peopleVersion 1SOC2ISO27001NIST800-171
Security Training & Awareness Policy
Mandatory curriculum, delivery, and phishing testing for all personnel.
Security Training & Awareness Policy
1. Purpose
Gives every Rex Black person the knowledge they need to handle data securely and to recognize and report threats.
2. Curriculum
Onboarding (within 30 days of start):
- Rex Black policies walkthrough.
- Phishing / social-engineering recognition.
- Password, MFA, and Vault use.
- Data classification and handling.
- Incident reporting.
- AI tool use and data exposure.
Annual refresh:
- Updated policies and material changes.
- Current threat landscape (phishing trends, ransomware, supply chain).
- Privacy (GDPR/CCPA, data subject rights).
- Secure remote work.
Role-specific: engineers: secure coding (OWASP Top 10, API auth, AWS IAM basics). HR / Finance: social engineering for invoice fraud. Client-facing: client-data handling and breach reporting.
Sensitive scopes (as applicable):
- HIPAA awareness for engagements touching PHI.
- CUI handling for government engagements.
- PCI DSS awareness for anyone handling payment card data.
3. Delivery
- Training is delivered via recorded modules plus interactive checks. Duration: ~45 minutes for the annual refresh.
- Completion is recorded in the training register
(
registers/training-completion.mdor equivalent system). - Personnel unable to complete on time get a 14-day grace period; beyond that, access to non-public systems is suspended until completion.
4. Phishing testing
- Phishing simulations are run at least quarterly with varied templates.
- Results inform targeted coaching; repeated failures escalate to the disciplinary process.
- Reporting a phishing email is always treated as the correct response, not penalized even if the email turns out to be legitimate.
5. Awareness
- Monthly security bulletin summarizes incidents in the industry, phishing themes, and any Rex Black internal updates.
- Slack channel
#security-pingsfor timely alerts.
6. Metrics
- Onboarding completion rate (target: 100% within 30 days).
- Annual completion rate (target: 100% by anniversary + 30 days).
- Phishing click-through rate (target: < 5% trending down).
- Phishing reporting rate (target: > 60%).
7. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Curriculum, delivery, metrics. |
| All personnel | Complete training on schedule; report suspicious activity. |
8. References
003-acceptable-use-policy.md023-hr-security-policy.md012-incident-response-plan.md
9. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.