TechKnowSurge
NIST NICE K0638 NIST CSF GV.OC-03 NIST 800-53 AT-4 ISC2 CISSP 1.12 NIST NICE S0379 CompTIA Security+ 5.6 NIST 800-53 PM-6
VideoSecurityFree

Monitoring and Reporting

Monitoring and reporting are essential components of security awareness programs, supporting internal oversight, regulatory compliance, and client-facing accountability. Reports typically cover training participation, phishing campaign results, policy acknowledgments, and meeting attendance.

Complete this video to capture a CTF flag worth 1 point.

About this video

Monitoring and reporting are fundamental to running an effective security awareness program, and organizations pursue them for a range of reasons. In some cases, the driver is internal — leadership wants visibility into how well security practices are being adopted across the workforce. In others, the requirement comes from external sources such as laws, industry regulations, or contractual obligations with clients or partners who need assurance that risk is being actively managed. The scope of security awareness reporting extends well beyond tracking who completed a training course. Comprehensive reports typically document participation in phishing simulation campaigns, acknowledgment of organizational policies and employee handbooks, and attendance at security-related meetings. Together, these data points give organizations and their stakeholders a full picture of security engagement and help demonstrate that appropriate controls are in place. This documentation becomes especially valuable during audits, client reviews, or regulatory assessments where evidence of a functioning security awareness program is required.

What you'll learn

What's covered

Monitoring and Reporting

Aligned to

NIST NICE
K0638 Knowledge of security awareness programs
S0379 Skill in verifying participation in a security awareness program
NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
NIST 800-53
AT-4 Training Records
PM-6 Measures of Performance
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
CompTIA Security+
5.6 Given a scenario, implement security awareness practices.

Key terms

Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Security Awareness Monitoring and Reporting
The process of tracking, measuring, and communicating employee participation in security training, phishing simulations, and policy acknowledgments to meet internal, regulatory, or business requirements.
Regulatory Compliance
The adherence to laws, government regulations, and industry standards that mandate how an organization must protect data and systems. Failure to meet regulatory requirements can result in fines, legal liability, and reputational damage.
Policy Acknowledgment
The recorded confirmation that an employee has read, understood, and accepted an organizational security policy or handbook.

Topics

Security Awareness Compliance Reporting Phishing Simulation Training Metrics Policy Acknowledgment Security Program Management

Transcript

One of the important parts of this training, and also security awareness, is monitoring and reporting. It's something that I've had to pull together for either internal reports or even external reports.

There are many different reasons why we might have to do monitoring and reporting. One of them might be that it's just a requirement for us to do it internally — it's a good thing that we do. But it also could be that we have to comply with laws and regulations out there that require us to do this monitoring and reporting. In many business relationships we might have this requirement. In fact, I've had to turn over reports to clients before, that they asked for these annual reports to make sure that we were doing what we need to do to keep our risk level down.

What the reports cover

The reports usually go over who participated, and it wasn't just for training, but it was for other aspects as well. For instance, the phishing campaigns that we would have. We'd also report who signed the policies and accepted the policies or the employee handbooks, who was part of certain meetings. So there are different aspects that we reported on.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →