This document is under active development and has not been finalized.
Skip to content

Training & Awareness

LEGAL BASIS

§30(2) No. 7 BSIG – Basic cyber hygiene practices and information security training

§38(3) BSIG – Management must regularly participate in training.

Training Program

Basic Training (all employees)

TopicContentInterval
Phishing & social engineeringRecognition, reporting channels, practical examplesAnnually
Password & access securityStrong passwords, MFA, password managersAnnually
Secure communicationEmail security, encrypted channelsAnnually
Incident reportingReporting obligation, channels, contactsAnnually
Data protection basicsPersonal data, GDPR basicsAnnually

Role-Specific Training

Target GroupAdditional Content
ManagementNIS2 obligations per §38, liability, governance (mandatory)
IT administrationSecure system operation, patch management, logging
Software developmentSecure coding, OWASP Top 10, supply chain security
Project managementSecurity requirements in projects, risk assessment

Onboarding

New employees receive before system access:

  • Introduction to information security policy
  • Basic cyber hygiene training
  • Acknowledgment of security policies

Documentation

  • Attendance records maintained centrally
  • Training completion is a prerequisite for system access rights
  • Annual evaluation of completion rates as KPI

AI Act Synergy

The AI competence program (Art. 4 AI Act) complements NIS2 training obligations. Details in the AI Act Compliance Documentation.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT