Support: competence, awareness, documentation
Clause 7 requires the organization to ensure that personnel are qualified for their security roles and aware of their responsibilities within the Information Security Management System (ISMS). It also mandates a structured approach to creating, controlling, and maintaining the documentation necessary to prove the ISMS is functioning.
What it means
Competence focuses on objective capability. The organization must define what skills or experience are needed for specific roles that affect security performance and ensure those people possess them, providing training or hiring where gaps exist.
Awareness ensures that every person working under the organization's control understands the high-level security policy, how their individual work contributes to the ISMS goals, and the risks associated with failing to follow security requirements.
Documented information refers to both "documents" (policies and procedures that guide actions) and "records" (evidence that actions took place). The standard requires these to be controlled so they are available when needed, protected from unauthorized changes, and regularly reviewed for accuracy.
How to meet it
- Define required competencies for key security roles within job descriptions or a skills matrix.
- Provide targeted training or professional certifications for staff managing technical security controls.
- Implement an organization-wide security awareness program that includes the ISMS policy and reporting procedures.
- Establish a document control procedure that defines how documents are named, versioned, approved, and archived.
- Create a centralized, access-controlled repository for all mandatory ISMS documentation.
- Conduct periodic reviews of documented information to ensure it remains current and relevant.
Evidence an auditor asks for
- Training logs, certificates of completion, or updated CVs proving personnel competence.
- Records of security awareness training attendance or results from knowledge checks/quizzes.
- A document register listing all policies, their current version numbers, owners, and last review dates.
- Documented evidence of approval (e.g., email approvals or digital signatures) for key ISMS policies.
- Examples of controlled records, such as completed risk assessment forms or incident logs.
Common pitfalls
- Treating awareness as a "check-the-box" exercise by sending an email without verifying that employees actually understand the policy.
- Maintaining multiple versions of the same policy in different folders, leading to the use of obsolete documents.
- Assuming competence based on tenure or title rather than maintaining objective evidence of training or qualification.