graphgrc

Security Training Process

Process for delivering and tracking security awareness training for all employees.

Roles and Responsibilities

Prerequisites

Process Steps

Step 1: New Hire Training

All new employees complete security training during onboarding (within first 7 days).

Training modules:

Delivery: Self-paced online training with quiz (80% passing score)

Owner: New Employee (completion), HR (tracking) Duration: 45-60 minutes, complete within first week

Step 2: Annual Refresher Training

All employees complete refresher training annually.

Training modules (updated yearly):

Delivery: Online training with quiz, scheduled in Q1 each year

Owner: All Employees Duration: 30 minutes annually

Step 3: Role-Specific Training

Employees in certain roles receive additional specialized training.

Engineering team:

Infrastructure team:

Managers:

Customer success / Support:

Owner: Respective team members Duration: 1-2 hours annually

Step 4: Phishing Simulations

Security team conducts simulated phishing campaigns quarterly.

Campaign details:

Scenarios:

Frequency: Quarterly (4 campaigns per year)

Owner: Security Team Duration: Ongoing, quarterly campaigns

Step 5: Tracking and Reporting

Security team tracks training completion and reports to leadership.

Metrics tracked:

Reporting:

Owner: Security Team Duration: Ongoing

Step 6: Remedial Training

Employees who fail phishing simulations or violate security policies receive additional training.

Triggers for remedial training:

Remedial training:

Owner: Security Team Duration: As needed

Step 7: Content Updates

Security team updates training content annually or as needed.

Update triggers:

Process:

Owner: Security Team Duration: Annual review in Q4

Validation and Evidence

Enforcement

References

Control Mapping


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.