ISO/IEC 27002:2022 · International framework of information security controls

ISO/IEC 27002 compliance starting with the human element

ISO/IEC 27002:2022 dedicates an entire control to people: security awareness, education and training in information security for the whole organization. We give you those programs, the assessments and the audit evidence, mapped to the standard’s controls and segmented by audience.

Request a demo

The human element is still the entry point

According to Verizon’s DBIR report, the human element is involved in around 6 in 10 breaches. That is why ISO/IEC 27002:2022 treats security awareness as a control of its own: control 6.3 requires giving all staff training and periodic updates suited to their role, with evidence that the program exists and is sustained.

What ISO/IEC 27002 requires from you about people

The standard groups its controls into four domains, and one is dedicated entirely to people. Three controls land directly on your security awareness program.

Security awareness, education and training (control 6.3)

Control 6.3 requires all staff to receive security awareness, education and training in information security suited to their role, together with periodic updates of the relevant policies and procedures. It is the core of the people controls domain and the first one an auditor reviews.

Roles, responsibilities and employment (controls 5.2 and 6.2)

The standard requires defining and assigning information security responsibilities (control 5.2) and incorporating them into the terms and conditions of employment (control 6.2). Each person has to know their role in protecting information from day one.

Event reporting and secure conduct (controls 6.8 and 8.7)

Control 6.8 requires staff to know how to report security events through the right channels, and 8.7 to sustain secure conduct against malicious code. Training is what turns those controls into habit.

A ready-made program, segmented by audience

You do not have to build it from scratch. The content mapped to ISO/IEC 27002 comes ready and is assigned by audience in a couple of clicks, each level with its own language and focus.

More than 140 training modules mapped to ISO/IEC 27002, ready to assign Each with its exam and its reinforcement newsletters, from everyday cyber hygiene to secure information handling. ✓ Included in the base content package, not as paid add-on content

All staff

Everyday cyber hygiene, how to classify and handle information, how to spot and report anything suspicious. Habits you can apply from day one, without regulatory jargon.

Roles with specific responsibilities

For those who administer systems, handle sensitive data or lead teams: security responsibilities, supplier and ICT supply chain management, and the conduct expected in each role.

Compliance mapped to ISO/IEC 27002

Each piece of content is linked to the standard’s controls it covers. You verify the level of compliance based on the training assigned to each person.

And every piece leaves traceability: who completed what, what result they got and how they progressed. That is the evidence that turns “we train our people” into something verifiable.

More than 700 organizations sustain their program with SMARTFENSE

We have spent more than 10 years helping organizations in banking, healthcare, the public sector and critical infrastructure reduce human risk and leave auditable evidence that they do. The difference compared to a generic campaign is traceability: who was trained, what result they got, how they responded to a phishing or ransomware simulation and how they improved over time. That is the evidence an ISO/IEC 27002 audit will ask for.

Banking Healthcare Public sector Critical infrastructure Technology

Request a demo and build your program for ISO/IEC 27002

Leave us your details and we will show you how to cover control 6.3 and the rest of the people controls with content mapped to the standard, ready for your organization.