A.6.3 Information Security Awareness, Education and Training
Control Objective
Personnel of the organisation and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organisation's information security policy, topic-specific policies and procedures, as relevant for their job function.
Policy Statement
anDREa enforces a continuous culture of security awareness by delivering structured education, technical training, and policy updates to all personnel and relevant third-party stakeholders. This program ensures that individuals understand their specific security roles and remain equipped to defend against evolving threat landscapes in compliance with ISO/IEC 27001 and NIS 2.
Due to the detailed training curricula, specific compliance completion timelines, and role-based educational requirements necessary for our workforce, this control is fully operationalized within its own dedicated document.
1. Mandatory Core Training & Policy Sign-Off
Upon onboarding, and continuously on an annual cycle, all anDREa employees and embedded contractors must complete a two-part educational baseline:
- Information Security & Data Protection Training: Personnel can complete this curriculum in either a guided "Training Form" with active feedback or a "Quiz Form" with performance tracking. A successful quiz score grants a validation window of exactly one year, after which the refreshed training must be re-taken. Automated system reminders trigger prior to expiration, and aggregate performance metrics are periodically reviewed during ISMS and Management Team (MT) sessions.
- Mandatory Policy Affirmation: Personnel must read and formally confirm compliance with our baseline regulatory policies. While all documentation is open for review, mandatory tracking focuses on but is not limited to:
- Clause 4 (Context of the Organisation) & Clause 5 (Leadership)*
- A.05.12 (Classification of Information) + A.05.13 (Labelling of Information)
- A.05.26 (Response to Information Security Incidents)
- A.06.04 (Disciplinary Process) & *A.06.07 (Remote Working) *
- AI/Large Language Model (LLM) Use Policy & the andREa's HR Hub
Note: These core modules are also available to external interested parties upon formal request.
2. Continuous Awareness & Update Channels
To combat evolving threat vectors and maintain a strong security culture, anDREa enforces three continuous awareness mechanisms:
- Security Awareness Articles: The Security Officer regularly publishes security awareness insights on our support website. These updates are mandatory reading for internal staff and are left publicly accessible to educate the wider myDRE ecosystem.
- Monthly Collaboration Sessions: Dedicated security briefings and awareness workshops are built directly into our company-wide monthly team meetings.
- Practical Security Campaigns: The Security Officer orchestrates regular security simulations, including controlled phishing campaigns, to evaluate and refine employee behavioral readiness.
- Policy Change Tracking: Any technical or structural changes to policies are reviewed, formally approved, and communicated during our bi-monthly Information Security Management Board (ISMB) Meetings.
3. NIS 2 Leadership & Governance Training
To satisfy the explicit executive accountability requirements of the NIS 2 Directive, targeted leadership training is mandatory. The anDREa Director, Management Team members, and the Solution Architect must undergo specific annual training designed to enhance their governance capabilities in:
- Identifying and assessing cybersecurity risks unique to anDREa’s cloud-agnostic research environments.
- Navigating the evolving legal obligations dictated by NIS 2, GDPR, and ISO 27001.
- Managing and governing the ISMS framework effectively.
This advanced training is executed via verified external courses, specialized workshops led by the Security Officer, or dedicated executive sessions within the bi-monthly ISMB forums. All completions are audited and recorded inside the NIS 2 Management Training Registry.