Auditen
Home / Frameworks / ISO 27001 / Support: competence, awareness, documentation
ISO 27001 · Clause 7

Support: competence, awareness, documentation

Clause 7 requires the organization to ensure that personnel are qualified for their security roles and aware of their responsibilities within the Information Security Management System (ISMS). It also mandates a structured approach to creating, controlling, and maintaining the documentation necessary to prove the ISMS is functioning.

What it means

Competence focuses on objective capability. The organization must define what skills or experience are needed for specific roles that affect security performance and ensure those people possess them, providing training or hiring where gaps exist.

Awareness ensures that every person working under the organization's control understands the high-level security policy, how their individual work contributes to the ISMS goals, and the risks associated with failing to follow security requirements.

Documented information refers to both "documents" (policies and procedures that guide actions) and "records" (evidence that actions took place). The standard requires these to be controlled so they are available when needed, protected from unauthorized changes, and regularly reviewed for accuracy.

How to meet it

Evidence an auditor asks for

  • Training logs, certificates of completion, or updated CVs proving personnel competence.
  • Records of security awareness training attendance or results from knowledge checks/quizzes.
  • A document register listing all policies, their current version numbers, owners, and last review dates.
  • Documented evidence of approval (e.g., email approvals or digital signatures) for key ISMS policies.
  • Examples of controlled records, such as completed risk assessment forms or incident logs.

Common pitfalls

  • Treating awareness as a "check-the-box" exercise by sending an email without verifying that employees actually understand the policy.
  • Maintaining multiple versions of the same policy in different folders, leading to the use of obsolete documents.
  • Assuming competence based on tenure or title rather than maintaining objective evidence of training or qualification.