HRS-005 Role-Based Security Training
Description
Personnel in roles with elevated security responsibilities, including system administrators, developers, data handlers, and incident responders, receive role-specific security training before gaining access to production systems and at defined intervals thereafter. Training records are maintained for each individual. The training programme names the roles and positions that require security skills, the criteria by which a role enters the programme and the competence each named group reaches. The members of the management body are one such group, and their standard is enough knowledge and skill to identify risks and to assess the organisation's risk-management practices and their effect on the services it provides. The curriculum for each group covers the secure configuration and operation of the systems that group touches, the threats current against them and what to do when a security-relevant event occurs. Training is delivered before a transfer into a role the programme names as well as before production access is granted. The effect of the training is assessed rather than its completion counted, and the assessment result feeds the next revision of the programme.
Rationale
General awareness training is insufficient for personnel who make security-critical decisions or hold elevated privileges. Role-based training ensures that those with the greatest access have the domain-specific knowledge to exercise it safely. A group with a competence standard is a different instrument from a course with an attendance list: it says what the person can do afterwards, which is what makes a non-executive director with no system access trainable under a control whose original trigger was production access. The management body is the group most often outside every syllabus and the one a regulator asks about first. An assessment of effect rather than completion stops the programme drifting into a compliance click-through, and unless its result feeds the next revision it is only a second attendance record.
Applicability (9 profiles)
Art. 20(2) and Annex points 8.2.2 to 8.2.4 are now stated: named role groups with the criteria by which a role enters the programme, a competence standard per group, the members of the management body as one of those groups with the Art. 20(2) standard of enough knowledge and skill to identify risks and assess risk-management practices and their effect on the services, training on transfer into a named role, and effectiveness assessed rather than completion counted. Annex point 8.1, the awareness programme reaching direct suppliers and service providers, stays a note on HRS-004.
Framework Mappings (13)
| HRS-12 | Personal and Sensitive Data Awareness and Training | full |
| HRS-14 | AI Competency Training | informative |
| HRS-12 | Personal and Sensitive Data Awareness and Training | full |
| EU-AI-Art.4 | AI Literacy — Measures to Support Staff and Operator Literacy | informative |
| HIPAA-164.308.a.5.i | Security Awareness and Training | informative |
| 6.3 | Information security awareness, education and training | partial |
| NIS2-Art.20.2 | Management Body Cybersecurity Training | full |
| NIS2-Art.21.2.g | Basic Cyber Hygiene Practices and Cybersecurity Training | informative |
| NIS2-CIR-8.2 | Security Training | full |
| AT-3 | Role-based Training | full |
| AT-4 | Training Records | full |
| PM-13 | Security and Privacy Workforce | partial |
| CC1.4 | COSO Principle 4: Demonstrates Commitment to Competence | partial |
Evidence (2)
Role-based security training completion records for personnel in elevated-privilege or security-critical roles.
Example: Training completion records from the LMS (KnowBe4 / internal training platform) filtered to role-based tracks, e.g. 'Cloud Security for Admins', 'Secure Coding', 'Incident Response', showing: employee name, role, training completed, completion date, and next due date.
Test: Export role-based training completion records for system administrators, developers, and incident responders. Verify: (1) every individual in a defined elevated-privilege role has a training completion record for the relevant role track, (2) completion occurred before or within 30 days of gaining production access, (3) annual renewal completions are on file, (4) no individual in a high-privilege role is overdue. (5) every member of the management body carries a completion record against that group's curriculum, (6) a person who transferred into a named role in the period completed its training on or before the transfer date, (7) the effectiveness assessment for each group is recorded with its result and the revision it produced.
Role-based training procedure defining which roles require additional training, the required curriculum per role, and the completion deadline before production access is granted.
Example: Role-Based Security Training Procedure (Confluence), listing: designated high-sensitivity roles (e.g. sysadmin, DevOps, data engineer, security analyst), required training modules per role, maximum time-to-complete after role assignment, and records retention requirement.
Test: Request the role-based training procedure. Verify: (1) at least three distinct elevated-privilege role categories are listed, (2) specific training modules are assigned to each role, (3) a maximum time-to-complete deadline is stated, (4) the procedure is approved and dated within the last 12 months. (5) the procedure names the criteria by which a role enters the programme rather than only listing the roles, (6) each named group carries a competence standard and a curriculum covering secure configuration and operation, current threats and behaviour when a security-relevant event occurs, (7) the members of the management body are a named group with a competence standard of their own, (8) the procedure triggers training on transfer into a named role as well as on the grant of production access.
Questions (3)
Do personnel in elevated-privilege or security-critical roles (e.g. sysadmins, developers, incident responders) receive role-specific security training before gaining production access and at defined intervals thereafter?
Role-based training records should show completion before or within 30 days of production access being granted, with annual renewal records on file.
Which of the following role-specific security training tracks does your organisation deliver?
At least three distinct role tracks covering different privilege tiers are expected. Training is matched to the systems and data each role can reach. The management body track is the one most often absent, because the programme is usually built around who holds production access and the board holds none.
How is the effect of role-based training measured?
Options run from strongest to weakest. A test at the end of a module measures recall of the module, not competence in the role, which is why it sits below an assessment against the standard. Answer on what happened at the last delivery rather than on what the procedure describes.