A.6.3 A.6 · People Controls

A.6.3 — Information security awareness, education and training

Ensure all personnel receive appropriate IS awareness, education and training relevant to their job function.

Also written as A6.3, Annex A 6.3, ISO 27001:2022 A.6.3, ISO27001 A.6.3.

What ISO 27001 A.6.3 requires

Information security awareness, education and training is one of 8 People Controls in ISO/IEC 27001:2022 Annex A. Ensure all personnel receive appropriate IS awareness, education and training relevant to their job function. People controls are tested against HR records, so the evidence usually lives outside the security team — joiner/mover/leaver files, training completions, and signed acknowledgements need to reconcile with your current headcount.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.6.3, gather artefacts such as:

  • IS training programme documentation and curriculum
  • Training completion records from LMS
  • Role-specific training content (developers, privileged users, management)
  • Annual awareness campaign evidence (phishing simulations, newsletters)

How to implement A.6.3

  1. Differentiate by role rather than training everyone identicallyThe control says training relevant to job function. One annual all-staff module does not meet that for developers, privileged administrators, or the people handling customer data. Define the role groups first, then the curriculum for each.
  2. Make it continuous rather than annualAn annual module is the minimum and is widely treated as insufficient on its own. Layer short, frequent touches — phishing simulation, briefings tied to real incidents, onboarding — so awareness is a programme rather than an event.
  3. Keep completion records that reconcile with headcountThe evidence auditors sample is completion rate against a current employee list. Reconciliation failures — leavers still listed, joiners missing — are more commonly the finding than the training content itself.
  4. Measure whether it workedPhishing simulation click rates over time, or a short assessment, gives you an effectiveness signal. The control asks for appropriate training; being able to show the measure improved is a much stronger position than showing attendance.
  5. Include contractors and third parties in scopeAnyone with access to your information is in scope, not just employees on payroll. Contractor and temporary-staff training is a routine gap because they sit outside the HR system that drives the training assignments.

Common audit findings for A.6.3

What actually gets raised against A.6.3, in rough order of how often it comes up:

Scoping A.6.3

A.6.3 is not realistically excludable — if you have personnel, it applies. It is one of the few controls where evidence is straightforward to produce and therefore one where a gap looks careless rather than risk-based. It is normally tested alongside A.6.1 screening and A.6.2 terms of employment.

How A.6.3 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.6.3 aligns with:

SOC 2: CC1.4 Commitment to competence, CC2.2 Internal communication

NIST CSF 2.0: PR.AT-01 General awareness and training, PR.AT-02 Specialized role training

ISO 27001:2013 mapping

A.6.3 consolidates the following ISO 27001:2013 control(s): A.7.2.2. If you are transitioning an existing ISMS, map your prior evidence for these to A.6.3 in your updated SoA.

Map A.6.3 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.6.3 in the Risk Register.

Related Annex A controls

A.6.1 Screening A.6.2 Terms and conditions of employment A.6.5 Responsibilities after termination or change of employment A.5.10 Acceptable use of information and other associated assets A.6.8 Information security event reporting

See all 8 People Controls →

Frequently asked questions

Is ISO 27001 A.6.3 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.6.3 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.6.3?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.6.3 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.6.3 map to in SOC 2 and NIST CSF?

A.6.3 aligns with SOC 2 CC1.4, CC2.2 and NIST CSF PR.AT-01, PR.AT-02. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

What was A.6.3 in ISO 27001:2013?

A.6.3 consolidates 1 control(s) from the 2013 edition: A.7.2.2. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.

What are the most common audit findings for A.6.3?

Completion records that do not reconcile with the current staff list. Identical training for all roles, with no differentiation for developers or privileged users.