Training
PURPOSE
Health Informatics Centre (HIC) maintains a structured approach to information security training and awareness to ensure all staff and relevant third parties are competent for their roles and understand their responsibilities under the information Security Management System (ISMS). Mandatory training includes internal SOPs, all-staff ISMS awareness sessions, University of Dundee Information Security Awareness Training (ISAT), and Medical Research Council (MRC) General Data Protection Regulation (GDPR) training (with a three-year cycle).
Role-specific training needs are identified and agreed during annual appraisals and ongoing 1:1 discussions, with outcomes recorded in appraisal documentation.
Completion of training is tracked using project management system tickets, with supporting evidence, including recordings, certificates, quizzes, and ISAT reports. The training plan and associated matrix are reviewed annually as part of ISMS management oversight to ensure currency, effectiveness, and alignment with ISO 27001 requirements.
RESPONSIBILITIES
ROLE | RESPONSIBILITY |
All Staff, Clients and Third Parties |
|
Line Manager |
|
Operational Team |
|
HIC Leadership Team |
|
DEFINITIONS
ISMS: Information Security Management System which covers the full range of HIC ISO 27001 documentation covering HIC's governance and data security processes.
SCOPE
All HIC staff, clients and relevant third parties.
Covers all ISMS-related training including SOPs, awareness, external mandatory training, and role-specific development.
TRAINING MATRIX
Category | Description | Frequency | Delivery | Who | Responsible | Evidence |
|---|---|---|---|---|---|---|
Core Training - ISMS Awareness | Standard Operating Procedures and Policy awareness | Onboarding | Self learning | New staff | Operational Team | Onboarding checklist |
Role Based Training | Additional training identified during appraisals and 1:1s | As required | Recorded/Live/External | All staff | Line Manager | Appraisal documentation |
Refresher & Role Specific Training- MRC GDPR/ONS (roles specific training) | Data protection and GDPR compliance | Every 3 years | External LMS | Staff & Clients | Operational Team | Certificate |
Refresher Training- Information Security & Governance | Overview of ISMS, responsibilities, policies | Monthly | Live or recorded | All staff | Operational Team | Quiz completion, Power BI snapshot through ISMS Dashboard |
Refresher Training - ISAT | University of Dundee Information Security Awareness Training | Annual | External LMS | All staff | University of Dundee / Line Manager responsible to ensure completion | Completion Report, Power BI Snapshot |
Retraining | Additional training identified from incidents, BCP/Incident testing | As required | Recorded/Live/External/Self learning | All staff | Line Manager | Actions in the project management system from incidents, BCP/incident testing |
PROCEDURE
Identify Requirements
Use the training schedule and appraisal outcomes to define mandatory and role-specific training.
Assign & Schedule
Create project management system tasks for all training events, specifying deadlines and responsible staff.
Deliver Training
Provide access to recorded modules, schedule live sessions, and ensure external training is accessible.
Assess Competence
Confirm completion via quizzes, certificates, attendance, and ISAT reports.
Store Evidence
Retain evidence in the project management system; capture ISAT Power BI snapshots for audit purposes.
Review & Improve
Review training completion and effectiveness annually.
Update the training plan and matrix based on audit findings, incidents, and organisational changes.
APPLICABLE REFERENCES
Information Security Policy
How To Co-ordinate Information Security Refresher Training
DOCUMENT CONTROLS
Process Manager | Point of Contact |
|---|---|
Jenny Johnston |
Revision Number | Revision Date | Revision Made | Revision By | Revision Category | Approved By | Effective Date |
|---|---|---|---|---|---|---|
1.0 | Feb 20, 2026 |
| Jenny Johnston | Material | Leadership Team | Feb 24, 2026 |
Copyright Health Informatics Centre. All rights reserved. May not be reproduced without permission. All hard copies should be checked against the current electronic version within current versioning system prior to use and destroyed promptly thereafter. All hard copies are considered Uncontrolled documents.