Skip to content

Security Awareness Training

What is Security Awareness Training?

Educational programmes designed to teach employees about security risks and best practices. Training covers topics such as phishing recognition, password hygiene, data handling, and incident reporting. Required by ISO 27001, HIPAA, PCI DSS, and NIST CSF.

Information Security

Each of these is named in at least one of the same controls as security awareness training. The number is how many controls name both.

What the standards actually require on security awareness training

Requirements naming security awareness training across 6 standards, quoted from the control text.

A cyber security awareness training register is developed, implemented and maintained.

ISM-2022 · A cyber security awareness training register is developed, implemented and maintained.
PCI DSS 4.03 controls

Personnel receive security awareness training upon hire and at least once every 12 months, covering threats and vulnerabilities including phishing, social engineering, and acceptable use.

12.6.3 · Security awareness training delivered
BSIMM1 control

Training. Software security awareness training is conducted so developers and stakeholders understand secure development expectations.

T1.1 · Conduct software security awareness training

Run a security awareness training programme for all employees and refresh the training on a regular cycle.

CCM-HRS-11 · Security Awareness Training

Personnel must receive security awareness training appropriate to their role and the entity's membership level.

DISP-PERS-AWARENESS · Security awareness training

Provide CJIS security awareness training to all personnel with access to criminal justice information at hire and at least every two years.

CJIS-5.2 · Security Awareness Training

Questions people ask about security awareness training

What is Security Awareness Training?
Educational programmes designed to teach employees about security risks and best practices. Training covers topics such as phishing recognition, password hygiene, data handling, and incident reporting. Required by ISO 27001, HIPAA, PCI DSS, and NIST CSF.
Why is Security Awareness Training important for compliance?
Security Awareness Training is a key concept in Information Security. Understanding security awareness training helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Awareness Training?
Security Awareness Training appears in the requirement text of Australian Information Security Manual, PCI DSS 4.0, BSIMM, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Defence Industry Security Program (DISP). Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Awareness Training?
Explore our compliance framework pages to see how security awareness training applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Awareness Training applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.