N.2.02 Education of managers and employees about digital security
Control Overview
This control mandates that leadership and personnel undergo regular, verified security training tailored to their roles. Directors and managers must receive specialized training to effectively identify, assess, and manage organizational cybersecurity risks and resource allocations. Employees must receive comprehensive digital security and data protection training aligned with their specific responsibilities, backed by knowledge testing to verify understanding of internal rules, policies, and incident reporting procedures.
Applicability Note: This control is fully applicable to the anDREa platform and is a mandatory requirement for all board members, internal staff, support teams, and relevant third-party personnel.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from passive awareness campaigns toward a formalized, recurring curriculum.
Training at anDREa is strictly role-based and governed by continuous lifecycle automation. Management team members participate in specialized cybersecurity risk and governance courses to fulfill their statutory oversight obligations. Employees are enrolled in mandatory Information Security and Data Protection Training (responses), which includes integrated knowledge testing (quizzes). To prevent training decay and satisfy compliance, our system automatically tracks completions and re-triggers the full training workflow annually for every user. Specialized technical units, such as our support and Research Support Teams (RST), receive additional targeted training focused on platform environment safety and secure data handling.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.06.03 - Information security awareness, education and training | Mandates that personnel receive appropriate awareness, education, training, and regular updates on organizational policies. |
| Executive Governance | NIS 2 Management Training Registry | Audit trail proving that directors undergo targeted risk management and NIS 2 compliance training at least once a year. |
| Staff Awareness Curricula | Information Security and Data Protection Training (responses) | Central compliance data tracking mandatory enrollment, completion metrics, and automated annual renewal triggers for staff. |
| Knowledge Verification | Information Security and Data Protection Training (responses) | Verifiable test scores and response databases proving that personnel have successfully digested internal rules and procedures. |
| Specialized Training Logs | Information Security and Data Protection Training (responses) | Tailored operational blueprints and training rosters confirming advanced technical security education for high-privilege teams. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Role-based training tracks, automated annual recurrence parameters, validation quizzes, and executive risk education are fully institutionalized and monitored.