What to Provide
Security awareness training completion log, with emphasis on new hires sampled.
For each new hire sampled, the evidence should demonstrate who has completed training and when.
NOTE: The audit team will communicate sample selections once they have been finalized. Please refrain from attaching evidence in this ER until samples have been communicated.
Evidence Format
Word/PDF document, exported images in a common image file type (i.e. .jpg, .png, .pdf), Excel/.csv export from the source system
Additional Guidance
Whether you implement your security awareness training with a third party vendor or using Thoropass Training, you'll need to upload your training log.
Associated Unified Control ID | Associated Framework Control |
CTRL-245 | LCL-9 |