6.4 Clause 7: Support
Key Takeaways
- Clause 7.2 Competence requires having the right skills (with retained documented evidence); Clause 7.3 Awareness requires understanding the policy, contribution, and consequences — they are not interchangeable
- Clause 7.4 requires the organization to decide what, when, with whom (both internal and external), and how to communicate about the ISMS
- The 2022 edition replaces the 2013 'documents' and 'records' vocabulary with 'maintained documented information' and 'retained documented information'
- Clause 7.5.3 requires control of documented information of external origin deemed necessary for ISMS planning and operation, not just internally authored documents
- ISO/IEC 27001 does not mandate a single 'Information Security Manual' — the organization decides what additional documented information it needs for effectiveness
Clause 7 is the backbone of the ISMS — it specifies the resources, skills, awareness, communication, and documented information needed to make the system operate. Without these support elements, the policies established in Clause 5 and the risks identified in Clause 6 cannot be addressed. The Foundation exam tests whether you can match each subclause to its specific requirement and avoid common vocabulary traps carried over from the 2013 version of the standard.
7.1 Resources
The organization must determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS. Resources include people, infrastructure, technology, time, training budgets, and external expertise such as consultants or auditors.
Note the four lifecycle verbs: establish, implement, maintain, continually improve — the same four verbs appear throughout the standard and mirror the PDCA cycle. A common exam scenario asks which activity is NOT covered; resources must be provided for all four, not just for initial implementation.
7.2 Competence
The organization must:
- Determine the necessary competence of persons doing work that affects ISMS performance
- Ensure those persons are competent on the basis of education, training, or experience
- Take actions to acquire necessary competence (training, mentoring, reassignment) and evaluate the effectiveness of those actions
- Retain documented information as evidence of competence (certificates, training records, CVs)
A trap: competence is about ability to do the work, not awareness. Awareness (7.3) is about understanding the ISMS, policy, and consequences of nonconformity. Competence is about having the skills to perform assigned tasks. The exam often pairs these two subclauses to test the distinction.
7.3 Awareness
Persons doing work under the organization's control must be aware of:
- The information security policy (Clause 5.2)
- Their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance
- The implications of not conforming with ISMS requirements
- Their roles and responsibilities in contributing to the effectiveness of the ISMS
Notice the overlap with Clause 5.3 — top management must communicate the policy, and Clause 7.3 ensures that workers actually understand it and their part in it. The exam may test the distinction between "communicate" (7.4) and "be aware of" (7.3): awareness is the result; communication is the mechanism.
7.4 Communication
Clause 7.4 requires the organization to determine what, when, with whom, and how to communicate about the ISMS. The standard explicitly distinguishes internal and external communications.
| Question | Internal | External |
|---|---|---|
| What? | ISMS performance, incidents, audit results | ISMS existence, certified status, incident notifications |
| When? | Regularly, on incidents, on changes | Per legal requirements, on demand, on significant changes |
| With whom? | Employees, management, contractors | Regulators, customers, suppliers, certification body |
| How? | Intranet, meetings, email, training | Letters, emails, press releases, supplier portals |
The exam often asks which decision is NOT required by Clause 7.4 — answers typically omit "with whom" or confuse internal vs external audiences. The standard also requires that communications reflect what is decided in the policy and that communications are consistent with the ISMS objectives.
7.5 Documented Information
7.5.1 General
Documented information required by the standard must be maintained and retained. The 2022 version replaces the 2013 vocabulary of "documents" and "records" with the single term documented information. This is the most heavily tested vocabulary change.
Documented information falls into two purposes:
- Maintained documented information — living documents the ISMS needs to function (policies, procedures, the risk treatment plan)
- Retained documented information — evidence of results (audit reports, training records, management review minutes, risk assessment results)
The standard also permits flexibility: the organization may determine what additional documented information it needs for effectiveness, and ISO 27001 does NOT mandate a specific "Information Security Manual" — a common misconception.
7.5.2 Creating and Updating
When creating or updating documented information, the organization must ensure appropriate:
- Identification and description (title, date, author, reference number)
- Format (paper, electronic, language, software and version)
- Review and approval for suitability and adequacy
7.5.3 Control of Documented Information
Documented information required by the ISMS and by ISO/IEC 27001 must be controlled to ensure:
- It is available and suitable for use, where and when needed
- It is adequately protected (from loss of confidentiality, improper modification, integrity loss)
Control activities include distribution, access, retrieval, use, storage, preservation, controlled change, retention, and disposition. The organization must also control documented information of external origin that it deems necessary for ISMS planning and operation — for example, vendor security whitepapers, regulatory guidance, or standards documents.
A common trap: the standard does NOT require a single rigid document control procedure — it requires that the controls achieve the outcomes of availability and protection. Procedures may be distributed across multiple processes.
Common Vocabulary Trap: "Documents" vs "Records"
The 2013 edition used "documented information" as an umbrella term but still referenced "documents" (maintained) and "records" (retained) as separate categories. The 2022 edition consolidates this language. On the exam, any answer that uses the words "documents and records" as separate categories is outdated and incorrect — use "maintained documented information" and "retained documented information" instead.
An organization trains new hires to operate the SIEM platform and stores their course completion certificates in personnel files. Which Clause 7 subclause most directly covers this activity?
Which of the following is NOT one of the four communication decisions required by Clause 7.4?
Under ISO/IEC 27001:2022, which pair of terms replaces the 2013 vocabulary of 'documents' and 'records'?