ISO 27001:2022
People controls – ISO 27001:2022

ISO 27001:2022 6.3: Information security awareness, education and training

The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose (stated in ISO/IEC 27002:2022): makes staff and relevant outside parties know and carry out their security duties. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.3.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 126 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 18 controls

  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 12.6.2 12.6.2 Awareness program reviewed annually and updated
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering
  • 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 6.2.2 6.2.2 Annual secure software training for developers
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 9.5.1.3 9.5.1.3 Training for personnel in POI environments
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

CIS Controls v8 · 11 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

NIST SP 800-53 Rev 5 · 10 controls

FedRAMP High · 9 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))

FedRAMP Moderate · 9 controls

  • AC-22 Publicly Accessible Content
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-2 Incident Response Training
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))

ISO 27701:2019 · 6 controls

  • 5.5.2 Competence
  • 5.5.3 Awareness
  • 6.3 Organization of information security
  • 6.4 Human resource security
  • 6.4.2 During employment
  • 6.6.3 User responsibilities

SOC 2 · 5 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

CMMC 2.0 · 3 controls

ISO/IEC 42001:2023 · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-181 · 3 controls

  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice

APRA CPS 234 · 2 controls

  • CPS234-15 Information Security Capability
  • CPS234-P33 Skill of Personnel Providing Control Assurance
  • SEC11-BP01 Train for application security
  • SEC11-BP08 Build a program that embeds security ownership in workload teams

C5 (Germany) · 2 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-03 Security training and awareness programme

HIPAA Security Rule · 2 controls

ISO 22301:2019 · 2 controls

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat
  • 3.2.2e Practical Exercises in Awareness Training

NIST SP 800-66 Rev 2 · 2 controls

APPI · 1 control

  • AUCDR-IS-6 Information security training and awareness program
  • AEO-10 Education, Training and Awareness

DORA · 1 control

EU AI Act · 1 control

ISO 22000:2018 · 1 control

  • 6.3 Planning of changes

ISO 27001:2013 · 1 control

  • A.7.2.2 Information security awareness, education and training

ISO 27002:2022 · 1 control

  • 6.3 Information security awareness, education and training

ISO 37301:2021 · 1 control

  • 6.3 Planning of changes

ISO 9001:2015 · 1 control

  • 6.3 Planning of changes

NIST SP 800-218 · 1 control

UK Cyber Essentials · 1 control

  • CE-SC.7 Educate Users on Strong Passwords

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 126 it maps to, and the evidence behind each claim, over MCP and REST.