C.10 Cybersecurity Education Policy

Version: April 2025
Applies to: All employees, contractors, vendors, and stakeholders
Aligned with: ISO/IEC 27001:2022 (A.6.3, A.5.10, A.8.11)

Purpose
To foster a security-aware culture by ensuring everyone understands their cybersecurity responsibilities and can recognize, prevent, and respond to threats.

1. Scope
Applies to all personnel accessing company systems or data. Covers:
- Security awareness training
- Role-specific education (e.g., for developers, admins)
- Policy and procedure familiarization
- Ongoing validation and reporting

2. Core Education Requirements

ID Requirement
EDU-01 Provide access to documentation on cybersecurity responsibilities
EDU-02 Maintain an education delivery platform (e.g. LMS)
EDU-03 Track training delivery using the same platform
EDU-04 Deliver role-specific training (e.g., engineers, developers) regularly
EDU-05 Provide general awareness training to all staff on a regular basis
EDU-06 Train staff on secure authentication practices
EDU-07 Train staff on secure communication over untrusted networks
EDU-08 Educate staff on data handling and common exposure risks
EDU-09 Train staff to identify and respond to social engineering attacks
EDU-10 Educate staff on how to report security control failures
EDU-11 Educate staff on how to report security incidents
EDU-12 Run regular reinforcement activities (e.g., phishing tests, workshops)
EDU-13 Use quantifiable measures to assess training effectiveness
EDU-14 Report results of training programs to business stakeholders

3. Enforcement & Sanctions
Failure to comply may result in:
- Training refreshers or formal warnings
- Suspension of access
- Termination of employment/contract
- Legal consequences (in case of regulatory breaches)

Sanctions are enforced proportionally and follow internal HR/cybersecurity protocols.

Direct URL: