Controls / Other controls proposal forms ask about
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: train staff to spot phishing and to report a suspected incident.
In Australia
No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 12.6.1 PCI DSS v4.0.1 (add-on) | Formal security awareness program A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it. evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance |
| PCI DSS 12.6.3.1 PCI DSS v4.0.1 (add-on) | Awareness training covers phishing and social engineering Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then. evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 14.1 CIS Controls v8.1 | Establish and Maintain a Security Awareness Program Set up and keep a security awareness programme whose aim is to teach the workforce how to use enterprise assets and data securely. Train people when they are hired and at least yearly after that. Revisit the content each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Security awareness programme document with content, audience, delivery methods and the annual review date; Training completion records showing new hires trained at onboarding and all staff trained at least annually; Management-approved awareness policy stating mandatory training, the target workforce population and consequences for non-completion; Learning management system export listing each worker's completion date, with contractors and temporary staff included; Annual content review record showing topics updated for new threats, systems or enterprise changes, with approver |
| CIS 14.2 CIS Controls v8.1 | Train Workforce Members to Recognize Social Engineering Attacks Teach the workforce to spot social engineering, for example phishing, pretexting and tailgating. evidence an assessor asks for Social engineering training module content covering phishing, pretexting and tailgating, with completion records; Phishing simulation campaign results showing click and report rates and the follow-up training for repeat clickers; Phishing simulation programme plan covering frequency, templates of increasing difficulty and target groups including executives; Tailgating and pretext awareness materials such as posters, briefings or physical social engineering test results; Report or dashboard of suspicious email reports through the report-phishing button, with time to report |
| CIS 14.6 CIS Controls v8.1 | Train Workforce Members on Recognizing and Reporting Security Incidents Teach the workforce to recognise a possible incident and to report it. evidence an assessor asks for Training content showing how to recognise a potential incident and the reporting channel to use; Completion records, plus a sample of workforce-originated incident reports showing the channel is being used; Incident reporting instructions issued to staff: examples of incidents, the report channel, hotline and expected response; Metrics on time from event to staff report for recent incidents, used to measure training effect; Tabletop or awareness exercise records where staff practised recognising and reporting an incident |
| PR.AT-01 NIST CSF 2.0 | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind evidence an assessor asks for Security awareness program curriculum; Completion records by population; Phishing simulation results and trends; Awareness campaign artefacts (posters, emails); Annual program effectiveness review |
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(e)(1) FTC Safeguards Rule (add-on) | 314.4(e)(1) Security awareness training Personnel receive security awareness training that is updated as necessary to reflect the risks identified by the risk assessment. evidence an assessor asks for Security awareness training records; Evidence the content was updated for identified risks |
HIPAA Security Rule, when it applies
HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(5)(i) HIPAA Security Rule (add-on) | Security Awareness and Training (Standard) Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders. evidence an assessor asks for Training curriculum; Completion records by workforce member; Role-based modules; Awareness campaigns calendar |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.14 23 NYCRR 500 (add-on) | Monitoring and Training Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering. Class A must implement endpoint detection and response solution and centralized logging. evidence an assessor asks for UEBA or user activity monitoring outputs; Anti-malware deployment coverage report; Annual training completion records with phishing simulation results; Class A EDR coverage dashboard; Class A centralized SIEM logging design and coverage; CISO-approved compensating control register if EDR/SIEM not implemented (Class A); Training content review covering social engineering |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 12.6.1 PCI DSS v4.0.1 (add-on) | Formal security awareness program A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it. evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance |
| PCI DSS 12.6.3.1 PCI DSS v4.0.1 (add-on) | Awareness training covers phishing and social engineering Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then. evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.7 Cyber Essentials | Educate Users on Strong Passwords Educate users to avoid common, predictable, or compromised passwords and on the importance of unique passwords per account. evidence an assessor asks for password guidance document; training attendance log; phishing/password module evidence |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 12.6.1 PCI DSS v4.0.1 (add-on) | Formal security awareness program A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it. evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance |
| PCI DSS 12.6.3.1 PCI DSS v4.0.1 (add-on) | Awareness training covers phishing and social engineering Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then. evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.6.3 ISO/IEC 27001:2022 (lens) | Information security awareness, education and training The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose (stated in ISO/IEC 27002:2022): makes staff and relevant outside parties know and carry out their security duties. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.3. evidence an assessor asks for Statement of Applicability entry for control A.6.3, showing inclusion or justified exclusion, implementation status and the risks it treats; A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers; Assessment results testing understanding at the end of training activities; Awareness materials across channels covering management commitment, obligations, accountability, event reporting and baseline controls |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.