# Security awareness and training policy

Source: https://aestech.com.au/policy-templates/#security-awareness-and-training-policy
Markdown URL: https://aestech.com.au/policy-templates/security-awareness-and-training-policy.md

Use for ISO 27001 A.6.3, SOC 2 Security awareness criteria, and PCI DSS requirement 12.6 training obligations.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how the company builds and maintains security awareness among its people, so that employees and contractors understand the threats relevant to their work, their obligations under company policies, and how to report security concerns.

2. Scope
This policy applies to all employees, contractors and, where relevant, temporary staff who access company systems or information, from their start date until the end of their engagement.

3. Policy statements
- All new starters must complete security awareness training before, or within [x] days of, being granted access to company systems.
- All staff must complete refresher training at least annually.
- Training content must cover, at minimum: phishing and social engineering, password and MFA practices, safe handling of confidential data, acceptable use, reporting of security events, and safe use of approved AI tools.
- Training content must be updated when policies, threats or company tooling change materially.
- Phishing simulations must be run at least [quarterly], with results used for education rather than punishment on a first failure.
- Staff who fail repeated phishing simulations must receive targeted follow-up training.
- Staff in roles with elevated risk, such as developers, administrators, finance and customer support, must receive additional role-specific training relevant to their duties, for example secure coding for developers.
- Completion of required training is a condition of continued system access, and non-completion must be escalated to the staff member and their manager.
- Awareness communications, such as alerts about current phishing campaigns, must be issued when relevant threats are identified.

4. Roles and responsibilities
- The [Security Lead] owns the awareness programme, selects training content and runs phishing simulations.
- [HR] ensures training is assigned at onboarding and tracks completion as part of the joiner process.
- Managers ensure their teams complete required training on time.
- All staff complete assigned training and apply it in their daily work.

5. Procedures
- Assign onboarding training automatically when an account is created.
- Schedule annual refresher training and send reminders before the due date.
- Run phishing simulations, record results and deliver follow-up training to repeat clickers.
- Review training content at least annually against current threats and policy changes.
- Report completion rates and simulation results to management at least [quarterly].

6. Evidence and records
Keep training completion records with dates, training content versions, phishing simulation schedules and results, follow-up training records, escalation records for non-completion, and management reports.

7. Review cadence
This policy and the training content are reviewed at least annually and after material changes to threats, tools or policies.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md