Clause 7 looks unglamorous, and yet it draws more audit findings than any other clause. A few training records missing. A procedure still circulating at an old revision. A document distributed with the approver field blank. None of these are about the quality of your security — they are about records and control.
They also occur largely independently of how capable an organisation is. A company with strong security practices will still take a nonconformity if it has no design for recording what it does. Conversely, once the shape of the records is fixed, day-to-day effort barely increases. Clause 7 is the clause where you fix that shape.
This article translates Clause 7 into practice: competence versus awareness, how to keep training records, designing document control, and what auditors ask for. For the planning that precedes it see Clause 6: Planning; for the whole standard, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
What This Clause Actually Asks For
Clause 7 has five parts.
1. Resources
Determine and provide the resources needed to establish, implement, maintain and continually improve the ISMS — people, time, budget, tooling, outside expertise. This is where top management's Clause 5 commitment becomes concrete.
2. Competence
For people doing work that affects information security performance, determine the necessary competence, ensure they have it through education, training or experience, and retain records as evidence of competence. Where competence is lacking, take action to acquire it — training, reassignment, hiring, outsourcing — and evaluate whether that action worked.
The point here is that "we sent them on a course" and "they are competent" are different claims. The standard asks for the second; the course is one means to it.
3. Awareness
People doing work under the organisation's control must be aware of the information security policy, how they contribute to the ISMS's effectiveness (including the benefits of improved performance), and what it means to fail to conform to ISMS requirements.
Competence is the ability to perform a specific role properly; awareness is the minimum everyone must hold. They cover different populations.
4. Communication
Determine the internal and external communications relevant to the ISMS: what, when, with whom, by whom, and how. Incident escalation paths, customer notification, reporting to authorities, and dealings with the certification body all belong here.
5. Documented information
Create and control the documentation the standard requires plus whatever the organisation decides it needs. When creating and updating, ensure identification (title, date, author, reference), format and media, and review and approval. Control means the documentation is available where and when needed and adequately protected, with rules for distribution, access, retrieval and use; storage and preservation; change control including version control; and retention and disposal. Externally created documents deemed necessary are also within scope.
What You Produce in Practice
| Deliverable | Purpose | Who approves |
|---|---|---|
| Competence requirements (skill map by role) | States the knowledge and skills each role needs | ISMS manager / department heads |
| Competence evaluation records | Evidence that each person meets the requirement | Department heads |
| Annual training plan | Audience, content, timing, evaluation method | ISMS manager (resources approved by top management) |
| Training delivery and completion records | Who took what, when, and how understanding was checked | ISMS manager |
| Comprehension check results | Evidence that awareness actually landed | ISMS manager |
| Undertakings / confidentiality acknowledgements | Evidence of obligations accepted by workers and contractors | HR / ISMS manager |
| Communication plan | Topics, channels, owners and timing, internal and external | ISMS manager |
| Document control procedure | Rules for creating, approving, distributing, revising and disposing | Top management |
| Document register | Current revision, revision date, approver, retention, in one list | ISMS manager |
| Records register | Record types, storage location, retention period, disposal method | ISMS manager |
Design competence and awareness as separate record trails. Laid out side by side, the audience and evidence become clear.
| Competence | Awareness | |
|---|---|---|
| Who | Specific roles: ISMS manager, internal auditors, system administrators, developers, supplier managers | Everyone working under the organisation's control, including executives, employees, contractors and on-site supplier staff |
| What is required | Able to perform that role's work properly | Understands the policy, their contribution, and the meaning of nonconformity |
| Typical evidence | Qualifications, course certificates, experience records, competence evaluation sheets | Annual training completion records, comprehension test results, signed undertakings |
| If lacking | Training, OJT, reassignment, hiring, outsourcing | Retake, individual follow-up |
Do not over-engineer document control. The minimum that works:
- Every document carries a document number, revision, issue date, revision date and approver
- The current version lives in exactly one place — not scattered across shared drives
- Each revision records one line on what changed and why
- Superseded versions are archived, not deleted, so the history can be shown
- Every record type has a defined retention period, aligned to legal and contractual requirements where they exist
See ISMS Document Structure and Adapting Template Procedures to Your Organisation.
Where It Goes Wrong
Training completion never reaches 100%
The most common practical problem. Four groups get missed: mid-year joiners, people returning from leave, long-term secondees, and executives. The fix is not relying on an annual broadcast — put training into the onboarding flow, ideally as a precondition for account issuance. See Designing Security Awareness Training.
On-site supplier staff are outside the training population
"People working under the organisation's control" includes contractors and agency staff working under your direction. Driving the training list from the employee roster alone misses them. Base the list on everyone holding a building pass or an account. See Supplier Security Management.
Training happened, but there is no evidence of awareness
"Materials were distributed" and "a video was published" are weak evidence that anything was understood. A five- to ten-question check transforms the quality of the record. Perfect scores are not the point; having the delivery and the result on file is.
No defined competence requirement
"Internal auditors shall be competent in auditing" leaves no way to judge. Make it decidable: "completion of internal auditor training, or participation in at least two prior audits."
The revision in use is not the current one
Old copies linger on shared drives and get used. The single-location rule handles most of this; adding "the current version is held at X" at the top of every procedure reduces the damage when printouts circulate.
No retention period defined
With no rule on how long to keep something, nobody can decide to delete it, and records accumulate indefinitely. For records containing personal data, having no retention period is itself a risk. Add retention and disposal columns to the records register.
The communication plan fails during an incident
Business-hours escalation is defined; nights and weekends are not. Who decides to notify customers is not settled. Design this together with the Clause 8 incident procedure — see Building an Incident Response Procedure.
What Auditors Look At
Clause 7 is the clause where you are asked to produce the records. Expect specific requests rather than abstract questions.
| Aspect | What is asked |
|---|---|
| Training coverage | Reconciling the roster against completion records for gaps |
| Mid-year joiners | When did your most recent hire receive training? |
| Supplier staff | Are on-site contractors and agency staff covered by training and undertakings? |
| Evidence of competence | On what basis do your internal auditors and administrators meet the requirement? |
| Evaluation of effectiveness | How was training effectiveness evaluated, and how did it change the next plan? |
| Version control | Is the document in use current, and does it name an approver? |
| Revision history | Can you explain what changed and why in the last revision? |
| Retention | Do the defined retention periods match actual storage? |
| External documents | Are the versions of referenced laws, guidelines and standards controlled? |
"When did your most recent joiner complete training?" is a standard question. Organisations that answer immediately usually have Clause 7 under control; organisations that start hunting for a roster usually have the same problem elsewhere in their records.
See Common Nonconformities and What Stage 2 Audits Look At.
Healthcare Examples
A healthcare SaaS provider
Set a separate competence requirement for anyone who can touch production patient data — support engineers, SRE, data platform staff — distinct from company-wide awareness training. Typically: completion of training on handling medical information, a confirmed understanding of the production access procedure, and an annual refresh. Record these in the role skill map and the competence evaluation records.
Responding to customer security questionnaires also belongs in the communication plan. Without defined authority and disclosure limits, a salesperson will eventually send architecture details on their own judgement.
A PHR operator
Because support speaks directly with individuals, competence in identity verification becomes the issue: disclosure to an impersonator is treated as the operator's failure. Beyond writing the procedure, you need records confirming staff can actually follow it.
A clinical trial systems company
Under ER/ES guidance and data integrity expectations, retention and version control requirements tend to be stricter than generic ISMS practice. Folding trial-related retention periods into the ISMS records register avoids maintaining two systems. See ISMS for Clinical Trial Systems.
A SaMD developer
ISO 13485 carries its own competence and document control requirements. Keeping two training registers and two document registers guarantees one of them goes stale. Keep one physical set of records and reference it from both systems. See SaMD, ISMS and QMS.
In all cases, the training and record-keeping the three-ministry guidelines expect can ride on Clause 7 operation. See Integrating ISMS Documents with the Three-Ministry Guidelines and Three-Ministry Guidelines.
Conclusion
- Clause 7 attracts the most findings, and the outcome depends on record design rather than on how good your security is
- Competence and awareness differ in audience and evidence. Design role-based competence separately from company-wide awareness
- What blocks 100% completion is joiners, returners, secondees and executives. Embedding training in onboarding is the most reliable fix
- The training population is not the employee roster — it includes contractors and agency staff under your direction
- Minimum document control: revision and approver on every document / one location for the current version / one line of revision rationale / archive superseded versions / define retention
- Whether you can instantly answer "when did your last joiner complete training?" is a practical gauge of Clause 7 maturity
On the foundation Clause 7 builds, Clause 8: Operation executes, Clause 9: Performance Evaluation checks, and Clause 10: Improvement closes the loop. See also Clause 4: Context, Clause 5: Leadership and Clause 6: Planning.
Pottech supports ISMS certification with a focus on healthcare. We supply templates for procedures, registers and training material and fix the document structure before operation begins, which removes most Clause 7 rework. See ISMS Certification Support or contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Japanese Industrial Standards Committee (JISC)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Information-technology Promotion Agency, Japan (IPA)
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.