Information Security Management
Mandatory Security Awareness Training
All employees undergo mandatory security awareness training on an annual basis. Certain higher risk roles go through additional training specific for their role and its associated risks, annually.
How it is checked
Annually for everyone, with extra role-specific training for higher-risk roles.
Framework requirements this speaks to
- ISO 27001 A.6.3 (awareness, education and training)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.