ISO 27001 Security Awareness Plan: Building a Security Culture
An ISO 27001 security awareness plan is not a tick-box exercise. It is the foundation of an effective information security management system. The standard requires that every person working for or on behalf of your organisation understands their role in protecting information assets. Without a structured awareness programme, your ISMS is vulnerable to the single biggest threat to any organisation: human error.
This guide covers the full requirements of Annex A Control 6.3, how to design a programme that meets certification standards, which topics to include, how to deliver and measure training, and how to report awareness effectiveness to management. By the end, you will have a blueprint for building a security culture that lasts.
Annex A.6.3 Requirements: What the Standard Expects
ISO 27001:2022 Annex A Control 6.3 is specifically dedicated to information security awareness, education and training. It requires the organisation to ensure that persons are aware of and contribute to the effectiveness of the ISMS. This control works alongside Clause 7.3 of the main standard, which mandates that awareness of the information security policy, individual contribution, and consequences of non-compliance is established and maintained.
The key requirements under Annex A.6.3 are:
- Establish an awareness programme that covers all relevant security topics
- Deliver awareness training to all employees, contractors, and relevant third parties
- Tailor training to different roles, responsibilities, and risk exposures
- Evaluate the effectiveness of awareness activities
- Maintain records of awareness training as evidence for auditors
- Update the programme when new threats emerge or policies change
The following table maps Annex A.6.3 requirements to specific implementation actions and audit evidence.
| Annex A.6.3 Requirement | Implementation Action | Audit Evidence |
|---|---|---|
| Awareness programme exists | Documented awareness policy and schedule | Awareness programme document, annual calendar |
| Training is role-specific | Role-based training matrix | Training records by role, competency assessments |
| Ongoing engagement | Monthly communications, phishing simulations | Communication logs, simulation reports |
| Effectiveness evaluation | Knowledge tests, behavioural metrics | Quiz scores, click-rate trends, incident data |
| Records maintained | Training management system or LMS | Completion certificates, attendance sheets |
| Programme reviewed and updated | Annual review against threat landscape | Review meeting minutes, updated materials |
Designing Your Security Awareness Programme
A well-designed security awareness programme starts with a clear understanding of your organisation’s risk profile. The topics you prioritise, the depth of training you deliver, and the frequency of engagement should all reflect the specific threats your industry faces and the sensitivity of the data you handle.
The programme design process follows five stages:
- Risk assessment – Identify the human-centred risks specific to your organisation, including phishing susceptibility, data handling errors, and insider threats
- Audience analysis – Segment your workforce by role, access level, and risk exposure. Executives, IT staff, finance teams, and general staff all need different emphasis
- Topic selection – Choose awareness topics that address the identified risks. Every topic must map to a specific risk or control objective
- Method selection – Select delivery methods that suit each audience and topic. Blend formal training with ongoing reinforcement
- Evaluation planning – Define how you will measure effectiveness at each stage of the programme
The most successful programmes treat awareness as a continuous process, not an annual event. A single training session creates a spike in knowledge that fades within weeks unless reinforced. Ongoing engagement builds lasting behaviour change.
Topics to Cover in Your Awareness Plan
Annex A.6.3 does not prescribe specific topics, but certification auditors expect coverage of the most common human-centred threats. The following table outlines the essential topics every ISO 27001 security awareness plan should include.
| Topic | Why It Matters | Key Behaviours to Embed |
|---|---|---|
| Phishing and social engineering | Over 90 percent of data breaches begin with a phishing email. Employees who cannot identify a phishing attempt are your highest-risk asset | Check sender addresses, hover before clicking, report suspicious messages, never share credentials via email |
| Password security and authentication | Weak and reused passwords are the most common attack vector | Use password managers, enable multi-factor authentication, never reuse passwords across systems |
| Data handling and classification | Mishandling sensitive data leads to breaches and regulatory penalties | Classify data correctly, use approved storage and transmission methods, follow retention schedules |
| Clean desk and clear screen | Physical access to unattended devices and documents remains a common risk | Lock screens when away, secure printed documents, clear desks at end of day |
| Incident reporting | Delayed reporting multiplies the damage of any security incident | Report immediately, no blame for good-faith reporting, know the reporting channels |
| Remote and mobile working | The shift to hybrid work has expanded the attack surface significantly | Use VPNs, secure home networks, never use public Wi-Fi for sensitive work, report lost devices immediately |
Delivery Methods and Frequency
Different topics and audiences require different delivery methods. A blended approach that combines formal training with regular reinforcement is the most effective model for building lasting security habits.
| Method | Frequency | Suitable Topics | Advantage |
|---|---|---|---|
| Induction training | On hire | All core topics at introductory level | Establishes baseline from day one |
| Annual e-learning modules | Once per year | Policy refreshers, regulatory updates | Provides auditable completion records |
| Phishing simulations | Quarterly | Phishing identification | Measures actual behaviour, not just knowledge |
| Toolbox talks | Monthly | Current threats, seasonal risks | Short, focused, timely |
| Security newsletters | Monthly | Threat intelligence, tips, case studies | Maintains top-of-mind awareness |
| Posters and digital signage | Ongoing | Key reminders, reporting channels | Passive reinforcement, high visibility |
| Role-based workshops | Quarterly or bi-annually | Data handling for finance, secure coding for IT | Targeted, relevant, deeper coverage |
| Drills and tabletop exercises | Annually | Incident response, business continuity | Tests preparedness under realistic conditions |
Frequency should increase when significant threats emerge, policies change, or after a security incident. If your organisation experiences a phishing wave, schedule an immediate toolbox talk rather than waiting for the next quarterly session.
Measuring Effectiveness of Awareness Training
Measuring effectiveness is a direct requirement of both Clause 7.3 and Annex A.6.3. Many organisations mistakenly use completion rates as their only metric. Completion measures attendance, not learning or behaviour change. A robust measurement framework uses multiple indicators across knowledge, behaviour, and outcomes.
The following indicators provide a comprehensive view of programme effectiveness:
- Pre- and post-training assessments – Measure knowledge gain from each training intervention. A score improvement of less than 20 percent suggests the training needs redesigning
- Phishing simulation click rates – Track the percentage of employees who click simulated phishing emails. Target a consistent downward trend over consecutive campaigns
- Incident reporting volume and speed – An increase in genuine incident reports from employees indicates growing vigilance. Also track the time between incident occurrence and report
- Audit findings – Fewer awareness-related nonconformities in internal and external audits demonstrate programme effectiveness over time
- Policy violation trends – Reductions in policy breaches observed through security monitoring, access logs, and physical walk-throughs
- Employee surveys – Measure confidence in identifying threats, understanding of reporting processes, and perception of security culture
Reporting to Management
Top management needs regular visibility into the effectiveness of the security awareness programme. Reporting serves two purposes: it demonstrates compliance to ISO 27001 auditors, and it builds management support for continued investment in awareness.
A management report on awareness should include:
- Executive summary – Overall programme status, key achievements, and areas requiring attention
- Participation rates – Percentage of employees who completed mandatory training and engagement rates across reinforcement activities
- Effectiveness metrics – Knowledge assessment scores, phishing simulation trends, and behavioural observations
- Incident data – Number and nature of security incidents related to human factors, with trend analysis
- Benchmarking – Compare internal metrics against industry benchmarks where available
- Recommendations – Proposed changes to the programme based on data, emerging threats, and business changes
- Action items – Management decisions required, including resource allocation and policy updates
Reports should be presented at least annually as part of the management review meeting (Clause 9.3). Quarterly reporting to the information security manager is considered best practice for maintaining momentum.
Building a Sustainable Security Culture
The ultimate goal of an ISO 27001 security awareness plan is not compliance alone. It is building a security culture where every employee instinctively acts to protect information assets. Culture is the collective behaviour that persists when no-one is watching. It is built through consistent messaging, visible leadership commitment, and positive reinforcement.
Leadership must model the behaviour they expect from the workforce. When executives complete the same training, follow the same security policies, and talk about security in meetings, they signal that security is everyone’s responsibility. Celebrate employees who identify threats and report incidents. Use real examples in training materials rather than hypothetical scenarios. Over time, security becomes part of how your organisation does business, not a compliance obligation imposed from above.
Frequently Asked Questions
What is the difference between Annex A.6.3 and Clause 7.3 of ISO 27001?
Clause 7.3 sets the requirement that persons doing work under the organisation’s control are aware of the policy, their contribution, and the implications of non-compliance. Annex A.6.3 is the specific control that defines the structured awareness, education, and training programme. Clause 7.3 states that awareness must exist; A.6.3 states how to achieve it.
How often should an ISO 27001 security awareness plan be updated?
The plan itself should be reviewed and updated at least annually, or whenever significant changes occur in the threat landscape, business operations, or regulatory environment. If a new type of cyber attack becomes prevalent, update the plan immediately rather than waiting for the annual review cycle.
Do contractors and temporary staff need to complete the same awareness training?
Yes. Annex A.6.3 applies to all persons working for or on behalf of the organisation, regardless of employment status. Contractors, consultants, temporary staff, and even interns must receive awareness training appropriate to their access level. This is a common nonconformity during certification audits, so ensure your contractor onboarding process includes mandatory awareness training.
Can awareness training be outsourced to a third-party provider?
Yes. Many organisations use external providers for e-learning platforms, phishing simulation tools, and security awareness content. The organisation retains responsibility for the effectiveness of the programme. You must ensure that outsourced training meets your specific requirements and that you have access to completion records and effectiveness data for audit purposes.
How do you measure the return on investment of security awareness training?
Measure ROI by tracking reductions in security incidents attributable to human error, lower phishing click rates, faster incident reporting times, and fewer awareness-related nonconformities in audits. Quantify the cost of incidents avoided and compare against the cost of the awareness programme. Organisations with mature awareness programmes typically see a 50 to 70 percent reduction in successful phishing attacks within 12 months.
What should be included in awareness records for an ISO 27001 audit?
Auditors expect to see training attendance or completion records, assessment results demonstrating effectiveness, a documented awareness programme, a schedule of activities, and evidence of management review of awareness metrics. Records should be retained for the duration specified in your document retention policy, typically three to five years.
Start Building Your ISO 27001 Security Awareness Plan
An effective security awareness plan is achievable for any organisation, regardless of size or budget. The key is to start with a clear understanding of your risks, design a programme that addresses them, deliver it consistently, measure what matters, and report the results to management.
Contact Bitrixme today to develop an ISO 27001 security awareness plan tailored to your organisation. Message us on WhatsApp for a free consultation.