Sekit CSF · Training & Awareness · Process
RCF-0392Phishing simulations
Phishing simulations are consistently run and employees who fall for them receive immediate targeted training
Mapping at a glance
RCF-0392Phishing simulationsTraining & Awareness · Process
RCF-0392 maps to 4 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.6.3Information security awareness, education and trainingsupportsThis process control runs phishing simulations on schedule and assigns targeted training to anyone who falls for one, closing the loop A.6.3 requires between testing and learning.A.8.7Protection against malwareenablesThe process facet runs phishing simulations on schedule and gets employees who click into targeted follow-up training promptly.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Phishing simulation results
The proof that phishing simulations are run to test employees and the follow-up training given to those who fall for them.
From the Sekit evidence catalog
This topic through the other lenses
All Training & Awareness controls
Ask Sekura: “What evidence proves RCF-0392?”
Also via MCP, free with account