For CISOs, IT, and compliance teams in LATAM, a cybersecurity awareness training program is not validated by the number of courses, but by continuous evidence of knowledge, simulation, and response. ISO calls for a formal program maintained for all staff, NIST and SANS make it measurable through exercises, and Verizon shows that human risk materializes in seconds and no longer comes only by email, but also by voice and mobile.
Taken together, the regulatory frameworks and operational measurements say something that no single source makes as clear on its own. The comparison shows that the question is not whether training is worthwhile, but which specific control can prove effectiveness, prioritize risk, and withstand audit.
| Source | Framework | Scope | Core metric | Main vector | Cadence / time | Operational use |
|---|---|---|---|---|---|---|
| ISO/IEC 27001:2022 Annex A 6.3 | ISO/IEC 27001:2022 | "for all employees" | Not specified | Not specified | "planned, established, implemented and maintained", "updated regularly" | Formal control for awareness, education and training |
| ISO 27001 Clause 7.3 Awareness | ISO/IEC 27001:2022 | "all persons doing work under the organization's control", "everyone in scope" | Not specified | Not specified | Continuous awareness of policy, role, and implications | Sustain ISMS effectiveness and show understanding |
| NIST SP 800-50r1 | NIST SP 800-50r1 | "enterprise-wide" program | Not specified | Social engineering, phishing, spear phishing, vishing, smishing | "phishing exercise" and hands-on exercises | Measure whether users detect the attempt or click |
| SANS phishing benchmarking | SANS Institute | Organizational program | "undesired action rate (click rate)" and "report rate" | Not specified | Recurrent simulations | Assess vulnerability and reporting ability |
| Verizon DBIR 2024 | Verizon DBIR 2024 | End users exposed to phishing email | Click time / reaction time | Email phishing | "21 seconds", "less than 60 seconds" | Shows the risk happens too fast |
| Verizon DBIR 2026 | Verizon DBIR 2026 | Breaches with a human element | "Human element was present in 62% of breaches", "Social Engineering" 16% | Mobile-centric social engineering, fake text messages and voice calls | 40% higher success rate than email phishing | Forces multichannel awareness measurement |
When ISO, NIST, SANS, and Verizon are viewed together, the central tension becomes clear. ISO requires a sustained and auditable program, while Verizon shows that the user decision happens within a window of seconds. That shifts the problem from "training" to "measuring behavior under pressure."
Does ISO call for a program or a one-off course?
ISO/IEC 27001:2022 does not describe a one-time action. Control Annex A 6.3 requires that the information security awareness, education and training program be "planned, established, implemented and maintained" and updated regularly. The same logic is reinforced by Clause 7.3 Awareness, which applies to "all persons doing work under the organization's control" and, in practical guidance, to "everyone in scope".
Whalemate's reading is that this turns awareness into a cross-functional ISMS control, not an HR campaign or an annual course done to check a box. If the standard asks for evidence of understanding, contribution, and consequences of nonconformity, the program needs auditable traceability. Without that, there is training, but there is no control.
What does NIST measure when it talks about phishing awareness?
NIST SP 800-50r1 recommends a "phishing exercise to promote awareness of social engineering attacks" and places phishing, spear phishing, vishing, and smishing among the core topics of an enterprise-wide program. The focus is not the lecture, but the practical exercise and whether the user detects the attempt or clicks.
Whalemate's reading is that NIST brings awareness down to observable behavior. That matters because it shifts the model from attendance to performance. For a CISO, the question stops being who completed the course and becomes who recognizes, reports, or falls for a realistic attempt.
Why does SANS not stop at click rate?
SANS proposes two core metrics for phishing simulations, "undesired action rate (click rate)" and "report rate." With that, the program measures not only exposure to deception, but also the user's reporting ability and defensive response.
Whalemate's reading is that this is the difference between training and managing human risk. If you only look at clicks, you know who made a mistake. If you add reports, you know who helps contain the threat. For compliance and IT, that second signal is the one that best translates into evidence of operational maturity.
