Skip to content

Security Awareness

What is Security Awareness?

The knowledge and understanding that employees have about cybersecurity threats and their role in protecting organizational information assets.

Information Security

Each of these is named in at least one of the same controls as security awareness. The number is how many controls name both.

What the standards actually require on security awareness

Requirements naming security awareness across 6 standards, quoted from the control text.

PCI DSS 4.05 controls

Personnel receive security awareness training upon hire and at least once every 12 months, covering threats and vulnerabilities including phishing, social engineering, and acceptable use.

12.6.3 · Security awareness training delivered

A cyber security awareness training register is developed, implemented and maintained.

ISM-2022 · A cyber security awareness training register is developed, implemented and maintained.
CIS Controls v82 controls

Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, (OWASP® Top 10 vulnerability awareness and prevention training for web application developers, and advanced...

CIS-14.9 · Conduct Role-Specific Security Awareness and Skills Training
OSFI B-132 controls

Operate cyber hygiene + security awareness per OSFI B-13 Domain 5. Cyber hygiene must (a) maintain patch management with risk-based prioritisation + KEV-driven remediation + (b) configuration management with hardened baselines + drift detection + (c) vulnerabi...

OSFIB13-5 · Cyber Hygiene and Security Awareness

The applicant makes employees aware of the importance of maintaining the security of personal information, for example through regular training and oversight.

CBPR-PR-29 · Employee security awareness

Implement a security awareness programme for all personnel including role-based training for operational technology staff.

AWWA-1.3 · Security Awareness and Training

Questions people ask about security awareness

What is Security Awareness?
The knowledge and understanding that employees have about cybersecurity threats and their role in protecting organizational information assets.
Why is Security Awareness important for compliance?
Security Awareness is a key concept in Information Security. Understanding security awareness helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Awareness?
Security Awareness appears in the requirement text of PCI DSS 4.0, Australian Information Security Manual, CIS Controls v8, OSFI B-13, APEC Cross-Border Privacy Rules (CBPR) System. Across these standards we have identified 15 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Awareness?
Explore our compliance framework pages to see how security awareness applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Awareness applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.