The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose: have staff and relevant outside parties know what security asks of them and do it. Guidance: build a programme aligned with the policies and procedures that reflects the information to be protected and the controls in place. It runs periodically, with initial sessions for new starters and for people moving into roles with substantially different security requirements, and understanding is tested at the end of each activity to check that knowledge transferred and the programme works. Awareness: aim to make people understand their responsibilities and how to meet them; plan by role, covering internal and external people such as consultants and supplier staff; schedule activities regularly so they repeat and reach newcomers; draw on incident lessons; and use varied physical or virtual channels (campaigns, booklets, posters, newsletters, websites, sessions, briefings, e-learning, email). Content covers management's commitment; the need to know and comply with applicable rules and obligations from policies, standards, laws, contracts and agreements; personal accountability for actions and omissions and the duty to protect the organization's and others' information; basic procedures such as reporting events (6.8) and baseline controls such as password security (5.17); and where to get further advice and material. Education and training: identify, prepare and deliver a training plan for technical teams that need particular skills to configure and maintain the required security of devices, systems, applications and services, and acquire any missing skills. Consider lectures, self-study, mentoring by experts or consultants, job rotation, hiring skilled people or consultants, delivered in classrooms, remotely, online or self-paced; technical staff keep current through publications, conferences and professional events. Other information: explain why, not only what and how, so people see how their behaviour helps or harms; the programme can be combined with other training such as privacy, ICT or safety.
This control maps to 142 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 142 it maps to, and the evidence behind each claim, over MCP and REST.