SID-PPL-02 — Security Awareness, Education, and Training
| Property | Value |
|---|---|
| Owner | operator |
| Category | process |
| CSF Function | protect |
| Group | People Security Controls |
Description
All personnel receive information security awareness training at onboarding and annually. Role-specific training for administrators, developers, and incident responders. Training covers EUDI-specific threats: social engineering targeting wallet users, credential misuse, device compromise patterns.
Framework Requirements
ISO 27001 Annex A: A.6.3
GDPR Checklist: Create an internal security policy