The most common training arrangement in an ISMS is "send one e-learning module to everyone once a year and count the completions." It is not wrong, but it meets about half the requirement, because the standard asks for competence and awareness separately, and the two differ in audience and in how they are demonstrated.
The arrangement also leaks. People who joined mid-year. People returning from extended leave. Contractor personnel working on site. A single annual send misses all three — and that is exactly where auditors and customer audits find the gaps.
Then there is the completion rate. People ask whether 95% is acceptable. It is not: 100% is required. This article explains why, and turns training design into practice. For where the requirement sits, see Clause 7: Support; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
Why This Trips People Up
Trying to satisfy competence and awareness with one initiative
| Competence | Awareness | |
|---|---|---|
| What is required | People doing work that affects ISMS performance have the ability that work needs | People working under the organisation's control understand the policy, their contribution, and the implications of not conforming |
| Audience | Specific role holders (ISMS manager, internal auditors, system administrators, developers) | Everyone working under the organisation's control |
| How it is secured | Training, experience, qualifications, or reassigning people | Communication, training, day-to-day reinforcement |
| Evidence to keep | Evidence of competence (completion, qualification, background) | Records that awareness was delivered |
| How it is judged | Define the competence each role needs, then judge sufficiency | Everyone is in scope; judge coverage |
One e-learning module to everyone covers awareness reasonably well but cannot demonstrate competence. The competence an internal auditor needs, the secure-coding knowledge a developer needs, and the access-management understanding a system administrator needs each have to be defined and secured separately.
Defining "workers" too narrowly
Awareness extends to people working under the organisation's control — not just permanent employees, but directors, fixed-term staff, part-timers, agency staff, and contractor personnel working under your direction. Limiting it to permanent employees invites a question about the validity of the scope. See Defining ISMS Scope.
Training that is just the policy read aloud
An e-learning module amounting to "I have read the policy" partly satisfies awareness but changes no behaviour. Awareness asks for understanding of how one's own work contributes and what follows from not conforming. Generalities do not reach either.
Completion rates are counted but non-completers are not handled
"We reached 95%" means, read the other way, you know exactly who the other 5% are and have done nothing about them. That is the easiest thing in the world for an auditor to pull on. 95% is read not as evidence of control but as evidence that an incomplete state was left alone.
Why it has to be 100%
Three reasons.
- The requirement says everyone. Awareness applies to people working under the organisation's control. A subset does not satisfy it
- Your records identify the non-completers. Once you are tracking completion, the people who did not complete are named. Named and untreated is a nonconformity to correct
- Attacks target the weakest individual. Phishing and insider misuse happen to a person, not to a statistical average. "Almost everyone knows" is not a defence
There are legitimately unreachable periods — extended sick leave, parental leave. Handle these as "out of scope this cycle, delivered on return," not as non-completion. Excluded properly from the denominator, with a procedure for delivery on return, nothing has been left alone.
What You Have to Decide
1. Who is in scope, and where the roster comes from
Define the audience and decide which system supplies the roster — HR, time and attendance, or identity management. A hand-maintained spreadsheet goes stale with every joiner and leaver. Tying the training roster to the same source as account provisioning leaks the least.
2. Types of training and their audiences
| Type | Audience | Frequency | Main content | Records kept |
|---|---|---|---|---|
| Induction | New joiners (including mid-career) and internal movers | Within N days of joining/moving | Policy, basic rules, reporting route, confidentiality undertaking | Date, attendee, comprehension check, signed undertaking |
| Annual all-hands | All workers | Annually | Policy essentials, last year's incidents, changes, worked cases | Date, attendee, comprehension results |
| Role-based | Administrators, developers, supplier managers, HR | Annually or as needed | Access management, secure coding, supplier assessment | Completion record plus competence judgement |
| Internal auditor | Internal auditors | On appointment plus maintenance | Audit method, gathering evidence, reporting | Certificate, audit history |
| Exercises | All workers or specific teams | At least annually | Phishing simulation, incident response drill | Execution record, results, improvements |
| Ad hoc | Those affected | On events | Post-incident prevention, communicating procedure revisions | Execution record, audience covered |
Derive role-based training from the SoA and role definitions. Mapping "operating this control requires this knowledge" keeps competence definitions from being arbitrary.
3. What goes in a completion record
- Date delivered or completed
- Name and department of the attendee
- Course name and version (bump the version whenever content changes)
- Delivery method (classroom, e-learning, video, on the job)
- Whether there was a comprehension check, and the result
- Treatment of non-completers (chase dates, scheduled date, reason for exclusion)
A comprehension check is more useful for "who got what wrong" than for the score. A question the whole organisation fails points straight at next year's content — and is a meaningful Clause 9 measurement. See Setting Security Objectives and KPIs.
4. Mid-year joiners, returners and contractor personnel
- Mid-career joiners: mandate induction within N days and tie it to account provisioning. "No production access until induction is complete" is a control with real teeth
- Returners from leave: re-deliver on return, including procedure changes made while they were away, plus any annual module they were excluded from
- Contractor personnel: either deliver your own training, or obtain evidence that the supplier delivered equivalent training. Decide which in the contract. See Supplier Security Management
How to Do It
Step 1: Build an annual training plan
At the start of the year, fix timing, audience and owner for each type above. Without a plan, you discover in March that something never happened. The plan also feeds the management review.
Step 2: Make the roster obtainable automatically
Export the audience from HR or identity management. If a manual roster is unavoidable, name the owner and the monthly refresh step. Roster freshness determines whether the completion rate means anything.
Step 3: Build content from your own cases
Generic security material changes little. Include your own near misses, points customers raised, and last year's internal audit observations, and the audience's sense of ownership changes. In the first year, when you have few cases, use published incidents from your sector.
Step 4: Deliver, then chase weekly
After sending, refresh the non-completer list weekly and send it to line managers. Completion arrives faster through the manager than through the individual. Add reminders a week before the deadline and on the day.
Step 5: Escalate after the deadline
The ISMS manager escalates remaining non-completers to the individual and their manager. The critical part is keeping the escalation record. Even if a handful are outstanding at year end, chase and escalation records show this is a managed incompletion. With no records, it reads as neglect.
Step 6: Evaluate and feed next year
Compile completion rates, comprehension results and exercise outcomes — click rates and report rates for phishing simulations, for instance — and report to the management review. See Phishing Simulation Exercises and Running a Management Review.
Step 7: Have internal audit verify coverage
Put "reconcile the roster against completion records" on the audit checklist. Reconciling the two is how you find gaps in the roster itself — the on-site contractor nobody added. See Running an Internal Audit.
Where It Goes Wrong
One annual send, and mid-year joiners fall through
The single most frequent failure: sent in April, a July joiner goes untrained until the following April. A standalone induction mechanism fixes it.
Records that do not name individuals
"Distributed to all staff" exists, but per-person completion does not, so coverage cannot be shown. Confirm at selection time whether your e-learning platform's logs can serve as evidence directly.
No comprehension check — opening equals completion
Treating a played video as completion secures no awareness in practice. Three to five questions suffice. Make at least one a genuine judgement question; a quiz everyone aces measures nothing.
No role-based training at all
Trying to meet the competence requirement with all-hands training. Internal auditor competence in particular is always checked; an audit performed by someone who does not know the method casts doubt on the internal audit itself.
Contractor personnel excluded
On site every day but absent from the employee roster, and therefore from training. Regardless of contract form, anyone touching your information assets should be in scope.
The same content every year
Three years of identical slides and nobody reads them. The policy essentials may not change, but last year's cases, procedure revisions and sector developments should. Versioning the content makes the refresh visible in the record.
Comprehension results never used
Tallying the score and stopping there. A widely failed question suggests either the procedure is written unclearly or the rule does not match how work is done. Building a route from training results back into procedure revision is where the ISMS starts to move.
No record of chasing non-completers
As above: falling short of 100% matters less than having no record of what you did about it. Keep the chase and escalation dates.
Healthcare Examples
A healthcare SaaS provider
Beyond all-hands training, you need role-based training for anyone who might touch production patient data: support, SRE, some engineers, analysts. Cover the access request procedure, what may be viewed, the fact that access is logged, and the prohibition on extraction. Making completion a precondition for granting production access turns it into a real control.
Hospital customers' security questionnaires almost always ask about training frequency and coverage. 100% completion plus the role-based training list answers them directly. See When ISMS Becomes a Contract Condition.
A PHR operator
Because data is held under the individual's consent, training centres on never exceeding the consented scope. Teach scope judgement through concrete cases so marketing and analytics staff do not assume "we hold it, so we may use it." See ISMS for PHR Operators.
A SaMD developer
ISO 13485 carries its own training requirements, so design not to maintain two sets of records. Add a "requirement satisfied (ISMS / QMS)" column to one record format and use it for both audits. See SaMD, ISMS and ISO 13485.
A development or maintenance supplier to hospitals
The hospital has its own staff training obligations, and the subjects overlap. Your own training should cover the remote maintenance procedure, what to do on seeing patient data, and the obligation to notify the hospital. For the hospital-side design see Designing Staff Security Training, and for the guidelines overall, The Three-Ministry Guidelines.
Conclusion
- The standard requires competence and awareness separately; one all-hands e-learning module cannot satisfy competence
- Awareness covers everyone working under the organisation's control — directors, fixed-term staff, agency staff and on-site contractor personnel included
- 100% completion is required. 95% reads as "non-completers identified and not handled." Exclude long-term absentees properly from the denominator and procedure their delivery on return
- The gaps appear in three places: mid-year joiners, returners and contractor personnel. Run induction as its own mechanism, tied to account provisioning
- Completion records need name, date, content version, comprehension result and treatment of non-completers
- When you fall short, chase and escalation records are what separate a managed incompletion from neglect
Pottech supports ISMS build and operation with a focus on healthcare. Training is an area where getting the scope definition and record design wrong at the outset cannot be repaired in later years. See ISMS Certification Support or contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Japanese Industrial Standards Committee (JISC)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Personal Information Protection Commission, Japan
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.