# Security Awareness Training Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** Robert — Security Lead  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Ensure all Touch2Sign personnel understand their security responsibilities, recognise common threats, and know how to report incidents. Supports ISO 27001 A.6.3 and SOC 2 CC1.4 awareness requirements.

## 2. Scope

Applies to:

- All employees (full-time and part-time)  
- Contractors with access to Touch2Sign systems or customer data  
- Interns and temporary staff  

Training required **before** production system access is granted.

### 2.1 Solo operator (current)

Robert (sole operator) completes **self-paced annual training** by reading the policy pack and attesting in [TRAINING_REGISTER.md](../TRAINING_REGISTER.md). This satisfies ISO A.6.3 / SOC 2 CC1.4 until additional staff join — see [SOLO_TEAM_OPERATING_MODEL.md](../SOLO_TEAM_OPERATING_MODEL.md).

Phishing simulations are **optional** for solo operator; apply when staff join.

## 3. Training programme

### 3.1 Induction (within first week)

| Topic | Format | Duration |
|-------|--------|----------|
| Information Security Policy overview | Video or live session | 30 min |
| Acceptable Use Policy | Read + acknowledge | 15 min |
| Password, MFA, and phishing basics | Interactive module | 30 min |
| Incident reporting | security@touch2sign.com, Security Lead | 10 min |
| Data classification overview | Read Data Classification Policy | 15 min |
| Remote working rules | Read Remote Working Policy | 10 min |

Completion recorded in HR/training register; manager confirms before production access.

### 3.2 Annual refresher (all staff)

Delivered **once per calendar year**:

- Updated policy highlights  
- Recent incident lessons (anonymised)  
- Phishing simulation results and guidance  
- GDPR and customer data handling reminders  
- eIDAS / signature evidence awareness for customer-facing roles  

Target completion: **100% within 30 days** of annual campaign launch.

### 3.3 Role-specific training

| Role | Additional topics | Frequency |
|------|-------------------|-----------|
| **Engineering** | Secure coding (OWASP Top 10), secrets handling, QA_SIGN_FLOW | Annual + on hire |
| **Support** | DSAR basics, minimum necessary access, phishing targeting support | Annual |
| **Sales / CS** | No PHI commitments, sub-processor list accuracy, demo data only | Annual |
| **Management** | Risk register, breach notification 72h, vendor approval | Annual |

## 4. Phishing awareness

Touch2Sign runs **simulated phishing exercises**:

| Activity | Frequency |
|----------|-----------|
| Simulated phishing emails | **Quarterly** |
| Clickers receive immediate micro-training | Automatic |
| Repeat clickers (>2 in 12 months) | 1:1 with Security Lead |

Reporting real phishing:

- Forward to security@touch2sign.com  
- Do not click links or open attachments  
- praised for reporting — no penalty for good-faith clicks on simulations  

## 5. Incident reporting training

All staff must know:

| Question | Answer |
|----------|--------|
| Who to contact? | Security Lead; security@touch2sign.com |
| When? | Immediately — no approval needed |
| What to report? | Suspected breach, lost device, phishing, policy violation, unusual system behaviour |
| What not to do? | Delete logs; notify attacker; discuss publicly |

Link to **Incident Response Plan** in training materials.

## 6. Policy acknowledgements

Staff acknowledge annually:

- Information Security Policy  
- Acceptable Use Policy  
- Remote Working Policy  
- HIPAA Scope Policy (confirmation: will not upload PHI)  

Electronic signature via HR system, signed checklist, or [TRAINING_REGISTER.md](../TRAINING_REGISTER.md) — stored **3 years**.

## 7. Training records

| Field | Retained |
|-------|----------|
| Employee name | Yes |
| Course / module | Yes |
| Completion date | Yes |
| Score (if applicable) | Yes |
| Acknowledged policy version | Yes |

Retention: duration of employment + **3 years**.

## 8. Non-compliance

Failure to complete mandatory training within deadline:

- Production access suspended until completion  
- Repeated non-compliance escalated to manager and CEO  

## 9. Metrics

Security Lead reports quarterly to CEO:

- Induction completion rate  
- Annual refresher completion rate  
- Phishing simulation click rate  
- Training-related audit findings  

## 10. Related documents

- Information Security Policy  
- Acceptable Use Policy  
- Incident Response Plan  
- DSAR Procedure  
- Secure Development Policy  

## 11. Review

Training content reviewed **annually** and updated after significant incidents or regulatory changes.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
