Skip to content

Security Training & Awareness Log

Purpose. The record of who completed which security training or awareness activity, and when (ISO/IEC 27001:2022 7.2, 7.3, control A.6.3; monitoring metric M9). Entries are appended automatically by the /isms:onboard command — each run of the onboarding/refresher adds a row and lands via a PR, so the git history is the audit trail.

Cadence: every team member completes the essentials refresher quarterly; new joiners complete it during onboarding. Material: ESSENTIALS.md (distilled from the approved policy set).

Log

Date Person Activity Material (version) Method Notes / questions raised
No entries yet — run /isms:onboard

How an entry gets here

  1. A team member runs /isms:onboard in Claude Code.
  2. Claude walks them through the essentials, takes questions, and spot-checks understanding.
  3. Claude appends a row here and opens a PR; the merge is the completion record.
  4. Anything they flagged as unclear or not-matching-reality is noted and routed to the ISM as an improvement item.

Change log

Version Date Author Comments
0.1 2026-07-02 ISMS Created — empty log, populated by /isms:onboard runs.