General security competence and awareness of personnel

Critical
High
Normal
Low

Personnel under the direction of the entire organization must be aware:

  • how they can contribute to the effectiveness of the information security management system and the benefits of improving the level of information security
  • the consequences of non-compliance with the requirements of the information security management systemwhich roles in the personnel have effects to the level of security

In addition, top management has defined ways in which personnel are kept aware of security guidelines related to their own job role.

Connected other frameworks and requirements:
32. Security of processing
GDPR
29. Processing under the authority of the controller or processor
GDPR
7.2.2: Information security awareness, education and training
ISO 27001
7.2.1: Management responsibilities
ISO 27001
PR.AT-1: Awareness
NIST CSF

Maintaining a log of cyber security trainings

Critical
High
Normal
Low

A log is kept of the cyber security training events provided by the organization to its staff. The log can be used to show what kind of specific investments the organization has made towards staff's cyber security expertise.

For each training the documentation should include:

  • Time
  • Topics and duration of the training
  • Training method and trainer
  • Staff involved in the training
Connected other frameworks and requirements:
T11: Turvallisuuskoulutus ja -tietoisuus
7.2.2: Information security awareness, education and training
ISO 27001
PR.AT-1: Awareness
NIST CSF
6.3: Information security awareness, education and training
ISO 27001
8.4 (MIL1): Develop Cybersecurity Workforce
C2M2
No items found.