This document is under active development and has not been finalized.
Skip to content

Training Program

Mandatory Training

Basic Training -- All Employees

ModuleContentDurationInterval
Information Security FundamentalsProtection goals, data classification, responsibilities30 minAnnually
Phishing & Social EngineeringRecognition, current attack patterns, reporting channels30 minAnnually
Password & Access SecurityPassword managers, MFA, screen locking20 minAnnually
Incident ReportingReporting obligation, channels, contacts, examples15 minAnnually
Data ProtectionPersonal data, GDPR fundamentals, data subject rights20 minAnnually

Total duration: ~2 hours per year

Management Training (§38(3) BSIG)

ContentDescription
Current threat landscapeRelevant attacks, trends, industry-specific risks
NIS2/BSIG obligations§30 measures, §32 reporting obligations, §38 liability
Risk managementReading and assessing risk analyses, approving measures
Incident escalationRole of management during incidents, communication decisions

Duration: 2--3 hours per year, delivered by ISO or external trainer

Role-Specific Training

Target GroupModulesDurationInterval
IT AdministrationSecure configuration, patch processes, log management, hardening4hAnnually
Software DevelopmentSecure coding, OWASP Top 10, dependency management, code review4hAnnually
Project ManagementSecurity requirements, risk assessment in projects2hAnnually
Helpdesk / SupportSocial engineering recognition, escalation, data protection2hAnnually

Training Methods

MethodApplication
E-learningBasic and mandatory training, self-paced
In-person trainingManagement training, role-specific workshops
Phishing simulationPractical awareness testing, semi-annually
Security advisoriesCurrent warnings via email during acute threats

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT