SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.6.3Information security awareness, education and training

Give staff regular, role-relevant security awareness and training, and keep it current. Informed people make far fewer of the mistakes attackers rely on.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0077Password policy · ProcessrelatedThis process control gets employees actively using a password manager for unique credentials, a hygiene outcome that awareness training under A.6.3 is meant to instill.RCF-0083Remote access · ProcessrelatedThis process control sets up remote access through the approved route with training included, one specific training topic that A.6.3's broader awareness programme should cover.RCF-0388Security awareness program · PolicysupportsThis policy control establishes mandatory security awareness training at onboarding and annually thereafter, supporting A.6.3's training requirement alongside the completion tracking and role-based training the other Sekit controls provide.RCF-0389Security awareness program · ProcesssupportsThis process control runs the training cycle so employees complete it on schedule and comprehension is checked, the follow-through A.6.3 requires beyond offering a course.RCF-0390Security awareness program · TechnicalsupportsThis technical control delivers awareness content and records per-person completion automatically, the tooling that makes A.6.3's tracking requirement practical.RCF-0391Phishing simulations · PolicysupportsThis policy control mandates recurring phishing simulations with defined frequency and scope, a specific awareness exercise A.6.3 expects as part of ongoing training.RCF-0392Phishing simulations · ProcesssupportsThis process control runs phishing simulations on schedule and assigns targeted training to anyone who falls for one, closing the loop A.6.3 requires between testing and learning.RCF-0393Phishing simulations · TechnicalsupportsThis technical control sends realistic phishing simulations, measures results per campaign, and auto-assigns remediation training, the tooling behind A.6.3's phishing awareness component.RCF-0394Role-based training · PolicysupportsThis policy control defines which roles carry elevated responsibilities and what extra training they need, the role-based layer A.6.3 expects on top of general awareness.RCF-0395Role-based training · ProcesssupportsThis process control delivers role-specific training to developers and administrators on schedule and verifies completion, operationalising A.6.3's role-based training requirement.RCF-0396Role-based training · TechnicalsupportsThis technical control assigns role-specific curricula by job function and tracks completion separately, the platform capability A.6.3's role-based training relies on.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Security awareness training records
The proof that employees receive regular security training and complete it, including role-specific training.
Phishing simulation results
The proof that phishing simulations are run to test employees and the follow-up training given to those who fall for them.
From the Sekit evidence catalog

In practice

In practice this means every employee completes a training module at onboarding and again at least once a year, with completion tracked per person rather than assumed. Auditors ask for the training records and the phishing simulation results together, since a company that trains but never tests, or tests but never trains the people who click, is common. The usual failure mode is a training platform that reports course assignment but not completion, so the record shows everyone was invited and nobody can confirm who finished it.

Common gaps

Security awareness training records show course assignment but not completion, so there is no proof anyone finished the training.
Phishing simulation results exist for the last campaign only, with no evidence that employees who clicked received the required follow-up training.
Role-based training for developers and administrators was never defined separately from the general awareness course everyone else takes.

Questions your auditor will ask

Can you show training completion, not enrollment alone, for all employees?
Security awareness training records list per-person completion dates from the training platform, distinct from the list of who was assigned the course.
What happens to an employee who clicks a simulated phishing email?
Phishing simulation results trigger automatic assignment of targeted follow-up training to that person, tracked to completion.
Do developers and administrators get training different from general staff?
Role-based training records show a separate curriculum assigned by job function for elevated roles, tracked apart from general awareness completion.
How often is phishing simulation run and how is the schedule set?
A written policy sets the recurring cadence, and simulation results are logged campaign by campaign against that schedule.

Where regulation demands it

NIS2 8.1 requires awareness raising and basic cyber hygiene, the baseline training A.6.3 asks every employee to complete.
ENS mp.per.4 requires formación, directly matching the role-based and general security training this control expects.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.6.3?”
Also via MCP, free with account