SOC2-CC1-SECURITY-TRAINING
Security Awareness Training
What this control does
Annual security awareness training for all employees covering phishing, social engineering, password hygiene, and data handling responsibilities.
Implementation guidance
Require completion of security awareness training within 30 days of hire and annually thereafter. Use a platform (KnowBe4, Proofpoint, Hoxhunt) with phishing simulation capability. Track completion rates. For employees who fail phishing simulations, require immediate remedial training. Maintain training records for 3 years.
Requirements satisfied
Why it matters
Untrained employees are the primary attack vector for phishing, social engineering, and credential compromise—incidents that often lead to unauthorized data access or breaches. Security awareness training measurably reduces susceptibility to these attacks and ensures employees understand their data handling obligations. Without documented training completion, the organization cannot demonstrate due diligence during incident response or regulatory inquiries.
Evidence to collect
- Training enrollment and completion report showing all employees trained within 30 days of hire and annually (filtered by hire date and training date)
- Phishing simulation campaign results showing click rates, reported emails, and failing users flagged for remedial training
- Remedial training completion records for employees who failed phishing simulations
- Training platform audit logs showing course content, assessment scores, and completion timestamps for a sample of 10–15 employees
Testing procedure
Request the training platform's completion report filtered by hire date to verify all employees completed training within 30 days of hire; spot-check 10–15 employee records to confirm assessment scores and timestamps. Review phishing simulation results from the past 12 months to identify failure rates and verify that failing employees were immediately enrolled in remedial training. Confirm remedial training completion. Verify that records are retained for at least 3 years by checking the platform's data retention settings and archive logs.
Common gotchas
Many organizations complete annual training but fail to enforce the 30-day onboarding requirement for new hires—leaving new employees unaware of policies before they have access. Phishing simulations are often treated as a metric to track but not acted upon; organizations frequently skip or delay remedial training for failing employees, reducing the control's effectiveness.