Abstract : Security standards help to create security policies, but theyare often very descriptive, especially when it comes to security aware-ness. Information systems security awareness is vital to maintain a highlevel of security. SETA programmes (Security Education, Training andAwareness) increase information systems security awareness and playan important role in finding the strategic balance between the preven-tion and response paradigms. By reviewing the literature, we identifyguidelines for designing a SETA programme following a PDCA (Plan DoCheck Adjust) cycle.