Back to all 93 controls
Annex A 6.3
People
A.6.3 Information security awareness, education and training
Staff are aware and competent.
What good looks like
Mandatory induction training, refresher training, role-based modules, phishing simulations.
Evidence an auditor will ask for
Training records, completion rates, phishing campaign results.
Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer
Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.
Certified Lead Implementer
2022 Standard Aligned
Audit-Ready Materials
Document template for this control
The Human Resources Security Policy template gives you auditor-ready wording that fulfils Annex A 6.3. Preview the full document before you download the editable version.
