ISO 27002:2022
People controls – ISO 27002:2022

ISO 27002:2022 6.3: Information security awareness, education and training

The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose: have staff and relevant outside parties know what security asks of them and do it. Guidance: build a programme aligned with the policies and procedures that reflects the information to be protected and the controls in place. It runs periodically, with initial sessions for new starters and for people moving into roles with substantially different security requirements, and understanding is tested at the end of each activity to check that knowledge transferred and the programme works. Awareness: aim to make people understand their responsibilities and how to meet them; plan by role, covering internal and external people such as consultants and supplier staff; schedule activities regularly so they repeat and reach newcomers; draw on incident lessons; and use varied physical or virtual channels (campaigns, booklets, posters, newsletters, websites, sessions, briefings, e-learning, email). Content covers management's commitment; the need to know and comply with applicable rules and obligations from policies, standards, laws, contracts and agreements; personal accountability for actions and omissions and the duty to protect the organization's and others' information; basic procedures such as reporting events (6.8) and baseline controls such as password security (5.17); and where to get further advice and material. Education and training: identify, prepare and deliver a training plan for technical teams that need particular skills to configure and maintain the required security of devices, systems, applications and services, and acquire any missing skills. Consider lectures, self-study, mentoring by experts or consultants, job rotation, hiring skilled people or consultants, delivered in classrooms, remotely, online or self-paced; technical staff keep current through publications, conferences and professional events. Other information: explain why, not only what and how, so people see how their behaviour helps or harms; the programme can be combined with other training such as privacy, ICT or safety.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 142 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 17 controls

  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.6.2 12.6.2 Awareness program reviewed annually and updated
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.6.3.1 12.6.3.1 Awareness training covers phishing and social engineering
  • 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 6.2.2 6.2.2 Annual secure software training for developers
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 9.5.1.3 9.5.1.3 Training for personnel in POI environments
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

NIST SP 800-53 Rev 5 · 11 controls

CIS Controls v8 · 10 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.2 Train Workforce Members to Recognize Social Engineering Attacks
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure
  • CIS-14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding

FedRAMP High · 10 controls

  • AC-22 Publicly Accessible Content
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))

FedRAMP Moderate · 10 controls

  • AC-22 Publicly Accessible Content
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • AT-2(3) Social Engineering and Mining
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • CP-3 Contingency Training
  • IR-9(2) Information Spillage Response | Training (IR-9(2))
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))
  • ISM-0252 Annual cyber security awareness training content
  • ISM-1565 Annual tailored privileged user training
  • ISM-2004 Supporting cyber skills development
  • ISM-2022 Cyber security awareness training register

ISO 22301:2019 · 4 controls

  • 7.2 Competence
  • 7.3 Awareness
  • 7.4 Communication
  • 8.5 Exercise programme

ISO 27701:2019 · 4 controls

  • 16.7.46.C.01 16.7.46.C.01 User training on MFA risks and safe use
  • 19.5.29.C.01 19.5.29.C.01 User awareness training for VoIP and UC
  • 22.1.27.C.01 22.1.27.C.01 User awareness and training for cloud services
  • 9.1.5.C.01 9.1.5.C.01 Ongoing security awareness and training programme for personnel

SOC 2 · 4 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

CMMC 2.0 · 3 controls

HIPAA Security Rule · 3 controls

ISO/IEC 42001:2023 · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-181 · 3 controls

  • B.6.12 B.6.12 Training of users and administrators
  • B.8 B.8 Personnel: involving people and choosing a security staffing model
  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice
  • SEC11-BP01 Train for application security
  • SEC11-BP08 Build a program that embeds security ownership in workload teams

C5 (Germany) · 2 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-03 Security training and awareness programme

ISO/IEC 27042:2015 · 2 controls

  • 10.1 10.1 Overview
  • 10.3 10.3 Recording competence

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat
  • 3.2.2e Practical Exercises in Awareness Training

NIST SP 800-66 Rev 2 · 2 controls

NY DFS 23 NYCRR 500 · 2 controls

  • §500.10 Cybersecurity Personnel and Intelligence
  • §500.14 Monitoring and Training
  • 0015 0015 Security practitioners have access to training
  • 0024 0024 Security awareness training at engagement and annually

APRA CPS 234 · 1 control

  • AUCDR-IS-6 Information security training and awareness program
  • AEO-10 Education, Training and Awareness

DORA · 1 control

  • EBA-GL-3.4.7 Information security training and awareness

ISO 27001:2022 · 1 control

  • 6.3 Information security awareness, education and training

ISO/IEC 27037:2012 · 1 control

  • 6.4 6.4 Competency

MTCS (Singapore) · 1 control

  • 7.7 Information security training and awareness

NIST SP 800-218 · 1 control

  • TSA-SD-11 Cybersecurity training and awareness
  • TSA-PSG-08 Security awareness training

UK Cyber Essentials · 1 control

  • CE-SC.7 Educate Users on Strong Passwords
  • MTSA-Training-Cyber Cybersecurity Training and Awareness

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 142 it maps to, and the evidence behind each claim, over MCP and REST.