HRS-004 Security Awareness Training
Description
All personnel complete a security awareness training programme at onboarding and at least annually thereafter. Training content covers the organisation's current threat landscape, security policies, phishing and social engineering awareness, acceptable use, incident reporting, privacy obligations and the recognition and reporting of potential insider threat indicators. Completion is tracked and reported. Where a customer contract sets conditions for personnel assigned to that customer's service to take part in the customer's own security awareness programme or its operational resilience training, the training record identifies that training per person with its completion date, so completion is producible to that customer.
Rationale
People are the most frequently exploited attack vector, and consistent documented training reduces successful social engineering and inadvertent policy violations. Insider threat indicators are the topic personnel are least equipped to act on without being taught. The signals are behavioural, not technical. The people best placed to notice them are colleagues rather than the security team, and the reporting route is usually not the one used for a suspicious email. GOV-027 requires the programme; this control carries the training content that feeds it. A customer's curriculum is somebody else's content sitting on the organisation's own record, which is why it goes missing: it is completed in the customer's system and never lands anywhere the organisation reports from. Held per person against the customer's service, the record answers a contractual condition without anyone assembling an email trail during an audit. HRS-005 holds role-based training content; the record of a customer-required completion sits here.
Applicability (9 profiles)
EX-96 written in S8 wave B (migration 057). The training record now identifies, for each person assigned to a customer's service, the training that customer required and its completion date, and the export can be filtered to that customer, so Art. 30(2)(i) holds full and completion is producible to the customer. HRS-005 holds role-based training content; the record of a customer-required completion sits on HRS-004.
Annex point 8.1.1 widens the audience beyond personnel to members of management bodies as a named group and to direct suppliers and service providers where appropriate under point 5.1.4. Point 8.1.3 requires the effectiveness of the programme to be tested, which is a measurement of the training rather than of completion.
Framework Mappings (26)
| HRS-11 | Security Awareness Training | full |
| HRS-12 | Personal and Sensitive Data Awareness and Training | full |
| HRS-13 | Compliance User Responsibility | partial |
| HRS-11 | Security Awareness Training | full |
| HRS-12 | Personal and Sensitive Data Awareness and Training | full |
| HRS-13 | Compliance User Responsibility | partial |
| DORA-Art.30.2.i | Participation in security awareness and resilience training | full |
| EU-AI-Art.4 | AI Literacy — Measures to Support Staff and Operator Literacy | informative |
| HIPAA-164.306.a | General Requirements | informative |
| HIPAA-164.308.a.5.i | Security Awareness and Training | full |
| HIPAA-164.308.a.5.ii.A | Security Reminders | full |
| HIPAA-164.308.a.5.ii.B | Protection from Malicious Software | informative |
| 6.3 | Information security awareness, education and training | full |
| AML.M0018 | User Training | informative |
| NIS2-Art.20.2 | Management Body Cybersecurity Training | informative |
| NIS2-Art.21.2.g | Basic Cyber Hygiene Practices and Cybersecurity Training | partial |
| NIS2-CIR-10.1 | Human Resources Security | informative |
| NIS2-CIR-8.1 | Awareness Raising and Basic Cyber Hygiene Practices | partial |
| NIS2-CIR-8.2 | Security Training | informative |
| AT-1 | Policy and Procedures | partial |
| AT-2 | Literacy Training and Awareness | full |
| AT-2(2) | Literacy Training and Awareness | Insider Threat | full |
| AT-2(3) | Literacy Training and Awareness | Social Engineering and Mining | full |
| AT-4 | Training Records | full |
| GOVERN 2.2 | AI Risk Management Training | informative |
| CC2.2 | COSO Principle 14: Communicates Internally | partial |
Evidence (2)
Security awareness training completion records showing all personnel completed training at onboarding and annually thereafter. Where a customer contract requires it, the export also identifies the training that customer set for personnel assigned to its service.
Example: Training completion report from the LMS or security awareness platform (KnowBe4, Proofpoint Security Awareness, or equivalent), showing: employee name, training module, completion date, and score (if applicable), filtered to the current training cycle.
Test: Export the training completion records for the current annual cycle. Verify: (1) the completion rate meets or exceeds the defined target, (2) every new hire has a completion record dated within 30 days of their start date, (3) the training content covers phishing awareness, acceptable use, incident reporting, privacy obligations and the recognition and reporting of insider threat indicators, (4) non-completions carry an open remediation action, (5) the reporting route taught for an insider threat indicator is named in the material and is reachable. (6) for a customer whose contract sets training conditions, every person assigned to that customer's service carries the required training with a completion date, and the export can be filtered to that customer without hand assembly.
Training effectiveness report or phishing simulation results showing the awareness programme is evaluated for effectiveness.
Example: Annual security awareness report or phishing simulation report (KnowBe4 / Proofpoint campaign report PDF), showing: simulation frequency, click rate trend over the year, comparison to benchmark, and curriculum changes made in response to results.
Test: Request the most recent security awareness programme report or phishing simulation results. Verify: (1) simulations were conducted at least quarterly, (2) click rate trend over the year is tracked, (3) results informed training content updates (confirm a curriculum change or targeted follow-up training triggered by high-click-rate cohorts), (4) the report was reviewed by the security team.
Questions (3)
Do all personnel complete a security awareness training programme at onboarding and at defined intervals thereafter?
Training records from the LMS or awareness platform should show completion rates at or above the defined target (typically 95%+), with new hires completing within 30 days of their start date.
Which of the following topics are included in your annual security awareness training curriculum?
Options run from the most commonly covered to the least. Phishing awareness, acceptable use, incident reporting and privacy obligations are the minimum. Insider threat indicators are behavioural, not technical. The colleagues best placed to notice them are not on the security team, and the reporting route is usually not the one used for a suspicious email, so the topic has to be taught.
Does your organisation evaluate the effectiveness of its security awareness programme (e.g. through phishing simulations, quiz scores, or click rate trends)?
Phishing simulation results showing click rate trends over the year, with curriculum changes triggered by high-risk cohorts, demonstrate programme effectiveness.