A.6.3Information security awareness, education and training
Give staff regular, role-relevant security awareness and training, and keep it current. Informed people make far fewer of the mistakes attackers rely on.
Mapping at a glance
A.6.3Information security awareness, education and trainingISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
Phishing simulation results
The proof that phishing simulations are run to test employees and the follow-up training given to those who fall for them.
From the Sekit evidence catalog
In practice
In practice this means every employee completes a training module at onboarding and again at least once a year, with completion tracked per person rather than assumed. Auditors ask for the training records and the phishing simulation results together, since a company that trains but never tests, or tests but never trains the people who click, is common. The usual failure mode is a training platform that reports course assignment but not completion, so the record shows everyone was invited and nobody can confirm who finished it.
Common gaps
Security awareness training records show course assignment but not completion, so there is no proof anyone finished the training.
Phishing simulation results exist for the last campaign only, with no evidence that employees who clicked received the required follow-up training.
Role-based training for developers and administrators was never defined separately from the general awareness course everyone else takes.
Questions your auditor will ask
Can you show training completion, not enrollment alone, for all employees?
Security awareness training records list per-person completion dates from the training platform, distinct from the list of who was assigned the course.
What happens to an employee who clicks a simulated phishing email?
Phishing simulation results trigger automatic assignment of targeted follow-up training to that person, tracked to completion.
Do developers and administrators get training different from general staff?
Role-based training records show a separate curriculum assigned by job function for elevated roles, tracked apart from general awareness completion.
How often is phishing simulation run and how is the schedule set?
A written policy sets the recurring cadence, and simulation results are logged campaign by campaign against that schedule.
Where regulation demands it
NIS2 8.1 requires awareness raising and basic cyber hygiene, the baseline training A.6.3 asks every employee to complete.
ENS mp.per.4 requires formación, directly matching the role-based and general security training this control expects.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.