ASUME

Trust Center

Training

Security-awareness expectations for personnel. A standalone training curriculum is still being formalised and is not independently verified.

Security awareness programme

ASUME is building a security-awareness programme that starts at onboarding and continues while people have access to material systems. Personnel with access to material systems or information already receive security guidance, instructions, or awareness appropriate to their responsibilities, as described in Security Measures.

Interactive workshops, simulated phishing exercises, and a published continuous curriculum are still being formalized and are not independently verified.

Security onboarding

ASUME is formalizing security onboarding so that new personnel receive guidance before they receive access to material systems. Current onboarding and offboarding access processes are described in Security Measures.

A standalone onboarding curriculum covering physical security, data handling, and current attack vectors is still being built out and is not independently verified.

Information security and risk training

Personnel with access to material systems or information receive security guidance appropriate to their responsibilities, as described in Security Measures. Topics are intended to include data handling, access expectations, and information-security practices relevant to the Service.

A mandatory recurring course for every employee, with content refreshed against the latest attack vectors, is still being formalized and is not independently verified.

Phishing training

A published phishing-training programme — including periodic simulated phishing assessments and up-to-date guidance on recognizing phishing — is a roadmap item.

Listing it here is not a representation that simulated phishing campaigns are running today.