Support
Provide the resources, competence, awareness, communication, and documented information the ISMS needs to run.
Mandatory documents in this clause
- ✓Evidence of competence (7.2)
- ✓Documented information required by the standard and by the organisation (7.5)
Resources
What it requires: Determine and provide the resources needed to establish, implement, maintain and improve the ISMS.
How to meet it: Budget and staff the ISMS; record resourcing decisions in management review.
Competence
What it requires: Determine the competence needed for people whose work affects information security, ensure they are competent, act to close gaps, and retain evidence of competence.
How to meet it: Keep training records, certifications, and role competency notes.
Awareness
What it requires: People doing work under your control must be aware of the policy, their contribution to the ISMS, and the implications of not conforming.
How to meet it: Annual security awareness training with completion tracking.
Communication
What it requires: Determine the internal and external communications relevant to the ISMS: what, when, with whom, and how.
How to meet it: A short communication plan covering incidents, policy changes, and customer/regulator comms.
Documented information
What it requires: Maintain the documented information required by the standard and that you need for effectiveness; control its creation and updating (identification, format, review and approval) and its availability, protection, distribution, storage, change control, retention and disposition, including documents of external origin.
How to meet it: Use a controlled doc repository with versioning, owners, and review dates.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.