Why this instruction is required
NKDL, Regulation No. 397, and practical proof for management.
The employee understands that cybersecurity is part of their work responsibility, not a private IT department topic.
Threat
After an incident, companies lose time and evidence if they cannot show what employees learned and when.
What to know
- Regulation No. 397 requires initial instruction within one month after a user account is granted and refresher instruction at least once per calendar year.
- The company must keep materials current, keep training records, and assess knowledge.
- A Vairogs report is evidence of record keeping and knowledge assessment, not a state certificate.
- This is a cybersecurity course. It does not replace occupational safety instruction under Regulation No. 749.
Actions
- Complete the course and test through your private work-email link.
- After training, keep the reporting channel and responsible manager contact available.
- If the responsibility is unclear, ask who is responsible for cybersecurity management in the company.
Workplace scenario
Practice scenario
A new colleague receives access to email, client files, and company chats. The manager asks what exactly must be proven if an audit or incident happens later.
Think before the test
- On which date was access granted, and when must instruction be completed?
- Where is the evidence of the course, test, and result kept?
- Who reviews whether the material still matches current threats?
For the manager and responsible person
The key management evidence is a clear record: invited, opened, completed, score, and date.
- Assign responsibility for invites, deadlines, and annual refreshers.
- Add the company incident-reporting channel to the training message.
- Keep the PDF/CSV report with internal cybersecurity documents.