Security Training & Awareness Log¶
Purpose. The record of who completed which security training or awareness activity, and when (ISO/IEC 27001:2022 7.2, 7.3, control A.6.3; monitoring metric M9). Entries are appended automatically by the
/isms:onboardcommand — each run of the onboarding/refresher adds a row and lands via a PR, so the git history is the audit trail.
Cadence: every team member completes the essentials refresher quarterly; new joiners complete it during onboarding. Material: ESSENTIALS.md (distilled from the approved policy set).
Log¶
| Date | Person | Activity | Material (version) | Method | Notes / questions raised |
|---|---|---|---|---|---|
| — | — | No entries yet — run /isms:onboard |
— | — | — |
How an entry gets here¶
- A team member runs
/isms:onboardin Claude Code. - Claude walks them through the essentials, takes questions, and spot-checks understanding.
- Claude appends a row here and opens a PR; the merge is the completion record.
- Anything they flagged as unclear or not-matching-reality is noted and routed to the ISM as an improvement item.
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-07-02 | ISMS | Created — empty log, populated by /isms:onboard runs. |