All articlesSecurity awareness

Security awareness for ISO 27001: what the control requires

Security awareness for ISO 27001: what the control requires

In short

  • Awareness in ISO 27001 sits in clauses 7.2 and 7.3 and Annex A control 6.3.
  • Awareness, training and competence are separate obligations; one generic course rarely covers all three.
  • It applies to everyone under the organisation's control, including management and contractors.
  • Phishing simulations are not literally required, but they are the clearest proof that training works.
  • Auditors check records, role-based content, updates, and ask staff how they would report an incident.

What does ISO 27001 require for security awareness?

ISO/IEC 27001:2022 requires everyone working under the organisation's control to know the security policy, their contribution to the management system and the consequences of not following it (clause 7.3), and to be competent for their role (clause 7.2). Annex A control 6.3 requires regular, role-relevant awareness and training, which the auditor verifies through evidence.

ISO 27001 security awareness looks like the easiest requirement in the standard. Send a presentation, collect a signature, move on. It is also one of the requirements auditors most often find hollow, because the standard asks for something more specific than a yearly course: people who know the policy, understand their part in the management system, are competent for their role, and can prove it. This guide sets out exactly what ISO/IEC 27001:2022 requires, where it says so, what a programme that satisfies it contains, and the evidence an auditor will ask to see.

Where ISO 27001 sets the requirement

The requirement is spread across three places, and a programme built on only one of them usually has gaps.

Clause 7.3, Awareness. Everyone doing work under the organisation's control must be aware of three things: the information security policy; their contribution to the effectiveness of the information security management system, including the benefits of better security performance; and the implications of not conforming with the system's requirements. Clause 7.3 is a management-system clause, so it cannot be excluded in the Statement of Applicability.

Clause 7.2, Competence. The organisation must determine the competence needed by people whose work affects information security, make sure they have it through education, training or experience, take action where they do not and evaluate whether that action worked, and keep documented information as evidence of competence.

Annex A control 6.3, Information security awareness, education and training. Personnel and relevant interested parties must receive appropriate awareness, education and training, plus regular updates on the organisation's security policy, topic-specific policies and procedures, as relevant to their job function. In the 2013 edition of the standard this was control A.7.2.2; certificates issued against the 2013 edition expired on 31 October 2025, so any programme still mapped to the old numbering needs updating.

Clause 7.4 on communication and several people controls in Annex A connect to it: 5.4 on management responsibilities, 6.2 on terms of employment, 6.4 on the disciplinary process and 6.8 on reporting security events. An auditor will read them together.

Awareness, training and competence are three different obligations

The standard deliberately separates the three, and treating them as one is the most common design mistake.

  • Awareness is knowing: what the policy says, why it matters, what happens if it is ignored, and how to report something suspicious. It applies to everyone.
  • Training is being able to do something: handle personal data correctly, configure a system securely, respond to an incident. It applies to specific roles.
  • Competence is the demonstrated result: the right people have the skills their role requires, and there is a record showing it.

A single company-wide module can deliver awareness. It cannot, on its own, show that the system administrator is competent to manage privileged access, or that the developer understands secure coding. That is why an auditor who sees one generic course for everyone will ask how role-specific competence is covered.

Who the requirement covers

Clause 7.3 applies to "persons doing work under the organisation's control", which is wider than the payroll. It includes permanent staff, temporary staff and interns, management and the board, and contractors or outsourced staff who access the organisation's systems or information. Control 6.3 extends it to relevant interested parties, which in practice means suppliers with access to in-scope systems.

Two groups are routinely missed. The first is management, who are often assumed to know already and never appear in the training records. The second is contractors, who sit outside the HR system that drives training assignments. Both gaps are easy for an auditor to find: they ask for the list of people with access to in-scope systems and compare it with the training records.

What a programme that meets the control contains

A defensible awareness programme is not a single event. It has six components.

  1. An onboarding baseline. Every new joiner receives the security policy, the acceptable use rules and the reporting procedure before or immediately after they get access, and acknowledges them. This covers clause 7.3 from day one.
  2. Role-based modules. Content matched to what each role can break: secure coding for developers, privileged access and change management for administrators, payment fraud and invoice manipulation for finance, data handling for HR and support, targeted phishing for executives and their assistants.
  3. A clear reporting habit. The single most valuable behaviour an awareness programme can build is reporting. People should know exactly how to report a suspicious email, a lost device or a mistake, and should see that reports are welcomed. This links directly to control 6.8.
  4. Practical exercises. Phishing simulations and short scenario exercises test behaviour, not recall.
  5. A defined cadence. The standard does not set a frequency, so the organisation must define one and keep to it. A common and defensible pattern is onboarding, short regular updates through the year, and an annual refresher.
  6. Update triggers. Content changes when the threats, the policy or the systems change: a new tool, a new type of attack reaching staff, or a lesson from an incident.

Are phishing simulations required?

ISO 27001 does not literally require phishing simulations. What it does require, in clause 7.2, is that the organisation evaluates whether its competence actions were effective. A completion record shows that someone watched a module; it says nothing about whether their behaviour changed. Simulations are the most direct way to measure that change, which is why auditors increasingly expect them, or an equivalent practical test.

Run them in a way that builds trust rather than fear. Tell staff that a simulation programme exists, even if individual campaigns are not announced. Treat a click as a training moment, not a disciplinary matter. Collect only the data the programme needs: under the GDPR, any monitoring of employees should be proportionate to its purpose and transparent, the same principle that applies to other people controls such as device management. If you need a starting point, Spain's national cybersecurity institute publishes a free INCIBE awareness kit for companies, which includes simulated attacks to measure staff before and after a training plan.

How to measure whether it works

Clause 9.1 asks the organisation to monitor and measure the performance of its management system, and awareness is a natural place to show it. Useful measures include:

  • Completion rate for onboarding and role-based modules, by team.
  • Reporting rate in simulations: the share of people who report the email, which matters more than the share who click.
  • Click rate trend over successive campaigns, rather than any single result.
  • Time to report a simulated or real phishing email.
  • Repeat clickers, who need a different intervention rather than the same module again.
  • Incidents with a human cause, reviewed to decide what the next content should cover.

The context for all of this is well documented. The Verizon Data Breach Investigations Report published in April 2025 found a human element in about 60% of the breaches it analysed, including credential abuse, social engineering and errors. Awareness does not remove that risk, but it is the control designed to reduce it.

The evidence an auditor asks for

In both the certification audit and every surveillance audit, the auditor will look for:

  • A documented awareness and training plan, with audiences, content and cadence.
  • Records of who completed what and when, including new joiners during the period.
  • Evidence that content differs by role, and a record of role competence requirements under clause 7.2.
  • Acknowledgement of the security policy by staff and in-scope contractors.
  • Results of phishing simulations or other practical tests, and what was done with them.
  • Evidence that content was updated when threats, policies or systems changed.

They will also test it directly. A common technique is to pick an employee at random and ask how they would report a suspicious email, or where they would find the security policy. If the answer does not match the documented procedure, the records alone will not carry the control.

Why this control fails audits

The failure pattern is consistent: awareness is treated as a formality. A slide deck is emailed once a year, nobody records who read it, it never changes, and it is the same for the finance team and the system administrators. At an initial audit this often surfaces as a minor non-conformity. At a surveillance audit, when the auditor is checking that the management system has kept operating, an awareness programme that stopped after certification is evidence that it has not. This is one of the first signs of a certification that is drifting, the situation covered in our guide to restarting a stalled ISO 27001 project.

One programme for ISO 27001, ENS and NIS2

Many Spanish companies have more than one framework to satisfy, and awareness is where they overlap most cleanly. The Esquema Nacional de Seguridad includes awareness and training as measures mp.per.3 and mp.per.4 in Annex II of Royal Decree 311/2022, and they are among the measures an auditor checks in an ENS audit. The NIS2 Directive requires members of management bodies to follow cybersecurity training (Article 20) and lists basic cyber hygiene and cybersecurity training among the required risk-management measures (Article 21). A single programme, with records mapped to each framework, can serve all three, in the same way that ISO 27001 and ENS can run as one programme.

A twelve-month awareness calendar

  • Continuously: onboarding baseline for every new joiner and contractor before or at access.
  • Monthly: a short update or micro-module on a current threat or a policy point.
  • Quarterly: a phishing simulation, followed by targeted training for those who need it and a note to everyone on what the campaign showed.
  • Twice a year: role-based sessions for high-risk functions such as administrators, developers and finance.
  • Annually: a full refresher, a review of the programme's metrics, and an update to the plan fed into the management review.
  • After any significant incident: content that addresses what happened.

Running awareness as an operated control

Meeting control 6.3 sustainably means turning awareness into a process that runs on its own and leaves a trail, rather than an event someone remembers before the audit. Qalea operates this as part of its People area: continuous training matched to roles, regular phishing simulations, and records that build up automatically and map to the ISO 27001 clauses and controls they support, alongside device management and endpoint protection on the same people layer. The aim is a control that is always in an auditable state, because it is always running. More on the standard itself is on our ISO 27001 page, with related guides on our ISO 27001 hub and our security awareness hub.

Frequently asked questions

How often does ISO 27001 require security awareness training?

ISO 27001 does not set a number of sessions per year. It requires awareness and training to be regular and relevant to each role, and the organisation must define its own cadence and keep to it. A common, defensible pattern is training at onboarding, short updates through the year and an annual refresher.

Is a single annual course enough to meet control 6.3?

Rarely. One generic annual course with no link to roles, no attendance records and no updates does not usually demonstrate compliance with control 6.3. The control asks for awareness, education and training relevant to each job function, plus evidence that it is delivered and kept current.

Are phishing simulations mandatory for ISO 27001?

ISO 27001 does not literally require phishing simulations. Clause 7.2 does require the organisation to evaluate whether its training actions were effective, and simulations are the most direct way to show a change in behaviour, so many auditors expect them or an equivalent practical test.

What awareness evidence will an ISO 27001 auditor ask for?

Typically a documented training plan, records of who completed which training and when, evidence that content differs by role, policy acknowledgements, results of phishing simulations or practical tests, and proof that content is updated. Auditors also interview staff at random to check that the training reached them.

Does ISO 27001 awareness apply to management and contractors?

Yes. Clause 7.3 covers everyone doing work under the organisation's control, which includes management, temporary staff and contractors with access to in-scope systems or information. Control 6.3 extends awareness to relevant interested parties such as suppliers. Management and contractors are the groups auditors most often find missing from records.

More articles

All articles