2.6 Support Processes: Competence, Communication & Documented Information (Clauses 7.2–7.6)
Key Takeaways
- Clause 7.2 requires determining competence, ensuring personnel are competent on the basis of education, training, or experience, and retaining appropriate evidence of competence.
- Clause 7.4 requires internal and external communications relevant to the ISMS, including what is communicated, when, with whom, and how.
- Clause 7.5 mandates control of documented information required by ISO/IEC 27001 and determined necessary for ISMS effectiveness, covering creation, update, and control.
- Clause 7.6 requires determining, maintaining, and making available the organizational knowledge necessary for ISMS operation and conformity of information security.
- Domain 4 scenarios frequently test distinctions among policies, procedures, guidelines, records, and how cloud, AI, and big-data trends change implementation risk.
2.6 Support Processes: Competence, Communication & Documented Information (Clauses 7.2–7.6)
After planning risk treatment and objectives, Lead Implementers must establish the Support processes that make the ISMS operable. Clauses 7.2 through 7.6 of ISO/IEC 27001:2022 define competence, awareness interfaces, communication, documented information, and organizational knowledge. PECB Domain 4 (Implementation of an ISMS) weights these topics heavily because certification auditors treat missing procedures, uncontrolled records, and untrained personnel as systemic weaknesses—even when Annex A technical controls exist.
Competence (Clause 7.2) and Awareness Inputs (Clause 7.3)
Clause 7.2 Competence requires the organization to:
- Determine the necessary competence of persons doing work under its control that affects information security performance.
- Ensure persons are competent on the basis of appropriate education, training, or experience.
- Where applicable, take actions to acquire necessary competence and evaluate the effectiveness of those actions.
- Retain appropriate documented information as evidence of competence.
Lead Implementers build a competence matrix mapping ISMS roles (risk owner, control owner, internal auditor, incident responder, asset owner) to required skills and evidence (certificates, training records, supervised experience). Competence gaps become training plans—not informal “read the policy” emails.
Clause 7.3 Awareness requires persons doing work under the organization’s control to be aware of the information security policy, their contribution to ISMS effectiveness (including benefits of improved performance), and implications of not conforming. Awareness is broader than annual phishing modules: it is continuous reinforcement tied to role-specific risks. Annex A people controls (especially A.6.3) operationalize awareness delivery, but Clause 7.3 remains the mandatory management-system requirement.
Communication Planning (Clause 7.4)
Clause 7.4 Communication requires the organization to determine internal and external communications relevant to the ISMS, including:
| Decision element | Implementation example |
|---|---|
| What is communicated | Policy changes, incident status, audit results, objective performance |
| When to communicate | Immediate for incidents; quarterly for metrics; annually for management review outcomes |
| With whom | Employees, contractors, regulators, customers, suppliers, board |
| How | Secure portals, all-hands briefings, contractual notices, regulatory portals |
An ISMS communication plan is a standard Lead Implementer deliverable. It distinguishes mandatory regulatory notifications (for example, breach reporting timelines) from routine awareness messaging, and it assigns owners so communications are not ad hoc during crises.
Documented Information Lifecycle (Clause 7.5)
Clause 7.5 Documented information is one of the most frequently tested Support topics. The organization must include documented information required by ISO/IEC 27001 and documented information determined necessary for ISMS effectiveness. Lead Implementers distinguish:
| Type | Purpose | Examples |
|---|---|---|
| Policy | Intent and direction from Top Management | Information security policy (Clause 5.2) |
| Procedure / process description | How mandatory activities are performed | Risk assessment procedure, incident response procedure |
| Guideline / standard / baseline | Recommended or technical detail | Secure configuration baselines |
| Record (evidence) | Proof that activities occurred | Risk assessment results, training attendance, audit reports, management review minutes |
Clause 7.5 requires control over:
- Creation and update — identification, format, review, and approval for suitability and adequacy.
- Control of documented information — availability where needed, adequate protection, distribution/access/retrieval/use, storage and preservation, version control, retention and disposition, and control of documents of external origin.
Practical implementation uses a Documented Information Register listing each required artifact, owner, classification, retention period, storage location, and review cycle. Common Stage 1 failures include outdated policies still marked “approved,” missing version history, or risk treatment plans that exist only in email threads.
Control A.5.37 Documented operating procedures complements Clause 7.5 by requiring operating procedures for information processing facilities to be documented where needed and made available to personnel who need them.
Organizational Knowledge (Clause 7.6)
Clause 7.6 Organizational knowledge—part of the ISO Harmonized Structure—requires the organization to determine knowledge necessary for the operation of its processes and to achieve conformity of information security, maintain that knowledge, and make it available as necessary. When addressing changing needs, the organization must consider current knowledge and determine how to acquire or access additional knowledge.
For Lead Implementers, organizational knowledge includes tribal expertise of control owners, architecture decisions, historical incident lessons, and supplier-specific configurations. Knowledge loss from staff turnover is an ISMS risk. Mitigations include runbooks, architecture decision records, mentoring, and controlled repositories—not solely individual inboxes.
Trends and Technologies Affecting Implementation
PECB Domain 4 explicitly expects implementers to evaluate modern technology trends when designing operations:
- Cloud computing (IaaS, PaaS, SaaS): Shared-responsibility boundaries change which Annex A controls the organization implements directly versus assures through supplier agreements (A.5.23).
- Big data (volume, variety, velocity): Large-scale analytics increase classification, access-control, and logging complexity.
- Artificial intelligence and machine learning: Training-data poisoning, model inversion, and automated decision risks require updated risk assessments and acceptable-use rules.
- Outsourced operations: Extended enterprises amplify supplier and incident-coordination requirements.
Lead Implementers do not treat trends as optional reading: they trigger updates to context (Clause 4.1), risk assessment (Clause 6.1.2), SoA entries, and communication plans.
Practical Implementation Scenario
Scenario: After approving the SoA, a scale-up’s auditors find that incident-response playbooks live only in a retired engineer’s personal cloud drive, competence records for internal auditors are missing, and contractors never received the information security policy.
Lead Implementer response: Establish Clause 7.5 document control with approved templates and a register; migrate playbooks into the controlled repository; complete Clause 7.2 competence evidence for auditor roles; execute Clause 7.3/7.4 awareness and communication campaigns for contractors; and document critical operational knowledge under Clause 7.6 so Stage 1 document review and Stage 2 interviews can demonstrate support-process conformity.
During a Stage 1 document review, the auditor requests evidence that persons performing internal audits are competent. Which ISO/IEC 27001:2022 clause primarily governs retention of competence evidence?
A Lead Implementer is classifying ISMS artifacts. Which item is best categorized as a record rather than a policy or procedure?
Clause 7.6 Organizational knowledge primarily requires the organization to: