Security awareness training is mandatory and tracked
Once your company begins on its compliance journey, whether it is SOC 2 Type 2 or ISO 27001, you will need records showing that every employee has taken annual security awareness training. Don’t worry if you haven’t been doing this in the years prior to getting SOC 2 Type 2 or ISO 27001. When you are ready to go for compliance, the security awareness training is mandatory once you are in your audit window. It is good to start doing security awareness training as soon as possible, and using one of these great platforms such as Curricula, KnowBe4, or Ninjio will make the process super easy. One thing to be aware of is that once you are in an audit period (for example, with SOC 2 Type 1), it
is a point-in-time (PIT) audit. The auditors come in and check the controls for a particular day and conduct the audit. For SOC 2 Type 2, you will decide on an audit reporting period from 3 months to 1 year. During that audit reporting...