Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.2.02 Education of managers and employees about digital security

Control Overview

This control mandates that leadership and personnel undergo regular, verified security training tailored to their roles. Directors and managers must receive specialized training to effectively identify, assess, and manage organizational cybersecurity risks and resource allocations. Employees must receive comprehensive digital security and data protection training aligned with their specific responsibilities, backed by knowledge testing to verify understanding of internal rules, policies, and incident reporting procedures.

note

Applicability Note: This control is fully applicable to the anDREa platform and is a mandatory requirement for all board members, internal staff, support teams, and relevant third-party personnel.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from passive awareness campaigns toward a formalized, recurring curriculum.

Training at anDREa is strictly role-based and governed by continuous lifecycle automation. Management team members participate in specialized cybersecurity risk and governance courses to fulfill their statutory oversight obligations. Employees are enrolled in mandatory Information Security and Data Protection Training (responses), which includes integrated knowledge testing (quizzes). To prevent training decay and satisfy compliance, our system automatically tracks completions and re-triggers the full training workflow annually for every user. Specialized technical units, such as our support and Research Support Teams (RST), receive additional targeted training focused on platform environment safety and secure data handling.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.06.03 - Information security awareness, education and trainingMandates that personnel receive appropriate awareness, education, training, and regular updates on organizational policies.
Executive GovernanceNIS 2 Management Training RegistryAudit trail proving that directors undergo targeted risk management and NIS 2 compliance training at least once a year.
Staff Awareness CurriculaInformation Security and Data Protection Training (responses)Central compliance data tracking mandatory enrollment, completion metrics, and automated annual renewal triggers for staff.
Knowledge VerificationInformation Security and Data Protection Training (responses)Verifiable test scores and response databases proving that personnel have successfully digested internal rules and procedures.
Specialized Training LogsInformation Security and Data Protection Training (responses)Tailored operational blueprints and training rosters confirming advanced technical security education for high-privilege teams.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Role-based training tracks, automated annual recurrence parameters, validation quizzes, and executive risk education are fully institutionalized and monitored.