Under active development Content is continuously updated and improved

2602.02602.0

>Control Description

The Supplier shall ensure that people who support the operation of Functions and protection of Data are appropriately trained in cyber security. The Supplier shall conduct awareness training at least every 12 months to recognise and respond to the following topics: i) Social engineering and phishing ii) Advanced persistent threats iii) Suspected breaches iv) Suspicious behaviours. A range of approaches to cyber security training, awareness and communications shall be employed and the Supplier shall update the training every 12 months or when there are significant changes to the threat.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.