Overview

LowerPlane’s training module helps you build and maintain a security awareness program that satisfies compliance requirements across ISO 27001, SOC 2, HIPAA, and PCI-DSS. Create training courses, assign them to employees or groups, track completion rates, and run phishing simulation campaigns to test employee readiness.

Training Courses

Training courses are the building blocks of your security awareness program. Each course contains educational content that employees must complete.

Course Properties

FieldDescription
TitleName of the training course
DescriptionSummary of what the course covers
TypeCategory of training (see types below)
DurationEstimated completion time in minutes
Pass ScoreMinimum score required to pass (percentage)
MandatoryWhether the course is required for all assigned employees
FrequencyHow often the course must be retaken: once, monthly, quarterly, or annually
Content URLLink to the training content (video, document, or external LMS)
StatusActive, Draft, Archived, or Scheduled

Course Types

Security Awareness

General security hygiene: password management, social engineering, data handling, and incident reporting.

Compliance

Framework-specific training: HIPAA privacy rules, GDPR data subject rights, PCI-DSS cardholder data handling.

Technical

Technical security training: secure coding practices, infrastructure security, vulnerability management.

Phishing Simulation

Simulated phishing exercises that test employee ability to identify and report suspicious emails.

Policy Review

Required reading and acknowledgment of organizational security policies.

Custom

Organization-specific training content created for your particular needs.

Creating a Course

1

Navigate to Training

Go to Personnel > Training and select the Courses tab.
2

Click Create Course

Click the Create Course button and fill in the course details.
3

Configure Content

Set the content URL, duration, pass score, and frequency. Mark the course as mandatory if all assigned employees must complete it.
4

Publish

Set the status to Active to make the course available for assignments.

Training Assignments

Assignments link courses to employees. When you assign a course, each targeted employee receives a training task with a due date.

Assigning Training

You can assign courses to:
  • Individual employees — select specific people from the directory
  • Groups — assign to an entire security group, and all members receive the assignment
  • All employees — assign to the entire organization
Use group-based assignments for role-specific training. For example, assign “Secure Coding” training to the Engineering group and “HIPAA Privacy” training to the Healthcare Operations group.

Assignment Statuses

StatusDescription
Not StartedThe employee has not yet begun the course
In ProgressThe employee has started but not completed the course
CompletedThe employee has finished the course and met the pass score
OverdueThe course deadline has passed without completion
FailedThe employee completed the course but did not meet the pass score

Completion Tracking

The training module provides detailed completion metrics:
MetricDescription
Total EnrolledNumber of employees assigned to the course
CompletedNumber of employees who have finished the course
In ProgressNumber of employees currently working on the course
OverdueNumber of employees past their deadline
Pass RatePercentage of completions that met the pass score

Course Detail View

Click on a course to see the full detail page, which includes:
  • Course metadata and configuration
  • Assignment list with individual completion status
  • Completion statistics and trends
  • Options to send reminders to overdue employees

Phishing Simulation Campaigns

Phishing campaigns test your employees’ ability to identify and report suspicious emails. These campaigns provide measurable data on your organization’s susceptibility to social engineering attacks.

Creating a Phishing Campaign

1

Navigate to Phishing

Go to Personnel > Training and select the Phishing Campaigns tab.
2

Create Campaign

Click Create Campaign and configure:
FieldDescription
NameCampaign name for internal reference
DescriptionPurpose and goals of the campaign
Email TemplateThe phishing email template to use
Template TypeCategory of phishing attempt
DifficultyEasy, Medium, or Hard
Target TypeWho receives the simulated phishing email
Target GroupsSpecific groups to target
Launch DateWhen to send the phishing emails
End DateWhen the campaign concludes
3

Launch

Launch the campaign to send simulated phishing emails to the targeted employees.

Campaign Statuses

StatusDescription
DraftCampaign created but not yet scheduled
ScheduledCampaign is set to launch at a future date
ActivePhishing emails have been sent and the campaign is collecting results
CompletedCampaign has ended and results are finalized
PausedCampaign temporarily stopped

Campaign Metrics

Phishing campaigns track key indicators:
  • Emails Sent — total simulated phishing emails delivered
  • Emails Opened — how many employees opened the email
  • Links Clicked — how many employees clicked the phishing link
  • Credentials Submitted — how many employees entered credentials on the fake page
  • Reported — how many employees correctly reported the email as suspicious
Phishing simulation results can be sensitive. Ensure results are used for training and improvement, not punitive action. Frame campaigns as learning opportunities to encourage a culture of security awareness.

Compliance Mapping

Training programs satisfy controls across frameworks:
FrameworkControlRequirement
ISO 27001A.7.2.2Information security awareness, education, and training
SOC 2CC1.4Security awareness training
HIPAA164.308(a)(5)Security awareness and training program
PCI-DSS12.6Security awareness program
GDPRArticle 39Data protection awareness

Reminders and Notifications

  • Assignment notifications — employees receive an email when a new training course is assigned
  • Overdue reminders — send reminder emails to employees who have passed their training deadline
  • Campaign notifications — managers are notified when phishing campaign results are available

Best Practices

  • Make security awareness training mandatory for all employees, with annual recertification
  • Use phishing simulations quarterly to maintain awareness and measure improvement
  • Tailor training to roles — technical staff need different content than non-technical employees
  • Track completion rates as a KPI and report them to leadership
  • Follow up on phishing failures with targeted training for employees who clicked or submitted credentials
  • Refresh content annually to address new threats and attack techniques