Security Training

Owner: Security. Review cadence: annual or on material change.

This document defines what security training MeterBox requires, when it runs, and how completion is recorded. The cadence commits referenced here are the same ones called out in the information security policy § 10. This doc is the curriculum + records detail behind that one-line commitment.

1 — Who + when

2 — Curriculum overview

Both the on-hire and annual modules cover the same areas; the on-hire module is longer (≈ 90 minutes) because it includes orientation, and the annual refresher is shorter (≈ 30 minutes) because it focuses on what's changed and recent incidents.

Area Why it's in the module
1. InfoSec policy walkthrough Roles, classification, acceptable use, access control.
2. Phishing + social engineering recognition The single highest-frequency external attack vector.
3. Acceptable use of AI / LLM tooling Restricted data must never leave the cluster; Confidential data only goes to reviewed LLMs with no-training clauses.
4. Data classification + handling The four-tier model (Public / Internal / Confidential / Restricted) from InfoSec § 3.
5. Incident reporting + the IR plan summary What to report, where, and how the IR plan escalates from there.
6. Secret management basics No plaintext secrets anywhere outside the cluster's secret store or the company password manager. Rotation cadence per operator runbook § 1.5.
7. Code of Conduct refresher Expected behavior, reporting channel, anti-retaliation.

3 — On-hire module

Run by the Security lead (or a designate) in a 90-minute session, in person or video, within 14 days of the new hire's start date. Covers all seven areas in § 2 with examples specific to the new hire's role.

Required artifacts produced at the end of the session:

4 — Annual refresher

Run by the Security lead in a 30-minute session each fiscal year. Format is async-friendly (recorded session + a short knowledge check) provided the recorded session is current within the fiscal year.

Each annual refresher highlights:

5 — Completion records

6 — Exceptions

7 — Review + version control

Last reviewed: 2026-06-04

Related docs