Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.6.3 Information Security Awareness, Education and Training

Control Objective

Personnel of the organisation and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organisation's information security policy, topic-specific policies and procedures, as relevant for their job function.

Policy Statement

anDREa enforces a continuous culture of security awareness by delivering structured education, technical training, and policy updates to all personnel and relevant third-party stakeholders. This program ensures that individuals understand their specific security roles and remain equipped to defend against evolving threat landscapes in compliance with ISO/IEC 27001 and NIS 2.

Due to the detailed training curricula, specific compliance completion timelines, and role-based educational requirements necessary for our workforce, this control is fully operationalized within its own dedicated document.


1. Mandatory Core Training & Policy Sign-Off

Upon onboarding, and continuously on an annual cycle, all anDREa employees and embedded contractors must complete a two-part educational baseline:

Note: These core modules are also available to external interested parties upon formal request.


2. Continuous Awareness & Update Channels

To combat evolving threat vectors and maintain a strong security culture, anDREa enforces three continuous awareness mechanisms:

  • Security Awareness Articles: The Security Officer regularly publishes security awareness insights on our support website. These updates are mandatory reading for internal staff and are left publicly accessible to educate the wider myDRE ecosystem.
  • Monthly Collaboration Sessions: Dedicated security briefings and awareness workshops are built directly into our company-wide monthly team meetings.
  • Practical Security Campaigns: The Security Officer orchestrates regular security simulations, including controlled phishing campaigns, to evaluate and refine employee behavioral readiness.
  • Policy Change Tracking: Any technical or structural changes to policies are reviewed, formally approved, and communicated during our bi-monthly Information Security Management Board (ISMB) Meetings.

3. NIS 2 Leadership & Governance Training

To satisfy the explicit executive accountability requirements of the NIS 2 Directive, targeted leadership training is mandatory. The anDREa Director, Management Team members, and the Solution Architect must undergo specific annual training designed to enhance their governance capabilities in:

  1. Identifying and assessing cybersecurity risks unique to anDREa’s cloud-agnostic research environments.
  2. Navigating the evolving legal obligations dictated by NIS 2, GDPR, and ISO 27001.
  3. Managing and governing the ISMS framework effectively.

This advanced training is executed via verified external courses, specialized workshops led by the Security Officer, or dedicated executive sessions within the bi-monthly ISMB forums. All completions are audited and recorded inside the NIS 2 Management Training Registry.