Cybersecurity GRC 12 items
Security Awareness & Training Program Review
Reviews the effectiveness of the security awareness and training program including phishing simulations and role-based training.
NIST 800-53ISO 27001:2022PCI DSS 4.0
Free PDF · enter your email to download.
Program Foundation
- Is a documented security awareness and training program established? *
- Is security training delivered to new hires before or shortly after granting access? *
- Is refresher training delivered at least annually to all personnel? *
Content & Role-Based Training
- Does training cover phishing, social engineering, and reporting procedures? *
- Is role-based training provided to personnel with significant security responsibilities? *
- Does training address acceptable use, data handling, and incident reporting? *
Phishing Simulations
- Are simulated phishing campaigns conducted periodically? *
- Are repeat clickers provided remedial training? *
- What was the phishing simulation failure rate in the most recent campaign (%)?
Tracking & Metrics
- Is training completion tracked and recorded per individual? *
- Are completion rates reported to management? *
- What is the current annual training completion rate (%)?
Download the full Security Awareness & Training Program Review checklist
Get it as a clean, printable PDF — free.
