Version 1.0 · Draft · Owner: HR
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Ensure all Touch2Sign personnel understand their security responsibilities, recognise common threats, and know how to report incidents. Supports ISO 27001 A.6.3 and SOC 2 CC1.4 awareness requirements.
Applies to:
Training required before production system access is granted.
Robert (sole operator) completes self-paced annual training by reading the policy pack and attesting in TRAINING_REGISTER.md. This satisfies ISO A.6.3 / SOC 2 CC1.4 until additional staff join — see SOLO_TEAM_OPERATING_MODEL.md.
Phishing simulations are optional for solo operator; apply when staff join.
| Topic | Format | Duration | Information Security Policy overview | Video or live session | 30 min |
|---|---|---|
| Acceptable Use Policy | Read + acknowledge | 15 min |
| Password, MFA, and phishing basics | Interactive module | 30 min |
| Incident reporting | security@touch2sign.com, Security Lead | 10 min |
| Data classification overview | Read Data Classification Policy | 15 min |
| Remote working rules | Read Remote Working Policy | 10 min |
Completion recorded in HR/training register; manager confirms before production access.
Delivered once per calendar year:
Target completion: 100% within 30 days of annual campaign launch.
| Role | Additional topics | Frequency | Engineering | Secure coding (OWASP Top 10), secrets handling, QA_SIGN_FLOW | Annual + on hire |
|---|---|---|
| Support | DSAR basics, minimum necessary access, phishing targeting support | Annual |
| Sales / CS | No PHI commitments, sub-processor list accuracy, demo data only | Annual |
| Management | Risk register, breach notification 72h, vendor approval | Annual |
Touch2Sign runs simulated phishing exercises:
| Activity | Frequency | Simulated phishing emails | Quarterly |
|---|---|
| Clickers receive immediate micro-training | Automatic |
| Repeat clickers (>2 in 12 months) | 1:1 with Security Lead |
Reporting real phishing:
All staff must know:
| Question | Answer | Who to contact? | Security Lead; security@touch2sign.com |
|---|---|
| When? | Immediately — no approval needed |
| What to report? | Suspected breach, lost device, phishing, policy violation, unusual system behaviour |
| What not to do? | Delete logs; notify attacker; discuss publicly |
Link to Incident Response Plan in training materials.
Staff acknowledge annually:
Electronic signature via HR system, signed checklist, or TRAINING_REGISTER.md — stored 3 years.
| Field | Retained | Employee name | Yes |
|---|---|
| Course / module | Yes |
| Completion date | Yes |
| Score (if applicable) | Yes |
| Acknowledged policy version | Yes |
Retention: duration of employment + 3 years.
Failure to complete mandatory training within deadline:
Security Lead reports quarterly to CEO:
Training content reviewed annually and updated after significant incidents or regulatory changes.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com