Clause 7

Support

Provide the resources, competence, awareness, communication, and documented information the ISMS needs to run.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILClause 7 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Mandatory documents in this clause

  • Evidence of competence (7.2)
  • Documented information required by the standard and by the organisation (7.5)
7.1

Resources

What it requires: Determine and provide the resources needed to establish, implement, maintain and improve the ISMS.

How to meet it: Budget and staff the ISMS; record resourcing decisions in management review.

7.2

Competence

What it requires: Determine the competence needed for people whose work affects information security, ensure they are competent, act to close gaps, and retain evidence of competence.

How to meet it: Keep training records, certifications, and role competency notes.

7.3

Awareness

What it requires: People doing work under your control must be aware of the policy, their contribution to the ISMS, and the implications of not conforming.

How to meet it: Annual security awareness training with completion tracking.

7.4

Communication

What it requires: Determine the internal and external communications relevant to the ISMS: what, when, with whom, and how.

How to meet it: A short communication plan covering incidents, policy changes, and customer/regulator comms.

7.5

Documented information

What it requires: Maintain the documented information required by the standard and that you need for effectiveness; control its creation and updating (identification, format, review and approval) and its availability, protection, distribution, storage, change control, retention and disposition, including documents of external origin.

How to meet it: Use a controlled doc repository with versioning, owners, and review dates.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Looking for the Annex A controls? See all 93 controls. To run these requirements with automation, read how AI manages compliance.