if you want to evaluate that all the employees have completed the information security awareness training, we can ask the following evidence as an auditor:
- Completion transcripts showing employee names, training dates, and scores
- Attendance records from training platforms
- total number of users
- Policy acknowledgement form, signed by the employees
- Training schedules aligned with Onboarding, preferably within 30 days and annual refreshers
Metrics
A. Fed Rate: Total employees targeted vs. organization size (use campaign enrollment lists)
B. Click Rate: (Clicked links / Emails delivered) × 100. Validate via phishing simulation tools
C. Report Rate: (Reported emails / Emails delivered) × 100. Check platform logs or CSV exports
If given an Excel export of users
• Cross-verify against HR records to ensure all employees are included.
• Filter for incomplete training or repeated phishing failures.
• Check timestamps for compliance with onboarding/annual deadlines
Those were tracking matrix
1. Phishing simulation: Proofpoint
2. Learning management systems (LMS): Melimu
What is the difference between training and awareness?
Training and awareness serve distinct purposes in a security program. Awareness is about fostering a security-conscious culture, using methods like newsletters, posters, and regular reminders to keep security top-of-mind for employees. It focuses on building general understanding and mindfulness regarding security practices. On the other hand, training is more structured and skills-oriented. It involves formal sessions like webinars, bootcamps, or interactive modules with defined goals, tailored content, and practical exercises to equip employees with specific competencies needed to handle security-related tasks effectively. While awareness shapes attitudes, training develops abilities.
Training: social engineering defense training: handling physically intruders, and visitors, telephone calls and enquiries, phishing emails, USB drop attacks, recognising legitimate and fraudulent websites, job specific training,