14.1
IG1 IG2 IG3

Establish and Maintain a Security Awareness Program

Asset Type: N/A
Security Function: Protect

Description

Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.

Implementation Checklist

1
Assess current protection controls in place
2
Configure and deploy required security controls
3
Test control effectiveness in non-production environment
4
Deploy to production and verify functionality
5
Document configuration and operational procedures
6
Develop or procure training content
7
Define training audience and completion requirements
8
Deploy training and track completion rates
9
Measure training effectiveness through testing/simulation
10
Establish security awareness training program
11
Track training completion and measure effectiveness
12
Conduct phishing simulations

Threats & Vulnerabilities (CIS RAM)

Threat Scenarios

Enterprise-Wide Phishing Campaign Targeting Untrained Workforce

Confidentiality

A sophisticated phishing campaign targets employees who have received no security awareness training, resulting in widespread credential compromise because staff cannot recognize social engineering tactics.

Accidental Insider Threat from Security-Unaware Employee

Integrity

An employee unknowingly installs malware by clicking a malicious link or opens a weaponized attachment because they have never been educated on safe computing practices through a formal awareness program.

Social Engineering Attack Exploiting Lack of Security Culture

Confidentiality

An attacker impersonates a vendor over the phone and convinces an employee to share system credentials, succeeding because no security awareness program has established a culture of verification and skepticism.

Vulnerabilities (When Safeguard Absent)

No Formal Security Awareness Training Program

Without an established security awareness program, employees receive no structured education on security threats, safe practices, or organizational policies, leaving human behavior as the weakest link.

Untrained New Hires Immediately Exposed to Threats

Absence of onboarding security training means new employees begin handling enterprise assets and data without understanding the threat landscape or their role in maintaining security.

Evidence Requirements

Type Evidence Item Collection Frequency
Technical Configuration screenshots or exports showing protection controls enabled Captured quarterly
Document Procedure documentation for protection measures Reviewed annually
Record Training completion records and compliance rates Tracked continuously, reported quarterly
Document Training content and curriculum documentation Reviewed annually
Document Governing policy document (current, approved, communicated) Reviewed annually