ISO/IEC 27002:2022 dedicates an entire control to people: security awareness, education and training in information security for the whole organization. We give you those programs, the assessments and the audit evidence, mapped to the standard’s controls and segmented by audience.
Request a demoAccording to Verizon’s DBIR report, the human element is involved in around 6 in 10 breaches. That is why ISO/IEC 27002:2022 treats security awareness as a control of its own: control 6.3 requires giving all staff training and periodic updates suited to their role, with evidence that the program exists and is sustained.
The standard groups its controls into four domains, and one is dedicated entirely to people. Three controls land directly on your security awareness program.
Control 6.3 requires all staff to receive security awareness, education and training in information security suited to their role, together with periodic updates of the relevant policies and procedures. It is the core of the people controls domain and the first one an auditor reviews.
The standard requires defining and assigning information security responsibilities (control 5.2) and incorporating them into the terms and conditions of employment (control 6.2). Each person has to know their role in protecting information from day one.
Control 6.8 requires staff to know how to report security events through the right channels, and 8.7 to sustain secure conduct against malicious code. Training is what turns those controls into habit.
You do not have to build it from scratch. The content mapped to ISO/IEC 27002 comes ready and is assigned by audience in a couple of clicks, each level with its own language and focus.
Everyday cyber hygiene, how to classify and handle information, how to spot and report anything suspicious. Habits you can apply from day one, without regulatory jargon.
For those who administer systems, handle sensitive data or lead teams: security responsibilities, supplier and ICT supply chain management, and the conduct expected in each role.
Each piece of content is linked to the standard’s controls it covers. You verify the level of compliance based on the training assigned to each person.
And every piece leaves traceability: who completed what, what result they got and how they progressed. That is the evidence that turns “we train our people” into something verifiable.
We have spent more than 10 years helping organizations in banking, healthcare, the public sector and critical infrastructure reduce human risk and leave auditable evidence that they do. The difference compared to a generic campaign is traceability: who was trained, what result they got, how they responded to a phishing or ransomware simulation and how they improved over time. That is the evidence an ISO/IEC 27002 audit will ask for.
Leave us your details and we will show you how to cover control 6.3 and the rest of the people controls with content mapped to the standard, ready for your organization.