Training

Training

PURPOSE

Health Informatics Centre (HIC) maintains a structured approach to information security training and awareness to ensure all staff and relevant third parties are competent for their roles and understand their responsibilities under the information Security Management System (ISMS). Mandatory training includes internal SOPs, all-staff ISMS awareness sessions, University of Dundee Information Security Awareness Training (ISAT), and Medical Research Council (MRC) General Data Protection Regulation (GDPR) training (with a three-year cycle).

Role-specific training needs are identified and agreed during annual appraisals and ongoing 1:1 discussions, with outcomes recorded in appraisal documentation.

Completion of training is tracked using project management system tickets, with supporting evidence, including recordings, certificates, quizzes, and ISAT reports. The training plan and associated matrix are reviewed annually as part of ISMS management oversight to ensure currency, effectiveness, and alignment with ISO 27001 requirements.

RESPONSIBILITIES

ROLE

RESPONSIBILITY

All Staff, Clients and Third Parties

  • Complete assigned training

Line Manager

  • Hold team members accountable for completion of training

Operational Team

  • Identify requirements, assign and schedule training, deliver training, maintain training records, monitor, review and improve training.

HIC Leadership Team

  • Demonstrate commitment to information security training and awareness

  • Ensure adequate resources are allocated for training activities

DEFINITIONS

  • ISMS: Information Security Management System which covers the full range of HIC ISO 27001 documentation covering HIC's governance and data security processes.

SCOPE

  • All HIC staff, clients and relevant third parties.

  • Covers all ISMS-related training including SOPs, awareness, external mandatory training, and role-specific development.

TRAINING MATRIX

Category

Description

Frequency

Delivery

Who

Responsible

Evidence

Category

Description

Frequency

Delivery

Who

Responsible

Evidence

Core Training - ISMS Awareness

Standard Operating Procedures and Policy awareness

Onboarding

Self learning

New staff

Operational Team

Onboarding checklist

Role Based Training

Additional training identified during appraisals and 1:1s

As required

Recorded/Live/External

All staff

Line Manager

Appraisal documentation

Refresher & Role Specific Training- MRC GDPR/ONS (roles specific training)

Data protection and GDPR compliance

Every 3 years

External LMS

Staff & Clients

Operational Team

Certificate

Refresher Training- Information Security & Governance

Overview of ISMS, responsibilities, policies

Monthly

Live or recorded

All staff

Operational Team

Quiz completion, Power BI snapshot through ISMS Dashboard

Refresher Training - ISAT

University of Dundee Information Security Awareness Training

Annual

External LMS

All staff

University of Dundee / Line Manager responsible to ensure completion

Completion Report, Power BI Snapshot

Retraining

Additional training identified from incidents, BCP/Incident testing

As required

Recorded/Live/External/Self learning

All staff

Line Manager

Actions in the project management system from incidents, BCP/incident testing

PROCEDURE

  1. Identify Requirements

    • Use the training schedule and appraisal outcomes to define mandatory and role-specific training.

  2. Assign & Schedule

    • Create project management system tasks for all training events, specifying deadlines and responsible staff.

  3. Deliver Training

    • Provide access to recorded modules, schedule live sessions, and ensure external training is accessible.

  4. Assess Competence

    • Confirm completion via quizzes, certificates, attendance, and ISAT reports.

  5. Store Evidence

    • Retain evidence in the project management system; capture ISAT Power BI snapshots for audit purposes.

  6. Review & Improve

    • Review training completion and effectiveness annually.

    • Update the training plan and matrix based on audit findings, incidents, and organisational changes.

APPLICABLE REFERENCES

  • Information Security Policy

  • How To Co-ordinate Information Security Refresher Training

DOCUMENT CONTROLS

Process Manager

Point of Contact

Process Manager

Point of Contact

Jenny Johnston

hic-ops@dundee.ac.uk

Revision Number

Revision Date

Revision Made

Revision By

Revision Category

Approved By

Effective Date

Revision Number

Revision Date

Revision Made

Revision By

Revision Category

Approved By

Effective Date

1.0

Feb 20, 2026

  • New standard operating procedure.

Jenny Johnston

Material

Leadership Team

Feb 24, 2026

Copyright Health Informatics Centre. All rights reserved. May not be reproduced without permission. All hard copies should be checked against the current electronic version within current versioning system prior to use and destroyed promptly thereafter. All hard copies are considered Uncontrolled documents.