Exemplar Global Certified Courses from USD 99. Ending Soon!

Clause 7 of ISO 27001: Resources, Competence, Awareness and Communication

AW

Team @ Audit Workshop

13 min read
Clause 7 of ISO 27001: Resources, Competence, Awareness and Communication

What Clause 7 Is Actually About

Clause 7 of ISO 27001 sits under the heading Support, and it covers four things that every functioning information security management system depends on: resources, competence, awareness, and communication. There is also a fifth element, documented information, which we cover in a separate article focused on Clause 7.5.

On paper, these requirements look straightforward. In practice, they are where a surprising number of organisations fall short during certification audits. Not because the concepts are difficult, but because the evidence is thin. Organisations often have the right intentions but cannot demonstrate them in a way that satisfies an auditor.

This article walks through each sub-clause in plain terms, explains what auditors look for, and gives you practical guidance on getting it right, whether you are implementing an ISMS for the first time, preparing for a certification audit, or conducting internal audits against ISO 27001.

Clause 7.1: Resources

The standard requires that the organisation determine and provide the resources needed to establish, implement, maintain, and continually improve the ISMS. That is the entire text of Clause 7.1. It is brief, but the implications are significant.

Resources in this context include people, technology, infrastructure, budget, and time. The standard does not prescribe how many people you need or what tools you must use. What it does require is that you have thought about what is needed and made a deliberate decision to provide it.

What auditors look for under Clause 7.1

Auditors will not simply accept a statement that resources have been provided. They will look for evidence that resource decisions are connected to the ISMS. Common lines of enquiry include:

  • Is there a dedicated information security function, or has responsibility been assigned to a named person alongside other duties?
  • Has the organisation budgeted for security tools, training, and remediation activities?
  • When information security risks were identified and treatment plans were created, were resources actually allocated to implement the controls?
  • Are resource constraints documented anywhere, and has management acknowledged them?

The most common issue auditors find here is a gap between the risk treatment plan and the reality on the ground. An organisation might have a beautifully documented Statement of Applicability with 93 controls selected, but when you ask who is responsible for implementing them and what budget has been set aside, the answers become vague. That gap is where a nonconformity lives.

If you are preparing for an audit, make sure you can trace a line from your risk treatment decisions to actual resource commitments. Meeting minutes, budget approvals, and job descriptions all serve as useful evidence.

Clause 7.2: Competence

Clause 7.2 requires the organisation to determine the competence needed by persons whose work affects information security performance, ensure those persons are competent on the basis of education, training, or experience, take action where gaps exist, and retain documented information as evidence of competence.

This is one of the most audited sub-clauses in any ISO standard, and ISO 27001 is no exception. The reason it attracts so much attention is that information security is a specialised field. The people responsible for managing an ISMS, responding to incidents, administering access controls, and conducting risk assessments need to actually know what they are doing.

Defining competence requirements

The first step is identifying which roles affect information security performance. This is broader than just the IT team. It includes:

  • The ISMS manager or information security officer
  • IT administrators managing systems, networks, and access
  • HR staff who handle onboarding and offboarding processes that affect access rights
  • Procurement staff who manage supplier relationships with information security implications
  • Internal auditors who audit the ISMS
  • Senior management who make decisions about risk treatment

For each role, you need to define what competence looks like. This does not have to be elaborate. A simple competence matrix that lists roles, required knowledge or skills, and how competence is demonstrated is sufficient for most organisations.

Demonstrating competence

Competence can come from formal qualifications, professional certifications, structured training, or demonstrated experience. The standard does not require everyone to hold a certification. What it requires is that you can show the person is actually capable of performing their role effectively.

Auditors will ask to see training records, certificates, CVs, or other evidence. They will also ask questions of the people themselves. If the ISMS manager cannot explain the organisation's risk assessment methodology, or the IT administrator is unclear on how access reviews are conducted, that raises questions about whether competence requirements have been genuinely met.

Acting on competence gaps

Where gaps exist, the organisation must take action. This might mean training, mentoring, reassigning responsibilities, or bringing in external expertise. Critically, you must then evaluate whether the action was effective. Sending someone to a training course and filing the certificate is not enough. You need to show that the training actually improved their ability to perform the relevant tasks.

If you are an internal auditor reviewing Clause 7.2, ask to see the competence matrix, then pick a few roles and trace through the evidence. Is the required competence defined? Is there evidence the person has it? If there was a gap, what was done, and did it work? Those four questions will tell you most of what you need to know. For a deeper look at how to approach this audit process, see our article on how to audit competence in ISO 9001, which covers the same evidence-gathering approach applicable across standards.

Clause 7.3: Awareness

Clause 7.3 requires that persons doing work under the organisation's control are aware of the information security policy, their contribution to the effectiveness of the ISMS, the benefits of improved information security performance, and the implications of not conforming with ISMS requirements.

This is where many organisations substitute activity for outcomes. They run an annual security awareness training session, tick a box, and consider the requirement met. Auditors are increasingly sceptical of this approach, and rightly so.

The difference between training and awareness

Awareness is not the same as having attended a training session. Awareness means that people actually understand the things listed in Clause 7.3 and can apply that understanding in their day-to-day work. A person who sat through a 30-minute online module two years ago and cannot recall the organisation's information security policy is not demonstrating awareness.

Effective awareness programmes are ongoing, varied, and targeted to the audience. Different people face different information security risks in their roles, and awareness activities should reflect that. The finance team needs to understand phishing and payment fraud. The IT team needs to understand incident reporting procedures. Remote workers need to understand secure working practices outside the office.

What auditors look for under Clause 7.3

Auditors will interview employees, not just review training records. They will ask workers what the information security policy says, what they would do if they suspected a security incident, and what they understand their responsibilities to be. If workers cannot answer these questions, training records become largely irrelevant.

Practical evidence of effective awareness includes:

  • Regular communications such as security tips, newsletters, or briefings
  • Phishing simulation results showing improvement over time
  • Records of team meetings where information security topics were discussed
  • Onboarding documentation that covers ISMS expectations for new staff
  • Acknowledgement records showing staff have read and understood the security policy

The key thing to communicate to your team is that awareness is about behaviour, not just knowledge. People need to know what to do and actually do it.

Clause 7.4: Communication

Clause 7.4 requires the organisation to determine the need for internal and external communications relevant to the ISMS. Specifically, you need to determine what to communicate, when to communicate it, with whom to communicate, and who shall communicate.

This sub-clause is often overlooked during implementation. Organisations focus heavily on technical controls and risk assessment, and communication planning ends up as an afterthought. That is a mistake, because poor communication is one of the most common root causes of information security incidents.

Internal communication

Internal communication under the ISMS covers a range of activities. It includes how information security incidents are reported, how policy changes are communicated to staff, how the results of internal audits and management reviews are shared with relevant parties, and how the ISMS manager keeps senior management informed of significant risks or changes.

The standard does not require a formal communication plan document, though having one is useful. What it requires is that you have thought through who needs to know what, and when, and that you have a reliable way of making that happen.

External communication

External communication is particularly important for ISO 27001 because information security incidents often have implications for customers, suppliers, regulators, and other external parties. Your communication planning should address:

  • How you will notify customers or partners in the event of a data breach
  • How you communicate your information security requirements to suppliers
  • How you respond to regulatory enquiries or mandatory breach notifications
  • How you manage public communications if a significant incident becomes visible externally

In Australia, the Notifiable Data Breaches scheme under the Privacy Act creates specific obligations for organisations that experience eligible data breaches. Your communication planning should be consistent with those obligations. If your ISMS communication plan does not address regulatory notification, that is a gap worth closing before a certification audit.

What auditors look for under Clause 7.4

Auditors will look for evidence that communication has actually happened, not just that a plan exists. They will ask to see examples of security communications sent to staff, check whether incident reporting channels are known and accessible, and verify that external communication processes are documented and have been tested.

A common finding is that organisations have a communication plan that references a process for notifying customers of incidents, but when the auditor asks how that process works in practice, nobody in the room has actually tested it or can describe the steps clearly. That is an observation at minimum, and potentially a nonconformity if the process is entirely theoretical.

Common Nonconformities in Clause 7

Based on real audit experience, the following are the most frequent issues raised against Clause 7 of ISO 27001:

  • No defined competence requirements for key ISMS roles. The organisation has people performing information security functions but has never formally defined what competence those roles require.
  • Training records exist but effectiveness has not been evaluated. Staff have attended training, but there is no evidence the training actually improved their capability or changed their behaviour.
  • Awareness activities are infrequent and generic. A single annual training session with no follow-up activity, no targeted messaging, and no measurement of effectiveness does not satisfy the intent of Clause 7.3.
  • Workers cannot describe the information security policy. When interviewed, staff are unaware of the policy's content or their own responsibilities under the ISMS.
  • Communication processes are undocumented or untested. The organisation cannot demonstrate how it would communicate with external parties in the event of a significant security incident.
  • Resource decisions are not traceable to ISMS requirements. There is no visible link between the risk treatment plan and the resources allocated to implement controls.

For a broader view of how these types of findings are classified and recorded, the article on audit techniques for Clause 7: verifying competence, awareness and documents provides useful practical guidance.

Practical Tips for Getting Clause 7 Right

Here is what actually works, based on practical audit experience across multiple organisations and sectors.

Build a simple competence matrix and maintain it

A spreadsheet listing roles, required competencies, current evidence of competence, and any identified gaps is all you need. Review it annually and when roles change. Make sure it covers all roles that affect ISMS performance, not just the IT team.

Make awareness ongoing and measurable

Move away from the annual training tick and toward a programme of regular, varied communications. Use phishing simulations. Send monthly security tips. Brief teams at toolbox talks or team meetings. Measure the results. If phishing click rates are declining over time, that is evidence your awareness programme is working.

Test your communication processes before you need them

Run a tabletop exercise that simulates a data breach and walk through your communication process. Who gets notified? When? By whom? What is the message? If you cannot answer these questions in a controlled exercise, you certainly will not be able to answer them during an actual incident. Document the exercise and the lessons learned.

Connect resource decisions to ISMS outputs

When you present your risk treatment plan to management for approval, make the resource requirements explicit. Show what budget, people, and time are needed to implement the selected controls. Get those commitments documented in meeting minutes or a formal decision record.

Prepare your people for auditor interviews

Staff at all levels may be interviewed during a certification audit. Make sure they understand the information security policy, know how to report an incident, and can describe their own responsibilities under the ISMS. This is not about coaching people to give rehearsed answers. It is about ensuring the awareness programme has actually worked. For guidance on how these interviews are typically conducted, the article on audit interviewing techniques every auditor should master is worth reading from both sides of the table.

How Clause 7 Connects to the Rest of the ISMS

Clause 7 does not operate in isolation. It connects directly to Clause 5 (Leadership), because top management must demonstrate commitment to providing resources and ensuring people understand their information security responsibilities. It connects to Clause 6 (Planning), because the competence and resources needed to implement risk treatment plans flow directly from the risk assessment and treatment process. And it connects to Clause 9 (Performance Evaluation), because the effectiveness of training and awareness activities should be reviewed as part of monitoring and management review.

When auditors find weaknesses in Clause 7, they often trace those weaknesses back to a failure of leadership commitment or forward to ineffective performance monitoring. A weak awareness programme, for example, is frequently a symptom of management not prioritising information security in practice, even if the policy says all the right things.

Understanding these connections helps you audit Clause 7 more effectively. Rather than treating it as a standalone checklist, look at how the support provisions feed into the system as a whole. Are the right people resourced and competent to implement the controls? Do staff understand what they need to do and why? Are communication channels in place and working? If the answers are yes and you have evidence to show it, you are in a strong position.

Training for ISO 27001 Auditors

If you are looking to build genuine capability in auditing information security management systems, understanding Clause 7 in depth is a solid starting point, but it is only one piece of the picture. Audit Workshop offers ISO 27001 auditor training at internal auditor and lead auditor levels, delivered by practitioners with real certification audit experience. The training is built around practical audit skills, not just clause-by-clause theory, so you leave with the ability to plan, conduct, and report on ISMS audits with confidence. You can explore the available courses at auditworkshop.com.

Frequently Asked Questions

Clause 7 covers the support requirements of an information security management system. It includes five sub-clauses: resources (7.1), competence (7.2), awareness (7.3), communication (7.4), and documented information (7.5). Together, these requirements ensure that the ISMS has the people, skills, knowledge, and communication processes needed to function effectively.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.