Touch2Sign Policy Library
← All policies

Security Awareness Training

Version 1.0 · Draft · Owner: HR

Download .md →

Security Awareness Training Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: Robert — Security Lead

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Ensure all Touch2Sign personnel understand their security responsibilities, recognise common threats, and know how to report incidents. Supports ISO 27001 A.6.3 and SOC 2 CC1.4 awareness requirements.

2. Scope

Applies to:

  • All employees (full-time and part-time)
  • Contractors with access to Touch2Sign systems or customer data
  • Interns and temporary staff

Training required before production system access is granted.

2.1 Solo operator (current)

Robert (sole operator) completes self-paced annual training by reading the policy pack and attesting in TRAINING_REGISTER.md. This satisfies ISO A.6.3 / SOC 2 CC1.4 until additional staff join — see SOLO_TEAM_OPERATING_MODEL.md.

Phishing simulations are optional for solo operator; apply when staff join.

3. Training programme

3.1 Induction (within first week)

Topic Format Duration
Information Security Policy overview Video or live session 30 min
Acceptable Use Policy Read + acknowledge 15 min
Password, MFA, and phishing basics Interactive module 30 min
Incident reporting security@touch2sign.com, Security Lead 10 min
Data classification overview Read Data Classification Policy 15 min
Remote working rules Read Remote Working Policy 10 min

Completion recorded in HR/training register; manager confirms before production access.

3.2 Annual refresher (all staff)

Delivered once per calendar year:

  • Updated policy highlights
  • Recent incident lessons (anonymised)
  • Phishing simulation results and guidance
  • GDPR and customer data handling reminders
  • eIDAS / signature evidence awareness for customer-facing roles

Target completion: 100% within 30 days of annual campaign launch.

3.3 Role-specific training

Role Additional topics Frequency
Engineering Secure coding (OWASP Top 10), secrets handling, QA_SIGN_FLOW Annual + on hire
Support DSAR basics, minimum necessary access, phishing targeting support Annual
Sales / CS No PHI commitments, sub-processor list accuracy, demo data only Annual
Management Risk register, breach notification 72h, vendor approval Annual

4. Phishing awareness

Touch2Sign runs simulated phishing exercises:

Activity Frequency
Simulated phishing emails Quarterly
Clickers receive immediate micro-training Automatic
Repeat clickers (>2 in 12 months) 1:1 with Security Lead

Reporting real phishing:

  • Forward to security@touch2sign.com
  • Do not click links or open attachments
  • praised for reporting — no penalty for good-faith clicks on simulations

5. Incident reporting training

All staff must know:

Question Answer
Who to contact? Security Lead; security@touch2sign.com
When? Immediately — no approval needed
What to report? Suspected breach, lost device, phishing, policy violation, unusual system behaviour
What not to do? Delete logs; notify attacker; discuss publicly

Link to Incident Response Plan in training materials.

6. Policy acknowledgements

Staff acknowledge annually:

  • Information Security Policy
  • Acceptable Use Policy
  • Remote Working Policy
  • HIPAA Scope Policy (confirmation: will not upload PHI)

Electronic signature via HR system, signed checklist, or TRAINING_REGISTER.md — stored 3 years.

7. Training records

Field Retained
Employee name Yes
Course / module Yes
Completion date Yes
Score (if applicable) Yes
Acknowledged policy version Yes

Retention: duration of employment + 3 years.

8. Non-compliance

Failure to complete mandatory training within deadline:

  • Production access suspended until completion
  • Repeated non-compliance escalated to manager and CEO

9. Metrics

Security Lead reports quarterly to CEO:

  • Induction completion rate
  • Annual refresher completion rate
  • Phishing simulation click rate
  • Training-related audit findings

10. Related documents

  • Information Security Policy
  • Acceptable Use Policy
  • Incident Response Plan
  • DSAR Procedure
  • Secure Development Policy

11. Review

Training content reviewed annually and updated after significant incidents or regulatory changes.


Approval

Name Role Signature Date
Robert CEO / Security Lead Electronic 11 July 2026

Questions: security@touch2sign.com · privacy@touch2sign.com