilities may include:

  • Protecting authentication credentials
  • Using MFA
  • Following information security policies
  • Protecting company devices
  • Handling information according to classification
  • Reporting security incidents
  • Not sharing credentials
  • Using approved software and services
  • Following secure remote-working practices
  • Participating in required training

13. Password and Authentication Awareness

Security awareness training shall explain the importance of protecting authentication information.

Personnel should understand:

  • Do not share passwords.
  • Do not reuse sensitive corporate passwords unnecessarily.
  • Do not store passwords insecurely.
  • Do not disclose MFA codes.
  • Do not approve unexpected MFA requests.
  • Report suspected credential compromise immediately.
  • Use approved password-management mechanisms where provided.

Training should also explain common attacks such as credential phishing and MFA fatigue/social-engineering attacks.


14. Data Protection Awareness

Personnel shall receive awareness appropriate to the information they handle.

Training may cover:

  • Confidential information
  • Customer information
  • Employee information
  • Financial information
  • Intellectual property
  • Security information
  • Source code
  • Credentials and secrets

Personnel should understand where sensitive information may be stored, transmitted, shared, or processed.


15. Remote Working Awareness

Where remote work is permitted, personnel shall receive guidance on secure remote working.

Topics may include:

  • Secure Wi-Fi
  • Device protection
  • Screen locking
  • Avoiding unauthorized devices
  • Secure handling of confidential information
  • Use of approved collaboration tools
  • Physical protection of laptops
  • Reporting lost or stolen devices
  • Secure use of public locations

16. Security Awareness for Privileged Users

Personnel with privileged access shall receive additional security awareness appropriate to their responsibilities.

Topics may include:

  • Least privilege
  • Administrative account security
  • MFA
  • Secure remote administration
  • Credential protection
  • Logging
  • Monitoring
  • Production access
  • Emergency access
  • Incident reporting

Privileged users should understand that their access creates additional security responsibilities.


17. Security Awareness for Developers

Developers with access to source code or production systems shall receive appropriate secure-development awareness.

Topics may include:

  • Secure coding
  • Authentication and authorization
  • Input validation
  • Dependency management
  • Secrets management
  • Secure API development
  • Code review
  • Vulnerability remediation
  • Security testing
  • Protection of production data

Training should be aligned with the organization’s technology stack and application-security risks.


18. Security Awareness During Employee Changes

Security responsibilities should be reinforced when employees:

  • Change roles
  • Receive additional privileges
  • Move to sensitive functions
  • Begin working with sensitive information
  • Become administrators
  • Move from development to production responsibilities

Additional role-based training may be required.


19. Training Records

The organization shall maintain appropriate records demonstrating completion of required security awareness activities.

Records may include:

  • Employee name/identifier
  • Training name
  • Training date
  • Completion status
  • Assessment result, where applicable
  • Training provider
  • Assigned role/category
  • Follow-up training

Where possible, training records should be maintained through an appropriate HR, learning-management, or compliance system.


20. Awareness Effectiveness

The organization should evaluate whether its awareness program is achieving its intended objectives.

Possible measurements include:

MetricExample
Training completion100% of required personnel
Phishing reportingIncrease in reported suspicious emails
Phishing interactionReduction over time
Incident reportingTimely reporting of security events
Assessment resultsImprovement in knowledge scores
Repeat failuresReduction in repeated awareness issues
Role-based trainingCompletion for privileged/technical roles

Metrics should be interpreted in context rather than treated as the only measure of security awareness effectiveness.


21. Security Awareness Campaigns

The organization may conduct periodic campaigns covering specific risks.

Examples:

January

Password and MFA security

March

Phishing awareness

May

Data protection

July

Secure remote working

September

Incident reporting

November

Social engineering and business email compromise

The schedule should be adapted to the organization’s risk profile.


22. Security Awareness and Incidents

Security incidents should be used as learning opportunities where appropriate.

For example:

Incident → Root Cause → Awareness Gap → Targeted Training → Follow-up Measurement

If an employee accidentally shares sensitive information, the organization may identify whether:

  • The employee understood the classification requirements.
  • The process was clear.
  • The system allowed the error.
  • Additional training is necessary.
  • A technical control should be introduced.

Security awareness should not be used as a substitute for technical or process controls when the risk requires them.


23. Management Responsibilities

Management shall support the security awareness program by:

  • Providing appropriate resources
  • Ensuring personnel complete required training
  • Supporting security culture
  • Reinforcing security responsibilities
  • Reviewing relevant awareness metrics
  • Supporting corrective actions

Security awareness should be treated as part of the organization’s security culture rather than simply an HR activity.


24. Employee Responsibilities

Employees and other personnel shall:

  • Complete required training
  • Follow security policies
  • Protect organizational information
  • Protect credentials
  • Report suspected incidents
  • Participate in required awareness activities
  • Follow role-specific security requirements
  • Ask for clarification when security requirements are unclear

25. Non-Compliance

Failure to complete mandatory security training or repeated failure to follow security requirements may result in appropriate management action in accordance with organizational policies and applicable employment or contractual requirements.

Where possible, the organization should first identify whether the issue resulted from:

  • Lack of awareness
  • Unclear procedures
  • Inadequate training
  • Technical limitations
  • Process deficiencies

Corrective action should address the underlying issue.


26. Evidence for ISO 27001 Audit

Possible evidence includes:

  • Security awareness policy
  • Annual training program
  • Training material
  • Employee training records
  • Learning-management reports
  • Security awareness presentations
  • Phishing simulation reports
  • Security newsletters
  • Awareness campaign records
  • Knowledge assessments
  • Role-based training records
  • Incident reporting exercises
  • Security metrics
  • Corrective-action records

An auditor may sample employees and verify that required training was completed and that the training was appropriate to their roles.


27. Example: SaaS Startup

Consider a 30-person SaaS startup.

A practical awareness program could include:

All Employees

  • Annual security awareness training
  • Phishing awareness
  • MFA/password security
  • Data protection
  • Incident reporting

Developers

  • Secure coding
  • Secrets management
  • Dependency security
  • Code-review security

IT/Cloud Team

  • Privileged access
  • Cloud security
  • Credential protection
  • Logging and monitoring

HR

  • Employee information protection
  • Joiner/mover/leaver security

Management

  • Business email compromise
  • Security risk
  • Incident escalation
  • Customer security commitments

This provides role-based awareness without creating an unnecessarily complex training program.


28. Quick Startup Checklist

Before considering Security Awareness operational, ask:

  • Is security awareness responsibility defined?
  • Do new employees receive security training?
  • Is periodic awareness training conducted?
  • Is training appropriate to employee roles?
  • Are developers given secure-development awareness?
  • Are privileged users given additional training?
  • Do employees know how to report incidents?
  • Is phishing/social-engineering awareness addressed?
  • Are training records maintained?
  • Is training completion monitored?
  • Is awareness effectiveness measured?
  • Are lessons from incidents incorporated into awareness activities?
  • Are awareness materials reviewed and updated?
  • Can training evidence be demonstrated during an audit?

29. ISO 27001 Connection

Security awareness supports the organization’s ISMS by ensuring that people understand the information security responsibilities relevant to their work.

It is particularly relevant to controls concerning:

  • Information security awareness, education, and training
  • Information security responsibilities
  • Acceptable use
  • Access control
  • Incident reporting
  • Secure development
  • Personnel security

The exact controls applicable to an organization should be determined through its risk assessment and Statement of Applicability.


30. Final Principle

Security awareness should not be treated as:

“Complete one online training course once a year.”

A more effective approach is:

Train → Reinforce → Test → Measure → Learn → Improve

The objective is to create an environment where employees understand:

What information needs protection, what security risks they may encounter, what is expected from them, and what they should do when something goes wrong.

For a startup, a strong security culture does not require a large training budget. It requires clear expectations, relevant training, practical examples, easy incident reporting, and continuous reinforcement.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *