Skip to main content

peopleVersion 1SOC2ISO27001NIST800-171

Security Training & Awareness Policy

Mandatory curriculum, delivery, and phishing testing for all personnel.

Download PDFSHA-256 4311699eb46e8ce2…

Security Training & Awareness Policy

1. Purpose

Gives every Rex Black person the knowledge they need to handle data securely and to recognize and report threats.

2. Curriculum

  1. Onboarding (within 30 days of start):

    • Rex Black policies walkthrough.
    • Phishing / social-engineering recognition.
    • Password, MFA, and Vault use.
    • Data classification and handling.
    • Incident reporting.
    • AI tool use and data exposure.
  2. Annual refresh:

    • Updated policies and material changes.
    • Current threat landscape (phishing trends, ransomware, supply chain).
    • Privacy (GDPR/CCPA, data subject rights).
    • Secure remote work.
  3. Role-specific: engineers: secure coding (OWASP Top 10, API auth, AWS IAM basics). HR / Finance: social engineering for invoice fraud. Client-facing: client-data handling and breach reporting.

  4. Sensitive scopes (as applicable):

    • HIPAA awareness for engagements touching PHI.
    • CUI handling for government engagements.
    • PCI DSS awareness for anyone handling payment card data.

3. Delivery

  1. Training is delivered via recorded modules plus interactive checks. Duration: ~45 minutes for the annual refresh.
  2. Completion is recorded in the training register (registers/training-completion.md or equivalent system).
  3. Personnel unable to complete on time get a 14-day grace period; beyond that, access to non-public systems is suspended until completion.

4. Phishing testing

  1. Phishing simulations are run at least quarterly with varied templates.
  2. Results inform targeted coaching; repeated failures escalate to the disciplinary process.
  3. Reporting a phishing email is always treated as the correct response, not penalized even if the email turns out to be legitimate.

5. Awareness

  1. Monthly security bulletin summarizes incidents in the industry, phishing themes, and any Rex Black internal updates.
  2. Slack channel #security-pings for timely alerts.

6. Metrics

  • Onboarding completion rate (target: 100% within 30 days).
  • Annual completion rate (target: 100% by anniversary + 30 days).
  • Phishing click-through rate (target: < 5% trending down).
  • Phishing reporting rate (target: > 60%).

7. Roles & responsibilities

Role Responsibility
Security Officer Curriculum, delivery, metrics.
All personnel Complete training on schedule; report suspicious activity.

8. References

  • 003-acceptable-use-policy.md
  • 023-hr-security-policy.md
  • 012-incident-response-plan.md

9. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center