{"description":"Security Awareness Training Campaign as a decision-aware workflow covering curriculum, launch, completion tracking, phishing simulation, escalation of non-completers, and effectiveness reporting. It runs on the EXISTING security-awareness training Control item (framework iso-27001 / nist-800-53, domains include awareness_training, control_owner = campaign owner): each cycle is one workflow instance attached to that Control — enriching it, never creating a duplicate control — and the prior cycle's archived instance on the same Control is the baseline for content refresh and simulation trends. No upstream workflow feeds this campaign; each cycle is driven by the campaign charter (trigger, window, audience segments, inclusion/exclusion rules, mandated topics, completion target, and phishing click/report thresholds) supplied at launch, together with the HR headcount and contractor/vendor rosters and the prior campaign report. In scope: running one campaign cycle end-to-end for all in-scope staff, contractors, and third parties with system access, against the campaign charter. Out of scope: routine LMS administration outside a campaign and HR disciplinary action beyond the policy consequence ladder. The named deliverables are the campaign effectiveness report and the indexed evidence archive, presented to the security governance / management review forum. No downstream workflow consumes it; the next cycle and any interim micro-training are scheduled at close (recorded on the campaign record — AssureSwarm has no compliance-calendar surface).","edges":[{"id":"e-prepare-and-launch-assess-campaign-results","source":"prepare-and-launch","target":"assess-campaign-results"},{"id":"e-assess-campaign-results-report-effectiveness","label":"Targets met","source":"assess-campaign-results","target":"report-effectiveness","whenValue":"targets_met"},{"id":"e-assess-campaign-results-verify-full-completion","label":"Escalation needed","source":"assess-campaign-results","target":"verify-full-completion","whenValue":"escalation_needed"},{"id":"e-verify-full-completion-report-effectiveness","source":"verify-full-completion","target":"report-effectiveness"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-TRAIN-01","UC-TRAIN-03","UC-TRAIN-02"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-awareness-training","contentDigest":"sha256:5676177ad081fc5c8472ca1056e07b505068d5a347b8365199c5a60b5bd0944a","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:5676177ad081fc5c8472ca1056e07b505068d5a347b8365199c5a60b5bd0944a","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-security-awareness-training"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-security-awareness-training","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53"],"teams":["it","hr"]},"name":"Security Awareness Training Campaign","nodes":[{"data":{"description":"Approve agent-built rosters, curriculum, and platform configuration, then authorize launch and kickoff communications","instructions":"**Objective** — Produce an approved, launched campaign — a reconciled audience roster, a topic-to-module curriculum matrix, a configured and pilot-tested learning platform, and staged kickoff communications — so that on approval every in-scope person holds an active, dated training assignment.\n\n**Inputs**\n- The campaign charter parameters supplied as the workflow's initial inputs: the trigger for running now (annual cycle, new-hire cohort, customer commitment, or post-incident refresher); the campaign window (start and end dates); the audience definition and segments (all staff, privileged users, developers, finance, customer-facing); the inclusion rules (employees, contractors, and third parties with system access); the documented exclusions each with a stated rationale; the mandated topic list; the completion target percentage; the phishing simulation click and report thresholds; the campaign owner; and escalation contacts.\n- The current HR headcount export and the contractor and vendor personnel lists, uploaded (PBC/external) as roster documents at this step — there is no Personnel item type, so the roster lives as step documents, not items.\n- The identity directory (external system, outside AssureSwarm), for reconciling roster membership against active accounts; the reconciliation extract and mismatch notes are attached as a document on this step.\n- The security awareness training policy and applicable obligations — ISO 27001 A.6.3, NIST 800-53 AT-2 and AT-3, and any contractual or regulatory training commitments — for required frequency, mandated topics, and completion expectations. The obligation mapping already lives on the anchor Control (its `framework` = iso-27001, nist-800-53 and `domains` = awareness_training). The policy itself is an EXISTING **Policy item** — the security awareness training policy (`policy_type: policy`, `framework` = iso-27001, nist-800-53, `domains` = awareness_training, `policy_owner` = the campaign owner) — with the disciplinary consequence ladder as a linked **Policy procedure item** (`policy_type: procedure`); both are linked to the anchor Control, so read the governed text from those items rather than from an upload. The HR confidentiality rules for individual simulation results are defensibly external and stay a document uploaded (PBC/external) at this step.\n- The prior campaign report, read from the report-effectiveness step document on the prior cycle's archived workflow instance on this same Control, as the baseline for content refresh.\n\n**Procedure**\n1. Build the audience roster from the HR export and contractor lists, reconcile it against the identity directory, and flag unresolved mismatches (accounts with no HR record, or personnel with no account). Segment the roster per the charter and set a per-segment due date inside the campaign window.\n2. Draft the curriculum matrix mapping every mandated topic to at least one module per segment, with role-specific modules for privileged users, developers, finance, and customer-facing staff. Refresh outdated content and phishing examples to current tactics, and set the quiz passing threshold per module.\n3. Configure the learning platform: load the module versions, create per-segment assignments with due dates and an automated reminder cadence, then run a pilot with a small test group to verify enrollment, module playback, quiz scoring, and completion capture in reports before any full-scale send.\n4. Draft the launch announcement, the sponsor message, and support contact details, and stage the kickoff send.\n5. Human checkpoint before launch: confirm the roster count reconciles to HR headcount within an explained tolerance, spot-check the topic-to-module mapping against the mandated list, and review pilot results. On approval, open assignments to all segments, send the kickoff communications, resolve access failures, and confirm every in-scope person holds an active assignment.\n\n**Record in AssureSwarm**\n- Step documents: attach the reconciled roster XLSX (with reconciliation notes), the curriculum matrix (XLSX/CSV), the campaign charter, the HR confidentiality rules, and the platform config plus pilot results — all as documents on this step. The training policy and consequence-ladder procedure are existing **Policy items** referenced as inputs, not re-uploaded as documents here.\n- Step fields: roster count, HR headcount, tolerance/variance explanation, per-segment due dates, and pilot outcome.\n- Workflow instance: this campaign run is the workflow instance on the existing security-awareness Control item (its `control_owner` = the campaign owner; the Control's `framework` and `domains` carry the obligation mapping) — record the launch timestamp on this step. No separate campaign item is created; the training policy and consequence-ladder procedure are existing **Policy items** referenced as inputs, not created here.\n\n**Exit criteria** — Roster reconciled to HR headcount within a documented tolerance; curriculum matrix covers every mandated topic per segment; pilot passed; assignments are live for all segments with kickoff communications sent; every in-scope person confirmed to hold an active assignment.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-build` and `/coach-workflow-assign` — build the per-segment training assignments from the reconciled roster and open them across the audience on approval.","label":"Prepare and launch campaign","performedBy":{"primitives":["coach-workflow-build","coach-workflow-assign","coach-item-create","coach-document-upload"]}},"id":"prepare-and-launch"},{"data":{"decisionField":"campaign_outcome","description":"Review interim simulation/intervention evidence through the campaign and classify final reconciled results against charter thresholds.","formData":{"fields":[{"key":"campaign_outcome","label":"Assess campaign results","options":[{"label":"Targets met","value":"targets_met"},{"label":"Escalation needed","value":"escalation_needed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Review interim simulation/intervention evidence through the campaign and classify final reconciled results against charter thresholds.\n\n**Inputs**\n- The launched campaign and the live per-segment assignments from **Prepare and launch campaign** (the reviewed roster and due dates).\n- Daily platform completion reports and quiz results.\n- HR joiner/leaver evidence, for keeping the roster living during the window.\n- Confirmation from the email security team that simulation domains are allowlisted.\n- The prior-cycle simulation baseline (click and report rates) and the HR-agreed confidentiality rules for individual simulation results.\n\n**Procedure**\n_This checkpoint absorbs “Track completion and run simulation”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Track completion and run simulation: Drive the live campaign to interim milestones — daily completion tracking, reminder cadence, and staggered phishing simulation waves — and present a reviewed interim statistics pack so leadership can approve any intervention beyond routine reminders.\n2. Pull completion reports daily, reconcile them to the living roster by adding joiners and removing leavers with HR evidence, and maintain dated completion snapshots by segment against the interim milestones.\n3. Reconcile the platform completion export, module assessment evidence and any existing participant completion records against the living roster. Investigate mismatches as tracking exceptions. Preserve the phishing-reporting knowledge activity in the approved training channel and use its assessment evidence; do not collect a second completion questionnaire.\n4. Send scheduled reminders to incomplete users, copy managers as the deadline nears, track quiz failures and retakes, and flag any segment trending below its milestone.\n5. Run the phishing simulation mechanics: confirm simulation domains are allowlisted with the email security team (so filters do not distort results), schedule scenario sends in staggered waves so early recipients do not tip off the rest, serve the point-of-failure teaching page to anyone who clicks, and capture delivery, open, click, credential-entry, and user-report rates by segment.\n6. Compile the interim statistics pack: completion trend by segment, at-risk segments with interventions already taken, simulation click and report rates against the prior baseline, and the repeat-clicker list handled under the HR-agreed confidentiality rules.\n7. Human checkpoint: review the interim statistics at the agreed cadence, approve interventions beyond routine reminders (such as leadership nudges to lagging segments), confirm simulation results reflect confirmed delivery with no filter interference, and confirm individual simulation results stay confidential per the HR agreement.\n8. Assess campaign results: Resolve, on the final reconciled results, whether the campaign satisfied its charter thresholds or whether non-completers and repeat clickers require the remediation path. The campaign owner or approver named in the charter owns this decision.\n\n**Decision criteria**\n- The agent first assembles the decision basis: the final completion snapshot by segment over the reconciled roster (excluding only exemptions backed by evidence); a metric-by-metric comparison against the charter — overall and per-segment completion versus the target, simulation click and report rates versus thresholds and the prior baseline, quiz pass data, and the repeat-clicker count, with critical segments such as privileged users highlighted; and a drafted assessment with a recommended outcome and an evidence reference for every metric cited.\n- Choose **targets_met** when completion and simulation results satisfy every charter threshold — overall and per-segment completion at or above target, simulation click and report rates within threshold, and no material shortfall in a critical segment such as privileged users.\n- Choose **escalation_needed** when any charter threshold is missed materially — non-completers remain against the completion target, or repeat clickers or a critical-segment shortfall require the remediation path.\n- Judge materiality against the charter thresholds and standards expectations (ISO 27001 A.6.3, NIST 800-53 AT-2/AT-3); a de-minimis shortfall backed by evidenced exemptions is not material.\n\n**Record in AssureSwarm**\n- Step result: retain module, completion date, score, role-specific applicability and phishing-reporting knowledge evidence from the approved training platform and curriculum, with source references feeding the effectiveness archive.\n- Step documents: attach each dated interim statistics pack (XLSX/PDF per snapshot) and the email-security allowlist confirmation to this step.\n- Step fields: current completion by segment, simulation click/report rates versus baseline, at-risk segments, and interventions approved.\n- Repeat-clicker list: keep it as a minimized / pseudonymized document on this step per the HR-agreed confidentiality rules — AssureSwarm documents have no field-level access restriction, so the list is data-minimized rather than held in a restricted-access record.\nSubmit the `campaign_outcome` SELECT field with the chosen branch. Record the decision rationale with evidence references in the step result, and the decision owner or approver in the step's approver record.\n\n**Exit criteria**\n- Completion tracked to the interim milestone with a living-roster reconciliation and every platform/participant record mismatch resolved or tracked as an exception; at least one phishing wave delivered with rates captured by segment and confirmed free of filter interference; interim pack reviewed and any beyond-routine intervention approved; confidentiality of individual results confirmed.\n- The `campaign_outcome` routing selector is submitted and the step result contains a rationale citing evidence; the unused branch is prunable because the branch edge value matches the submitted form value.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-scan` tracks completion against the living roster; `/coach-notify` sends the scheduled reminder and manager-escalation cadence.","kind":"decision","label":"Assess campaign results","performedBy":{"primitives":["coach-workflow-scan","coach-notify","coach-query-data"]}},"id":"assess-campaign-results"},{"data":{"description":"Resolve refusals and deadline/access consequences, revalidate completion and approve named residual exceptions.","instructions":"**Objective** — Resolve refusals and deadline/access consequences, revalidate completion and approve named residual exceptions.\n\n**Inputs**\n- The `escalation_needed` decision from **Assess campaign results** and its rationale.\n- The non-completer and repeat-clicker lists from **Track completion and run simulation**, validated against the reconciled roster and evidenced exemptions.\n- The policy consequence ladder and the HR-agreed rules for when HR involvement and access review are required.\n- The closing position and accepted exceptions from **Escalate and remediate**.\n- The reconciled roster (numerator/denominator basis) and platform source completion data for spot-checks.\n\n**Procedure**\n_This checkpoint absorbs “Escalate and remediate”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Escalate and remediate: Close out non-completers and repeat clickers through the policy consequence ladder and matched remedial training, and produce a closing position that lists who completed, who remains outstanding, and every deadline move — for human handling of refusals, disputes, and exceptions the agent cannot resolve.\n2. Validate the non-completer and repeat-clicker lists against the reconciled roster and exemptions, notify each outstanding user and their manager with a firm new deadline, and apply the policy consequence ladder in order — manager notification, then leadership visibility, then access review for persistent non-completion — keeping dated evidence of every escalation touch.\n3. Schedule and assign remedial training matched to failure mode: the core curriculum for non-completers and focused phishing-recognition modules for repeat clickers, confirming each assignment is visible to its user.\n4. Track remedial progress daily, send deadline reminders, arrange follow-up sessions for repeated quiz failures, and compile the closing position listing who completed, who remains outstanding, and every requested deadline move.\n5. Human checkpoint: handle what the agent cannot resolve — refusals, disputes, and exception requests; approve or reject deadline extensions; decide when HR involvement is required by policy; authorize any access-review consequence; and accept residual exceptions by name before this branch converges.\n6. Verify full completion: Recompute and sign off the verified completion position over the full in-scope population after remediation, with every residual exception classified and dispositioned, so the numbers are ready for management reporting.\n7. Recompute the completion rate over the full in-scope population after remediation, tying the numerator and denominator to the reconciled roster with no silent exclusions.\n8. Classify every roster member as completed, exempted with evidence, or proposed for risk acceptance, and confirm repeat clickers finished their remedial modules.\n9. Spot-check a sample of completion records back to platform source data to confirm the recomputed rate is trustworthy, and draft the verification memo listing the final completion rate and each residual exception with its proposed disposition.\n10. Human checkpoint: review the verification memo, approve or reject each residual exception and risk acceptance by name, and sign the verified completion position.\n\n**Record in AssureSwarm**\n- Step documents: attach the escalation log (dated touches per user, XLSX) and the closing-position document (DOCX/PDF) to this step; list each remedial assignment (user, module, deadline) inside these documents — there is no Personnel item to link per-person assignments to.\n- Step fields: outstanding count, access reviews authorized, exceptions accepted (by name), and deadline extensions granted. Residual exceptions accepted here stay named in the closing position rather than becoming separate items — there is no per-person record type to hold them.\n- Step document: attach the verification memo (DOCX/PDF — final rate, per-member classification, spot-check results) to this step; individual per-person risk acceptances stay named in the memo (there is no Personnel item to link them to).\n- Step fields: verified completion rate, count completed/exempted/risk-accepted, and sign-off owner.\n- Item field update: where remediation leaves a material residual human-risk shift, update the existing human-risk / phishing Risk item — `Risk.residual_rating`, and `Risk.treatment: accept` where the residual is formally risk-accepted.\n\n**Exit criteria**\n- Every non-completer and repeat clicker has an evidenced escalation trail and a matched remedial assignment; deadline extensions and access-review consequences are decided and recorded; residual exceptions are accepted by name; the closing position is complete.\n- The completion rate is recomputed over the full population tied to the reconciled roster; every member is classified; the sample spot-check is documented; each residual exception and risk acceptance is approved by name; the verified position is signed.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` issues the escalation notices to outstanding users and their managers with the firm new deadline.","label":"Verify full completion","performedBy":{"primitives":["coach-notify","coach-workflow-assign","coach-item-update","coach-query-data","coach-document-upload"]}},"id":"verify-full-completion"},{"data":{"description":"Approve the agent-drafted effectiveness report and evidence archive and record management direction, next-cycle scheduling, and policy updates; that approval closes the campaign with every open item transferred to a live owner","instructions":"**Objective** — Produce and present the approved campaign effectiveness report and a complete, indexed evidence archive to the security governance or management review forum, capture management decisions and directed actions with owners and due dates, and transfer every open item to a live owner — the approval recorded here closes the campaign with the audit trail preserved.\n\n**Inputs**\n- On the targets-met path: the submitted assessment from **Assess campaign results** (final metrics versus charter).\n- On the escalation path: the signed verified completion position from **Verify full completion** (post-remediation rate, exceptions, risk acceptances) plus the escalation log.\n- The prior-cycle report (for comparison), the charter, the roster reconciliation records, the curriculum matrix and content version identifiers, dated completion exports, and simulation data.\n- The training-policy and consequence-ladder procedure **Policy items**, for any gap-driven updates, and the policy's required training frequency (the test the next-cycle schedule must meet).\n\n**Procedure**\n_Items 1–4 are agent-run and items 6–8 close the workflow (folded from the former \"Close and archive\" step); the human moment is item 5, and the approval recorded there is the closure — there is no separate confirmation._\n1. Draft the effectiveness report: completion rate versus target, simulation click and report trends against baseline, segments of concern, escalation and remediation outcomes where that path ran, quiz analytics, prior-cycle comparisons, and recommendations for the next cycle (content changes, frequency, or targeted micro-training).\n2. Assemble the evidence archive with a consistent index: the charter, roster reconciliation records, the curriculum matrix, content version identifiers, dated immutable completion exports, simulation data with personal data minimized per privacy rules, the escalation log if used, and the verified completion sign-off.\n3. Stage the package in the evidence repository with the retention schedule applied and access limited to authorized reviewers, and record the next-cycle window it is filed against on this step (AssureSwarm has no compliance-calendar surface).\n4. Put the closing proposals on the table for the same review: lessons learned (what raised completion, which simulation scenarios were most effective), the proposed next campaign window plus any interim micro-training or simulation waves, and any gap-driven update to the training-policy or consequence-ladder **Policy items** the campaign exposed — drafted as a new version on the existing Policy item, never as a fresh standalone document.\n5. Human checkpoint: verify every reported metric ties to verified data, approve the report, present it at the governance or management review forum, capture management decisions and directed actions with owners and due dates, and in the same approval accept the next-cycle schedule against the policy frequency and dispose of the raised procedure updates. The report must satisfy ISO 27001 management review and NIST AT-2 and AT-3 effectiveness expectations; this approval authorizes closure.\n6. Log every directed action from the management review in the action tracking system with an owner and due date, and confirm nothing remains owned by the closed campaign.\n7. Apply the approved outcomes: bump the version on any updated Policy item and record the agreed next campaign window and interim training on the campaign record.\n8. Mark the campaign record closed, link the archived evidence package, and send the closure note to stakeholders, confirming every open item has transferred to a live owner.\n\n**Record in AssureSwarm**\n- Step documents: attach the named campaign effectiveness report (DOCX/PDF), the indexed evidence archive (ZIP/PDF), and the lessons-learned note to this step.\n- Step fields: reported completion rate, simulation trend, management decisions, directed actions (owner + due date each), and the next-cycle window with any interim micro-training (AssureSwarm has no compliance-calendar surface).\n- Item create + relationship: create one Issue item per directed action (`issue_type: opportunity` or `observation`, `source: management_identified`, `issue_owner`, `target_remediation_date`), each linked to the anchor Control and to this workflow instance — the action-tracker convention.\n- Item field update: where the campaign exposed gaps, update the existing training-policy / consequence-ladder **Policy items** in place — bump `Policy.version` (and refresh `Policy.next_review_date`) — rather than drafting a separate policy/procedure update document.\n- Workflow instance: mark this campaign run (the workflow instance on the anchor security-awareness Control) closed/archived and link the archived evidence package as a document. The instance IS the campaign record — there is no separate campaign item to close — and all its step documents and forms are the durable audit trail; retention and access enforcement beyond AssureSwarm live in the external evidence repository, with the AssureSwarm copy as the record.\n\n**Exit criteria** — Every reported metric ties to verified data; the report is approved and presented; management decisions and directed actions are captured and logged with live owners and due dates; the next cycle and any interim training are scheduled against the policy frequency; procedure updates are approved or dispositioned; the evidence archive is staged with retention and access controls applied and linked to the closed campaign record with the audit trail preserved.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` assembles the indexed effectiveness report and evidence archive from the campaign records; `/coach-notify` sends the closure note to stakeholders.","label":"Report effectiveness","performedBy":{"primitives":["coach-render-package","coach-dashboard-create","coach-document-upload","coach-item-update","coach-item-create","coach-notify"]}},"id":"report-effectiveness"}],"sourceTemplateId":"workflow-library:controls-security-awareness-training"}
