Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes.
CSV register of staff ICT security awareness training completions, including training modules, completion dates, assessment scores, and certification status as required by DORA Article 15.
ict-training-recordsDocument describing the institution's ICT security awareness programme, including objectives, target audiences, delivery methods, content modules, and effectiveness metrics.
ict-awareness-programmefs-ict-training-statusDORA-Art15-P1reporting_period_endcompletion_rate_percent{
"properties": {
"average_assessment_score": {
"maximum": 100,
"minimum": 0,
"type": "number"
},
"board_members_trained": {
"type": "boolean"
},
"completion_rate_percent": {
"maximum": 100,
"minimum": 0,
"type": "number"
},
"includes_phishing_simulation": {
"type": "boolean"
},
"modules_available": {
"minimum": 0,
"type": "integer"
},
"reporting_period_end": {
"format": "date",
"type": "string"
},
"role_specific_training_available": {
"type": "boolean"
},
"staff_trained": {
"minimum": 0,
"type": "integer"
},
"total_staff": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"reporting_period_end",
"total_staff",
"staff_trained",
"completion_rate_percent"
],
"type": "object"
}