A.6.3 People
Information security awareness, education and training
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AT-2fullcovers — The ISO control establishes a recurring, role-aware awareness program that directly fulfills the intent of AT-2 to ensure all users understand their security responsibilities.
- AT-3fullcovers — By requiring targeted training for technical teams and skill-gap remediation, the ISO control satisfies AT-3’s mandate for role-based training aligned with job functions.
- AT-4mostlyaligns with — The ISO control’s requirement to assess understanding after each activity supports the record-keeping and effectiveness-tracking objectives of AT-4.
- PM-13partialaligns with — The ISO control’s emphasis on building and maintaining technical security skills across the workforce contributes to the broader workforce-development goal of PM-13.
Aligned NIST CSF 2.0 outcomes (6)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-04mostlyaligns with — By embedding security awareness, education, and training into human-resources practices for new and transferring personnel, the ISO control supports the CSF outcome of integrating cybersecurity into HR processes.
- ID.IM-01partialaligns with — The ISO control mandates post-activity assessments of personnel understanding and uses lessons learned from incidents to refine the programme, contributing to the CSF outcome of identifying improvements from evaluations.
- PR.AT-01nonegoverns — The ISO control establishes and operates a recurring awareness programme that ensures all personnel understand their security responsibilities and baseline controls, directly satisfying the CSF outcome of providing general awareness and training.
- PR.AT-02nonegoverns — The ISO control requires a targeted education and training plan for technical teams that need specialized skills, matching the CSF outcome of equipping individuals in specialized roles with the necessary knowledge and skills.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — Awareness of data-handling obligations and incident-reporting procedures reduces the chance that staff will inadvertently disclose sensitive information.
- CWE-284partialprevents — Personnel who understand their responsibilities and the baseline controls they must follow are less likely to grant or exercise access rights beyond what policy permits.
- CWE-356partialprevents — Security awareness training can teach users to heed or demand warnings for unsafe actions.
- CWE-451partialprevents — Security awareness training can teach users to recognize UI misrepresentation and phishing attempts.
- CWE-522partialprevents — Regular reminders about password security and personal accountability make users less likely to store or transmit credentials in cleartext or other unprotected forms.
- CWE-676partialprevents — Developer security awareness training can teach safe alternatives to risky functions.
- CWE-732partialprevents — Training on baseline controls and policy compliance helps staff avoid assigning overly permissive file or resource permissions that expose assets to unauthorized actors.
- CWE-798partialprevents — Education on secure configuration practices discourages technical staff from embedding or relying on hard-coded credentials in systems and applications.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1204mostlyprevents — Trained users are more likely to recognize and avoid executing malicious files, links, or images delivered through social engineering, thereby limiting user-driven execution of adversary payloads.
- T1566mostlyprevents — Personnel who regularly receive awareness training on phishing indicators and reporting procedures are less likely to open malicious attachments or click malicious links, reducing the success rate of phishing campaigns.
- T1598mostlyprevents — Security awareness reduces the chance that employees will disclose sensitive organizational information when targeted by information-gathering phishing attempts.
- T1078partialmitigates — Personnel trained on account security responsibilities and the importance of protecting credentials are less likely to allow their valid accounts to be misused for unauthorized access.
- T1110partialmitigates — Awareness of password policies and the risks of credential reuse or weak passwords reduces the likelihood that users will choose credentials that are easy for adversaries to guess or crack.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — Regular awareness and targeted training reduce the likelihood that administrators will leave systems or applications in default or insecure states by ensuring they understand and apply baseline hardening requirements.
- A07partialmitigates — Personnel who receive periodic training on authentication procedures and password controls are less likely to implement weak credential practices that enable authentication bypass or account compromise.
- A09partialmitigates — Including incident-reporting procedures in awareness programmes increases the chance that security events are promptly logged and escalated, improving detection coverage and response effectiveness.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.