Back to Corporate Standards
CS-01 · Corporate Standards

Security Training Mandate

Mandatory cyber-awareness program for every workforce member.

DOCUMENT

CS-01

OWNER

Chief Information Security Officer

EFFECTIVE

January 1, 2026

REVIEWED

April 1, 2026

Class · PUBLIC·Review cycle · Annual

Purpose

Human error remains the leading cause of preventable security incidents. This Mandate establishes the minimum baseline of security education that every workforce member of Alexa Cybersecurity must complete in order to obtain and retain access to company information systems.

It implements ISO/IEC 27001 Annex A.6.3 (Information security awareness, education and training), NIST 800-53 AT-2/AT-3, and the awareness obligations of the SOC 2 Common Criteria.

Scope

This Mandate applies to all employees, contractors, consultants, interns, and third-party service providers (collectively, 'Workforce') that access systems, data, or facilities owned or operated by Alexa Cybersecurity.

Mandatory training tracks

  • 01Onboarding Security Foundations — completed within 7 calendar days of access provisioning.
  • 02Annual Security Refresher — every 12 months, role-specific content.
  • 03Phishing Simulation — at minimum 6 simulated campaigns per year per user.
  • 04Privileged Access Training — additional curriculum for administrators, on-call engineers, and operators with production access.
  • 05Secure Software Development Training — annual, for every contributor to source-controlled production code.
  • 06Incident Reporter Training — quarterly drill for the on-call rotation and Tier-1 SOC analysts.
  • 07Data Protection & Privacy — covering GDPR, CCPA, and client-specific obligations.

Completion thresholds

Workforce members must achieve a passing score of 80% or higher on each module's assessment. A maximum of two retakes is permitted; failure beyond that triggers a one-on-one remediation session with the security education team.

Failure to complete required training within 14 days of the due date results in temporary suspension of access privileges until completion.

Records and audit

Training completion records are retained for the duration of employment plus seven (7) years and are produced on demand for ISO 27001, SOC 2, and government bidding evidence requests.

Enforcement

Violations of this Mandate are subject to corrective action up to and including termination of employment or contract, and revocation of system access.

/CONTROLLED_DOCUMENT

This document is the official, controlled version of CS-01 — Security Training Mandate. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

April 1, 2026

NEXT REVIEW

Annual