Purpose: This research aimed to propose a conceptual framework for the evaluation and education of information security awareness. For that, three levels of information security awareness including knowledge, attitudes and behavior were articulated.Methodology: This survey was carried out via employing 7 components. Various critical factors affecting users’ awareness of information security have been identified including independent variables such as gender, education, IT skills, work experiences, occupation, academic discipline and job credit.Findings: The importance of components and their priority for education were clarified.Findings also indicated that four out of 7 components (including IT skills, occupation, academic discipline, and job credit) have a significant relationship with the richness of awareness on the information security.Conclusion: The importance of information security in organizations was emphasized, and it was concluded that it is necessary to account on occupation, academic discipline and job credit of employees toward a credible guarantee for the effectiveness of training courses.Priorities have been drawn in the proposed framework.