ISO 27001 Control A.6.3: Information Security Awareness, Education and Training
Control A.6.3 is where information security stops being the security team’s job and becomes everyone’s. It requires that personnel, and relevant interested parties, receive appropriate awareness, education and training, plus regular updates on the policies and procedures relevant to their role. It matters because most incidents involve people: a clicked phishing link, a misdirected email, a reused password. Controls reduce the odds, but an aware workforce is the control that scales across every process. A.6.3 is a preventive people control, and it is also the organization’s side of the bargain you set in terms and conditions of employment. This is the third control in our walk through Annex A.
What the control requires
Annex A control 6.3 of ISO 27001:2022 states that personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organization’s information security policy, topic-specific policies and procedures, as relevant for their job function.
Three distinct things are required, and they are not the same:
- Awareness - keeping security front of mind: what the threats are, what good behaviour looks like, how to report a problem
- Education and training - building the specific knowledge and skills a role needs, from secure coding for developers to data-handling for support staff
- Regular updates - not a one-time induction, but ongoing refreshers as policies, procedures and threats change
The phrase “as relevant for their job function” is the proportionality lever: a developer, a finance clerk, and a board member need different training, not the same generic module. “Interested parties” extends the reach to relevant third parties - contractors, and sometimes key suppliers - where appropriate.
A.6.3 is preventive, reducing the likelihood of human-factor incidents. Annex A states the control; ISO 27002 gives the guidance, and your Statement of Applicability records how you deliver it.
How to implement awareness, education and training
Start with induction, then sustain it
Every new joiner should receive security awareness training as part of onboarding, before or as they gain access - this is the natural partner to the obligations they accept under A.6.2. But induction alone does not satisfy “regular updates.” Build an annual refresher cycle at minimum, and top it up with timely messages when a policy changes or a new threat emerges.
Tailor content to job function
Generic annual training that everyone clicks through teaches little. Segment your audience:
- All staff - phishing, passwords and authentication, acceptable use, clear desk and clear screen, and how to report an event
- Developers and engineers - secure coding, handling secrets, secure development practices
- Privileged and IT roles - access management, change control, logging and monitoring expectations
- Leadership - their responsibilities under the ISMS and how security connects to business risk
Our guidance on building a cybersecurity training program and creating security awareness in the workplace goes deeper on structuring this.
Aim for behaviour, not attendance
The point of the control is changed behaviour, not a completion percentage. Reinforce training with practical measures: simulated phishing with constructive follow-up, short topic-specific reminders, and visible, blame-free reporting channels. A strong security culture is what turns a training module into instinct - people who feel safe to report are worth more than people who scored well on a quiz.
Keep people current as things change
The “regular updates” requirement means your programme has to react. When you revise a policy, communicate it and, where it matters, confirm people have seen it. When a new scam targets your sector, send a short, specific alert. These timely nudges often do more than the annual module.
Measure and evidence it
This control produces clear, auditable evidence: training records showing who completed what and when, induction logs, phishing simulation results and trends, and records of policy-update communications. Completion and phishing metrics also feed your monitoring and measurement under Clause 9.1, and gaps can surface as improvements under Clause 10.1.
Related controls and clauses
A.6.2 connection. Terms and conditions commit the organization to inform and train; A.6.3 is how that commitment is delivered.
A.6.8 connection. Training people to recognise and report events feeds information security event reporting (A.6.8) - awareness is what makes reporting happen.
Clause 7.3 connection. Annex A control 6.3 operationalises the management-system requirement in Clause 7.3 Awareness; the clause sets the obligation, the control delivers the programme.
Clause 7.2 connection. Competence overlaps with the education and training element - ensuring people are actually capable in their roles, not just aware.
Clause 9.1 connection. Training completion and phishing susceptibility are natural metrics for measuring whether this control is effective.
What auditors check
A programme exists and reaches everyone. Auditors look for a defined awareness and training programme with evidence that all personnel, including new joiners and contractors, have taken part.
Content is role-relevant. They check that training is tailored “as relevant for their job function,” not a single generic module for the whole company.
It is ongoing, not one-off. Auditors look for a refresher cycle and evidence of updates when policies or threats change, matching the “regular updates” wording.
Records back it up. They sample training records, induction logs, and communication evidence. Completion data that cannot be produced is treated as training that did not happen.
Some sign of effectiveness. Mature audits look beyond attendance for evidence the programme changes behaviour - phishing trends, reporting rates - tying back to Clause 9.1.
Common mistakes to avoid
Induction only. Training people once at onboarding and never again fails the “regular updates” requirement outright. Build a recurring cycle.
One generic module for all. Ignoring job function wastes everyone’s time and misses the control’s proportionality. Developers and finance staff need different things.
Measuring clicks, not behaviour. A 100% completion rate on a module nobody absorbed proves little. Reinforce and test in realistic ways.
Leaving contractors out. “Interested parties, where relevant” means third parties with access often need awareness too. Excluding them is a common gap.
No records. Delivering good training but keeping no completion or communication evidence means you cannot demonstrate the control. Track it.
Punishing reporters. A blame culture kills reporting, which is exactly what awareness is meant to encourage. Keep reporting safe and constructive.
How 27kay can help
We help organizations build security awareness and training that actually changes behaviour and produces clean audit evidence - not a once-a-year checkbox. As part of ISO 27001 implementation, we design a role-based programme, set up induction and refresher cycles, add phishing simulation and reporting reinforcement, and wire completion and effectiveness data into your measurement. For the full picture, see our ISO 27001 knowledge hub.
Want a training programme that convinces auditors and genuinely reduces human-factor risk? Get in touch - we will assess what you have and help you build a programme people actually learn from.