Why it matters
Most incidents start with a person, not a system — phishing, weak passwords, misdirected data.
How a self-led small team implements it
Annual training plus a short session at onboarding is proportionate for a small team; you don't need a formal LMS.
What auditors expect to see
Training records, completion dates.
Track A.6.3 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS