Security Awareness Training Policy
Document owner: Chief Information Security Officer (CISO)
Version: 3.0
Effective date: January 1, 2026
Last updated: January 15, 2026
Classification: Public — Trust Center
Review cadence: Annual review; updates for emerging threats
Company: Acme Cloud, Inc.
Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA
Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com
Definitions and Key Terms
| Term | Definition |
|---|
| Security Awareness | The knowledge and attitude members of an organization possess regarding the protection of physical and information assets |
| Phishing | A type of social engineering attack using fraudulent communications to deceive recipients into revealing sensitive information |
| Social Engineering | Psychological manipulation techniques used to trick people into making security mistakes or giving away sensitive information |
| Spear Phishing | Targeted phishing attacks directed at specific individuals or organizations using personalized information |
| Business Email Compromise (BEC) | A type of scam targeting organizations that conduct wire transfers, using compromised business email accounts |
| Malware | Malicious software designed to damage, disrupt, or gain unauthorized access to computer systems |
| Ransomware | Malware that encrypts files and demands payment for decryption |
| Multi-Factor Authentication (MFA) | A security mechanism requiring two or more verification factors to gain access |
| Password Manager | Software that securely stores and manages passwords |
| Clean Desk Policy | Requirements for securing sensitive information when leaving a workstation unattended |
| Data Classification | The process of categorizing data based on its sensitivity and the impact of unauthorized disclosure |
| Privileged Access | Elevated system access rights that allow administrative functions |
| Insider Threat | Security risks that originate from within the organization, whether intentional or accidental |
| Incident | A security event that has been identified and requires investigation or response |
| Compliance Training | Training required to meet regulatory or contractual obligations |
| Learning Management System (LMS) | Software application for administering, tracking, and delivering training courses |
| Security Champion | A development team member with additional security responsibilities |
| Tabletop Exercise | A discussion-based exercise where participants review and discuss responses to scenarios |
| Phishing Simulation | Controlled test phishing campaigns to assess and train employee awareness |
| Security Culture | The collective attitudes, behaviors, and practices regarding security within an organization |
Scope and Purpose
This Security Awareness Training Policy establishes Acme Cloud, Inc.'s requirements for educating all personnel on information security risks, responsibilities, and best practices. The policy scope encompasses all employees, contractors, temporary workers, and third parties with access to Acme Cloud systems, data, or facilities. The purpose is to create a strong security culture where every individual understands their role in protecting the organization's assets, reducing human-related security risks, meeting compliance requirements, and supporting the overall security program.
Training Program Objectives
| Objective | Description | Measurement |
|---|
| Risk Reduction | Reduce human-caused security incidents | Incident metrics |
| Compliance | Meet regulatory and certification requirements | Audit results |
| Culture Building | Foster security-conscious behavior | Survey results |
| Skill Development | Build security knowledge and skills | Assessment scores |
| Threat Awareness | Keep personnel informed of current threats | Training currency |
| Empowerment | Enable employees to identify and report threats | Reporting rates |
Applicability Matrix
| Personnel Category | General Training | Role-Based Training | Phishing Simulations | Compliance Training |
|---|
| Full-Time Employees | Required | Per role | Required | Per role |
| Part-Time Employees | Required | Per role | Required | Per role |
| Contractors (onsite) | Required | Per role | Required | Per role |
| Contractors (remote) | Required | Per role | Required | Per role |
| Temporary Workers | Required | Per role | Optional | Per role |
| Executive Leadership | Required | Required | Required | Required |
| Board Members | Overview | N/A | N/A | N/A |
Training Program Structure
Training Curriculum Overview
| Training Category | Audience | Duration | Frequency | Delivery |
|---|
| Security Fundamentals | All personnel | 60 minutes | Annual | LMS |
| New Hire Security Orientation | New employees | 45 minutes | Onboarding | LMS + live |
| Phishing Awareness | All personnel | 20 minutes | Annual | LMS |
| Password and Authentication | All personnel | 15 minutes | Annual | LMS |
| Data Protection and Privacy | All personnel | 30 minutes | Annual | LMS |
| Social Engineering Defense | All personnel | 25 minutes | Annual | LMS |
| Physical Security | All personnel | 15 minutes | Annual | LMS |
| Incident Reporting | All personnel | 15 minutes | Annual | LMS |
| Remote Work Security | Remote workers | 20 minutes | Annual | LMS |
| Code of Conduct | All personnel | 30 minutes | Annual | LMS |
Role-Based Training Matrix
| Role | Required Training Modules | Additional Requirements |
|---|
| All Employees | Security Fundamentals; Phishing; Data Protection; Code of Conduct | Monthly awareness communications |
| Engineering/Development | + Secure Coding; OWASP Top 10; API Security | Security Champion optional |
| SRE/DevOps | + Infrastructure Security; Cloud Security; Incident Response | Incident response exercises |
| Customer Support | + Customer Data Handling; Social Engineering; Ticket Security | Data protection focus |
| Sales/Marketing | + Data Protection; Email Security; Travel Security | Mobile device security |
| Finance | + Financial Fraud; Wire Transfer Security; Vendor Verification | BEC awareness |
| HR/People | + Privacy Training; Employee Data Protection; Background Checks | PII handling |
| Legal/Compliance | + Privacy Regulations; Data Breach Response; Compliance Requirements | Regulatory updates |
| Executives | + Executive Targeting; BEC; Crisis Management; Board Reporting | Executive tabletop |
| IT/Security | + Advanced Security Topics; Incident Response; Forensics Awareness | Continuous professional development |
| Privileged Access Users | + Privileged Access Management; Elevated Responsibility; Access Review | Quarterly refresher |
Training Schedule
| Training | Q1 | Q2 | Q3 | Q4 | Notes |
|---|
| Security Fundamentals | ● | | | | Annual renewal |
| Phishing Awareness | | ● | | | Annual renewal |
| Data Protection | | | ● | | Annual renewal |
| Social Engineering | | | | ● | Annual renewal |
| New Hire Orientation | Ongoing | Ongoing | Ongoing | Ongoing | Within 5 days |
| Phishing Simulations | ● | ● | ● | ● | Monthly |
| Tabletop Exercises | | ● | | ● | Semi-annual |
| Security Champion Training | ● | | ● | | Bi-annual |
| Executive Briefing | ● | ● | ● | ● | Quarterly |
Core Training Modules
Security Fundamentals (Annual)
| Topic | Content | Duration | Assessment |
|---|
| Security Overview | Acme Cloud security program; policies; your role | 10 min | Quiz |
| Threat Landscape | Current threats; attack vectors; real-world examples | 10 min | Quiz |
| Password Security | Strong passwords; password managers; MFA | 10 min | Quiz |
| Phishing Awareness | Recognizing phishing; reporting; response | 10 min | Quiz |
| Data Protection | Classification; handling; storage; sharing | 10 min | Quiz |
| Physical Security | Clean desk; badge; visitor management | 5 min | Quiz |
| Incident Reporting | When and how to report security concerns | 5 min | Quiz |
Phishing Awareness Module
| Topic | Content | Skills Developed |
|---|
| What is Phishing | Definition; types; attacker objectives | Recognition |
| Email Red Flags | Suspicious indicators in phishing emails | Analysis |
| URL Analysis | Checking link destinations; hover techniques | Verification |
| Attachment Safety | Safe handling of attachments; file types | Caution |
| Reporting Phishing | Using the report button; forwarding to security | Action |
| Mobile Phishing | SMS phishing (smishing); mobile email | Awareness |
| Voice Phishing | Phone-based social engineering (vishing) | Recognition |
| Spear Phishing | Targeted attacks; personalization | Awareness |
Data Protection Module
| Topic | Content | Skills Developed |
|---|
| Data Classification | Levels; examples; marking requirements | Classification |
| Handling Requirements | Per-level handling procedures | Application |
| Customer Data | Special requirements for customer data | Responsibility |
| PII Protection | Personal data identification and protection | Compliance |
| Data Sharing | Secure sharing methods; external transfer | Secure practices |
| Storage Security | Approved storage locations; encryption | Compliance |
| Data Retention | Retention periods; disposal requirements | Lifecycle |
| Breach Prevention | Common causes; prevention measures | Prevention |
Social Engineering Defense
| Topic | Content | Skills Developed |
|---|
| Social Engineering Tactics | Pretexting; baiting; quid pro quo | Recognition |
| Authority Attacks | Impersonation of executives or authorities | Skepticism |
| Urgency Manipulation | Creating false urgency to bypass judgment | Pause and verify |
| Information Gathering | How attackers research targets | OPSEC |
| Verification Procedures | Callback procedures; out-of-band verification | Verification |
| BEC Prevention | Wire transfer verification; approval workflows | Process |
| Physical Social Engineering | Tailgating; impersonation; shoulder surfing | Awareness |
| Case Studies | Real attack examples and lessons learned | Application |
Phishing Simulation Program
Program Overview
| Element | Description | Frequency |
|---|
| Simulation Campaigns | Controlled phishing tests to all employees | Monthly |
| Campaign Variety | Different scenarios, difficulty levels, vectors | Rotating |
| Immediate Feedback | Just-in-time training upon clicking | Automatic |
| Reporting Incentives | Recognition for correct reporting | Ongoing |
| Metrics Tracking | Click rates, report rates, improvement trends | Monthly |
| Remediation Training | Additional training for repeat clickers | Per threshold |
Simulation Scenarios
| Scenario Type | Difficulty | Examples | Frequency |
|---|
| Generic Phishing | Low | Prize winning; package delivery; account verification | Monthly |
| Corporate Impersonation | Medium | IT department; HR benefits; payroll updates | Monthly |
| Vendor Impersonation | Medium | AWS alerts; Slack notifications; SaaS renewals | Quarterly |
| Spear Phishing | High | Executive requests; personalized content | Quarterly |
| Credential Harvest | Medium | Login page clones; SSO impersonation | Monthly |
| Attachment-Based | Medium | Invoice attachments; document sharing | Quarterly |
| SMS Phishing | Medium | Account verification; package tracking | Quarterly |
Simulation Metrics
| Metric | Definition | Target | FY2025 Actual |
|---|
| Click Rate | Percentage clicking phishing links | <5% | 4.2% |
| Report Rate | Percentage correctly reporting phishing | >40% | 47% |
| Credential Submission Rate | Percentage entering credentials | <2% | 1.1% |
| Repeat Clicker Rate | Percentage clicking multiple campaigns | <3% | 2.4% |
| Time to First Report | Time until first employee reports | <5 min | 3.2 min |
Remediation Process
| Click Count | Remediation Action | Timeline | Tracking |
|---|
| First click | Immediate training module (5 min) | Automatic | LMS |
| Second click | Extended training module (15 min) | Within 48 hours | LMS + manager notification |
| Third click | Manager conversation + training | Within 1 week | HR involvement |
| Fourth click | CISO meeting + performance impact | Within 2 weeks | Formal documentation |
| Credential submission | Immediate password change + training | Immediate | Security team |
Specialized Training Programs
Secure Coding Training (Engineering)
| Module | Content | Duration | Frequency |
|---|
| OWASP Top 10 | Current top web application security risks | 120 min | Annual |
| Secure Coding Fundamentals | Input validation; output encoding; authentication | 180 min | Annual |
| API Security | REST/GraphQL security; authentication; rate limiting | 90 min | Annual |
| Dependency Security | SCA; vulnerability management; updates | 60 min | Annual |
| Secrets Management | Proper handling of credentials and keys | 45 min | Annual |
| Security Testing | SAST/DAST tools; penetration testing basics | 90 min | Annual |
Privileged Access Training
| Module | Content | Duration | Audience |
|---|
| Elevated Responsibility | Risks and responsibilities of privileged access | 30 min | All privileged users |
| Access Management | Requesting, using, and releasing privileged access | 20 min | All privileged users |
| Monitoring and Audit | Activity logging and review expectations | 15 min | All privileged users |
| Insider Threat Awareness | Indicators; reporting; prevention | 20 min | All privileged users |
| Emergency Access | Break-glass procedures; documentation | 15 min | On-call personnel |
Incident Response Training
| Training Type | Audience | Duration | Frequency |
|---|
| Incident Reporting | All employees | 15 min | Annual |
| Incident Response Overview | Security + SRE | 60 min | Annual |
| IR Tabletop Exercise | IR team | 120 min | Semi-annual |
| Technical IR Procedures | Security team | 180 min | Annual |
| Customer Communication | CS + Legal + Comms | 90 min | Annual |
| Executive Crisis Management | Leadership | 90 min | Annual |
Privacy and Compliance Training
| Module | Audience | Content | Duration |
|---|
| GDPR Fundamentals | All employees | GDPR principles; rights; obligations | 45 min |
| CCPA/CPRA Overview | All employees | California privacy requirements | 30 min |
| HIPAA Basics | Applicable roles | PHI protection requirements | 45 min |
| Data Subject Rights | CS + Privacy | Handling DSRs; SLAs; procedures | 30 min |
| Privacy by Design | Engineering | Building privacy into products | 60 min |
| Vendor Privacy | Procurement | Vendor privacy assessment | 30 min |
Training Delivery Methods
Delivery Channels
| Channel | Use Cases | Benefits | Limitations |
|---|
| LMS (Online) | Formal courses; compliance training | Scalable; trackable; self-paced | Limited interaction |
| Live Virtual | New hire orientation; tabletop exercises | Interactive; Q&A possible | Scheduling complexity |
| In-Person | Specialized workshops; incident simulations | High engagement | Resource intensive |
| Email | Monthly awareness tips; threat alerts | Broad reach; timely | Limited engagement |
| Slack | Quick tips; reminders; reporting | Real-time; convenient | Information overload risk |
| Posters/Signage | Visual reminders; clean desk | Ambient awareness | Limited detail |
| Newsletter | Monthly security digest; stories | Comprehensive updates | May be skipped |
| Gamification | Quizzes; competitions; badges | Engaging; memorable | Not all topics suitable |
LMS Platform Requirements
| Requirement | Description | Implementation |
|---|
| Course Management | Create, assign, track training courses | LMS platform |
| Automated Assignment | Role-based automatic enrollment | Integration with HRIS |
| Progress Tracking | Monitor completion status | Dashboard + reports |
| Assessment | Quizzes with passing threshold | Built-in assessments |
| Certificates | Completion certificates | Automated generation |
| Reminders | Automated overdue notifications | Email + Slack integration |
| Reporting | Compliance reports; metrics dashboards | Export + analytics |
| SSO Integration | Single sign-on access | Identity provider integration |
Content Development Standards
| Standard | Description | Application |
|---|
| Adult Learning Principles | Practical, relevant, self-directed content | All modules |
| Microlearning | Short, focused segments (5-15 min) | Most modules |
| Multimedia | Video, audio, interactive elements | Enhanced engagement |
| Real Examples | Acme Cloud-relevant scenarios | Contextualization |
| Regular Updates | Annual content review; emerging threat updates | Currency |
| Accessibility | WCAG 2.1 AA compliance | All content |
| Assessment | Knowledge checks with 80% passing threshold | All formal training |
Compliance and Tracking
Compliance Requirements
| Requirement Source | Training Required | Frequency | Evidence |
|---|
| SOC 2 | Security awareness training | Annual | Completion records |
| ISO 27001 | Information security awareness | Annual | Completion records |
| GDPR | Data protection training | Annual | Completion records |
| HIPAA (if applicable) | Privacy and security training | Annual | Completion records |
| CCPA/CPRA | Privacy training | Annual | Completion records |
| Company Policy | Code of Conduct; security policies | Annual | Signed acknowledgment |
Tracking and Reporting
| Metric | Definition | Target | Reporting Frequency |
|---|
| Overall Completion Rate | Completed / Required | >98% | Monthly |
| On-Time Completion | Completed within deadline | >95% | Monthly |
| Assessment Pass Rate | First-attempt pass rate | >90% | Monthly |
| Role-Based Completion | By department/role | 100% | Quarterly |
| Training Hours | Total training hours delivered | — | Quarterly |
| Feedback Scores | Training satisfaction ratings | >4.0/5.0 | Per course |
FY2025 Training Completion Metrics
| Training Category | Required | Completed | Completion Rate | Target |
|---|
| Security Fundamentals | 340 | 336 | 98.8% | 100% |
| Phishing Awareness | 340 | 334 | 98.2% | 100% |
| Data Protection | 340 | 338 | 99.4% | 100% |
| Code of Conduct | 340 | 340 | 100% | 100% |
| New Hire Security | 48 | 48 | 100% | 100% |
| Secure Coding (Engineering) | 85 | 84 | 98.8% | 100% |
| Privileged Access | 34 | 34 | 100% | 100% |
| Privacy/GDPR | 340 | 332 | 97.6% | 100% |
Non-Compliance Escalation
| Days Overdue | Action | Responsible Party |
|---|
| 0-7 days | Automated LMS reminders | System |
| 8-14 days | Manager notification | LMS + Security team |
| 15-21 days | Director escalation | Security team |
| 22-30 days | VP/CISO notification | Security team |
| >30 days | Access restriction consideration | CISO + HR |
Security Awareness Communications
Regular Communications
| Communication | Audience | Frequency | Channel | Content |
|---|
| Security Tip of the Week | All | Weekly | Slack | Short security tips |
| Monthly Newsletter | All | Monthly | Email | Security digest |
| Threat Alerts | All | As needed | Email + Slack | Current threat warnings |
| Policy Updates | All | As needed | Email | Policy changes |
| Phishing Alerts | All | As needed | Slack | Confirmed phishing notices |
| Security Champion Update | Champions | Bi-weekly | Meeting + Email | Security updates |
| Executive Security Brief | Leadership | Quarterly | Meeting | Risk and metrics |
Awareness Campaign Calendar
| Month | Theme | Activities |
|---|
| January | New Year Security Reset | Password changes; MFA audit |
| February | Data Privacy Day | Privacy training emphasis |
| March | Phishing Awareness | Increased simulations |
| April | Physical Security | Clean desk reminders |
| May | Identity Protection | MFA; password managers |
| June | Travel Security | Pre-travel tips |
| July | Social Engineering | Awareness scenarios |
| August | Back-to-School Security | Family cyber safety |
| September | Insider Threat | Reporting awareness |
| October | Cybersecurity Awareness Month | Full campaign |
| November | Gratitude for Reporting | Reporter recognition |
| December | Holiday Security | Shopping safety; travel |
Recognition and Gamification
| Recognition Type | Criteria | Reward |
|---|
| Phishing Reporter | Correctly reports simulated phishing | Public recognition |
| Early Reporter | First to report real phishing | Recognition + swag |
| Security Champion | Consistent security advocacy | Annual award |
| Training Champion | 100% on-time completion | Recognition |
| Department Excellence | Highest department completion rate | Team recognition |
Numbered Policy Statements
-
Universal Participation: All Acme Cloud, Inc. personnel including employees, contractors, and third parties with system access must complete assigned security awareness training.
-
Onboarding Requirement: New personnel must complete security orientation training within five business days of starting work.
-
Annual Refresh: Security fundamentals training must be completed annually by all personnel, with completion required by the anniversary of the previous training.
-
Role-Based Training: Personnel must complete role-specific security training appropriate to their job function and access levels.
-
Completion Tracking: All training completion must be documented in the Learning Management System with records retained for audit purposes.
-
Passing Threshold: Formal training modules require 80% or higher assessment scores to demonstrate comprehension.
-
Phishing Simulation Participation: All personnel must participate in phishing simulation programs as part of ongoing security awareness.
-
Remediation Requirement: Personnel who fail phishing simulations or assessments must complete additional remediation training as assigned.
-
Privileged User Training: Personnel with privileged access must complete additional training on elevated responsibilities and risks.
-
Executive Training: Executive leadership must participate in security briefings and crisis management exercises.
-
Training Currency: Training must be refreshed when significant changes occur in threats, technology, or policy.
-
Non-Compliance Consequences: Failure to complete required training may result in access restrictions and management escalation.
-
Feedback Integration: Training programs shall incorporate participant feedback and lessons from incidents for continuous improvement.
-
Metrics Reporting: Training completion and effectiveness metrics shall be reported to leadership quarterly and to the Board annually.
Framework Appendix
Compliance Mapping
| Requirement | SOC 2 Criteria | ISO 27001 Control | NIST CSF | Implementation |
|---|
| Security awareness | CC1.4 | A.7.2.2 | PR.AT-1 | Training program |
| Security training | CC1.4 | A.7.2.2 | PR.AT-1 | Role-based modules |
| Personnel accountability | CC1.5 | A.7.2.1 | PR.AT-1 | Policy acknowledgment |
| Training effectiveness | CC1.4 | A.7.2.2 | PR.AT-5 | Assessment; metrics |
| Threat awareness | CC3.3 | A.6.1.1 | PR.AT-1 | Communications |
NIST SP 800-50 Alignment
| NIST Guidance | Policy Implementation |
|---|
| Awareness program | Ongoing communications; tips; alerts |
| Training program | LMS-based formal training |
| Education program | Security Champion; specialized training |
| Program evaluation | Metrics; simulations; feedback |
| Continuous improvement | Annual review; incident integration |
Training Effectiveness Measurement
| Level | Measurement | Method | Frequency |
|---|
| Reaction | Satisfaction with training | Post-training surveys | Per course |
| Learning | Knowledge acquisition | Assessment scores | Per course |
| Behavior | Application of knowledge | Phishing simulation results | Monthly |
| Results | Business impact | Incident metrics; audit findings | Quarterly |
Related Trust Center documents
security overview, code of conduct, access control, incident response, privacy policy, sdlc policy, data retention
Document revision history
| Version | Date | Author | Summary of changes |
|---|
| 1.0 | 2024-06-01 | Legal & Compliance | Initial Trust Center publication |
| 2.0 | 2025-03-15 | GRC Program | SOC 2 Type II alignment refresh; expanded subprocessors |
| 2.5 | 2025-09-01 | Security Engineering | Encryption standards update; ISO 27001 mapping |
| 3.0 | 2026-01-15 | Trust Center Program | Full procurement-grade expansion; 34-document set |
Contact
Acme Cloud, Inc.
1200 Market Street, Suite 400
San Francisco, CA 94103, USA
Training Program Contacts
Appendix: Training Calendar FY2026
| Training | Q1 | Q2 | Q3 | Q4 | Audience |
|---|
| Security Fundamentals | ● | | | | All |
| Phishing Awareness | | ● | | | All |
| Data Protection/Privacy | | | ● | | All |
| Social Engineering | | | | ● | All |
| Secure Coding | ● | | ● | | Engineering |
| Incident Response Exercise | | ● | | ● | IR team |
| Executive Tabletop | | ● | | ● | Leadership |
| Phishing Simulations | ● | ● | ● | ● | All (monthly) |
| Security Champion Training | ● | | ● | | Champions |
Document Version: 3.0
Last Updated: January 15, 2026