5.4.1 Assess and evaluate the IT security awareness and training Program for compliance with corporate policies, regulations, and laws ( statutes ), and measure program and employee performance against objectives.
5.4.2 Review IT security awareness and training program materials and recommend improvements.
5.4.3 Assess the awareness and training program to ensure that it meets not only the organization’s stakeholder needs, but that it is effective and covers current IT security issues and legal requirements.