Could you ask one of your ISO 27001 experts for their recommendations on Security Awareness and Training.
1 - How do I get this going in my company?
2 - What will the auditor be looking for in this requirement?
The first thing you need to do is identify which gaps of incompetence you have (i.e., which knowledge, or skills your employees need to have). Some examples are:
Use of passwords
Software installation and patching
Performing of internal audit
Second, you need to define the method to be applied: training sessions, workshops, newsletters? What will work best for your company? On which frequency to perform them (e.g., weekly, monthly, annually?)
After that, you need to evaluate if these gaps can be fulfilled by internal personnel, or you will need external support.
Once you have these answers, you can start defining your training and awareness plan.
These articles will provide you a further explanation about awareness: