simpl.
Cybersecurity GRC 12 items

Security Awareness & Training Program Review

Reviews the effectiveness of the security awareness and training program including phishing simulations and role-based training.

NIST 800-53ISO 27001:2022PCI DSS 4.0

Free PDF · enter your email to download.

Program Foundation

  • Is a documented security awareness and training program established? *
  • Is security training delivered to new hires before or shortly after granting access? *
  • Is refresher training delivered at least annually to all personnel? *

Content & Role-Based Training

  • Does training cover phishing, social engineering, and reporting procedures? *
  • Is role-based training provided to personnel with significant security responsibilities? *
  • Does training address acceptable use, data handling, and incident reporting? *

Phishing Simulations

  • Are simulated phishing campaigns conducted periodically? *
  • Are repeat clickers provided remedial training? *
  • What was the phishing simulation failure rate in the most recent campaign (%)?

Tracking & Metrics

  • Is training completion tracked and recorded per individual? *
  • Are completion rates reported to management? *
  • What is the current annual training completion rate (%)?

Download the full Security Awareness & Training Program Review checklist

Get it as a clean, printable PDF — free.