For CISOs, IT, and compliance teams in LATAM, Human Risk Management brings together three layers that often appear separately: standards call for a continuous awareness and training program, not a one-off course; analysts and vendors describe HRM as continuous measurement of behavior and human risk; and the operational value appears when that measurement makes it possible to prioritize interventions, reallocate resources, and report to leadership with risk metrics, not just course completion.
What appears when standards and operational HRM are compared
Placed side by side, the sources show something that is rarely stated outright: the minimum required by standards demands continuity and structure, while HRM adds a behavioral quantification layer that enables concrete operational decisions. That difference is what separates a program that complies from one that actually manages human risk.
| Subject | Type of requirement or approach | What is measured or expected | Frequency or time frame | Decision or operation it enables | Source |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 clause 7.3 and Annex A 6.3 | Normative requirement for awareness and information security training | That people are aware of the policy, their contribution to the effectiveness of the ISMS, and the implications of noncompliance; maintain appropriate awareness and training | Continuous, because the ISMS must be established, implemented, maintained, and continually improved | Demonstrate that there is a structured and continuous awareness and training program | clause 7.3 requires awareness of policy, contribution to the ISMS, and implications of noncompliance, and Annex A 6.3 requires maintaining appropriate awareness and training |
| ISO/IEC 27002:2022 control 6.3 | Control guidance for awareness, education, and training | That people receive appropriate awareness, education, and training, with regular updates based on their role | Regular and role based | Design differentiated programs by function and keep regular updates | control 6.3 calls for appropriate awareness, education, and training, plus regular updates relevant to the role |
| PCI DSS v4.0 requirement 12.6 | Normative requirement for a formal security awareness program | Implement a formal program that educates personnel on information security and their responsibilities in protecting cardholder data | Continuous and managed program, not an isolated course | Prove the existence of a formal and structured awareness program | requirement 12.6 calls for implementing a formal security awareness program, not a standalone event |
| NIST SP 800-50 | Practical framework for awareness and training | Identify roles and responsibilities, define goals and messages by audience, establish performance metrics, and evaluate effectiveness | Periodic evaluation | Measure effectiveness by audience and adjust the program | |
| NIST Cybersecurity Framework v1.1 PR.AT | Awareness and training category within Protect | That all users receive awareness and training on their specific responsibilities, and that security personnel maintain appropriate skills | Implicit continuity through skill maintenance | Align human risk management with the Protect function | |
| Forrester HRM | Operational definition of an HRM solution | Detect and measure security behaviors, quantify human risk, trigger interventions, enable the workforce, and build a positive culture | Continuous and behavior change oriented | Use quantified risk to trigger interventions and guide culture strategy | HRM solutions should detect and measure behaviors, quantify human risk, and initiate interventions, while meeting regulatory awareness is a secondary use case |
| Adaptive Security HRM | Continuous management framework | Phishing clicks, reports of suspicious activity, policy tracking, and dynamic risk scores per employee | Continuous, through Assess, Prioritize, Tailor, Track, and behavior-triggered training | Prioritize interventions, inform the board, and justify investment | |
| Infosec Institute HRM | Scoring approach based on real signals | Integrate real-time SIEM, endpoint, and network data to generate a more complete assessment; measure human errors, clicks, and suspicious reports | Real time and throughout the employee lifecycle | Continuously adjust the program with behavioral and technical evidence | HRM integrates real-time SIEM, endpoint, and network data to generate a more complete risk score based on real behavior |
| Hoxhunt HRM | Outcome-driven approach for CISOs, SOC, and awareness teams | Behavior measurement, reduction in real phishing clicks, increase in valid reports, fewer data handling errors, and SOC integration | Continuous and outcomes based | Demonstrate risk reduction, adapt training, and integrate employee reports into SOC workflows | HRM calls for outcome-based metrics such as fewer clicks, more valid reports, and SOC integration |
| Arctic Wolf HRM | Treating human risk as an operational part of total cyber risk | Correlate identity activity, access patterns, and behavior signals to understand, prioritize, and reduce risk introduced by users | Continuous measurement over time | Prioritize training, control strengthening, and access changes based on risk profiles | human risk is treated as a measurable component of total risk by correlating identity, access, and behavior |
Do standards require awareness or human risk management?
The standards in the source material speak first and foremost about awareness, education, training, and formal programs. clause 7.3 requires people to be aware of the policy, their contribution to the ISMS, and the implications of noncompliance, control 6.3 asks for appropriate awareness, education, and training with regular updates based on role, and requirement 12.6 requires implementing a formal security awareness program.
Whalemate's reading is that this minimum standard is not enough, by itself, to manage human risk. It is enough to show that a program exists, that it is continuous, and that it has structure. It does not automatically resolve which people, teams, or third parties need priority intervention, or what evidence would show that human risk actually went down.
Why does Forrester treat compliance as a secondary goal?
Forrester says an HRM solution should detect and measure security behaviors, quantify human risk, initiate risk-based interventions, and build a positive security culture. In that same line, meeting awareness requirements appears as a secondary use case compared with behavior change and culture.
The tension with ISO and PCI is not a regulatory contradiction, but a difference in level. Standards set a floor. Forrester is describing what a program should do if the goal is not only to pass an audit, but to reduce exposure. For a CISO, that changes the main KPI: from completion and attendance to observable behavior and quantified risk.
What fails when a program measures activity instead of behavior?
Hoxhunt notes that many traditional awareness programs focus on activity metrics, such as course completion. Infosec Institute, in contrast, says HRM must rely on real user behavior and integrate real-time data from SIEM, endpoint, and network sources to build a more complete risk score.
Whalemate's reading is that measuring activity helps with administrative audit, but not with operational prioritization. Completing a course does not show whether a person reports phishing, avoids data handling mistakes, or repeats risky behavior. HRM appears precisely when the unit of analysis stops being the course taken and becomes observed behavior.
What is actually measured in Human Risk Management?
The sources converge on a fairly concrete set. Adaptive Security talks about dynamic risk scores per employee, phishing clicks, reports of suspicious activity, and policy tracking. Hoxhunt adds outcome-based metrics such as reduced clicks on real phishing, increased valid reports, and fewer data handling errors. Infosec Institute adds reduced human error, fewer clicks in simulations, and more reports of suspicious emails.
Not all sources use the same taxonomy, but they do follow the same logic. Measurement stops being binary and starts tracking behavior, exposure, and response signals. That makes it possible to see risk by individual, by department, by role, or by stage in the employee lifecycle.
What does technical integration add compared with isolated awareness?
Infosec Institute describes HRM as a discipline that integrates real-time signals from SIEM, endpoint, and network devices. Living Security says HRM unifies behavior, access, identity, and threat exposure data into a single human risk view per individual. Arctic Wolf proposes correlating identity activity, access patterns, and behavior signals to treat human risk as a measurable component of total cyber risk.
Whalemate's reading is that this technical layer turns awareness into an operational security function. If the program stays isolated in an LMS, courses, or generic campaigns, it does not connect with identity, access, or telemetry. When it does connect, the team can decide more precisely where to train, where to harden controls, and where to review permissions or processes.
What does it mean for risk to be continuous and not annual?
PCI DSS 12.6 requires a formal program, ISO/IEC 27002:2022 control 6.3 calls for regular updates tailored to the role, and NIST SP 800-50 recommends periodically evaluating program effectiveness. On the operational side, Adaptive Security proposes behavior-triggered training instead of calendar-driven training, while continuous measurement and improvement cycles focused on the highest-risk users.
The tension is clear. Compliance is often organized around periodic milestones, many of them annual. HRM, by contrast, treats risk as something that changes with threats, habits, roles, and context. For IT and CISOs, that makes it possible to move from date-based campaigns to signal-based interventions.



