ISO/IEC 27000 Information Security Awareness, Education and Training, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security awareness, education and training.

Assessment Step

1
Information Security Awareness, Education and Training (InformationSecurityAwarenessEducationandTraining)
Do personnel and relevant interested parties receive appropriate information security awareness, education, training, and regular updates of the organization's information security policy, topic-specific policies, and procedures, as relevant to their job function?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Information Security Awareness, Education and Training
Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organization's information security policy, topic-specific policies and procedures, as relevant for their job function.
Citations
27001
Annex A, Control 6.3
27002
Section 6.3