7.1 — Resources
A one-sentence requirement that a surprising number of ISMS projects quietly fail — because the plan was solid but nobody actually funded it.
In plain language
In plain language: 7.1 requires you to figure out what the ISMS actually needs to be built, run, maintained, and continually improved — people, budget, tools, time — and then provide it, not just acknowledge that it would be nice to have.
Position in the standard
Why this requirement exists
A risk treatment plan with no budget behind it is a wish list. This requirement exists because it is easy to build an ISMS that looks complete on paper while starving it of the actual time and money needed to keep it running — and an auditor who sees resourcing gaps will expect to see them show up as unclosed risks and stale documentation elsewhere in the file.
Scenario: a company assigns ISMS ownership to an IT manager as a side responsibility, with no dedicated hours and no tooling budget. Risk assessments slip, the SoA goes stale, and internal audits get postponed indefinitely — not because anyone lacks knowledge, but because nobody was ever actually resourced to do the work.
What the standard expects
The standard expects the organization to determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS. It does not specify what those resources are or how much is enough — that is left to the organization’s own context and risk appetite, but the determination and provision both have to be deliberate and traceable.
In practice
- Name an ISMS owner with dedicated time allocated for the role, not just a title added to an already full job description.
- Attach a budget line to the ISMS covering tooling, training, and any external support (audits, consulting) it needs.
- Revisit resourcing whenever scope or risk changes significantly — a resourcing decision made at certification does not automatically stay adequate.
Evidence the auditor will ask for
- An approved budget or resource plan covering the ISMS.
- A named ISMS owner with a defined allocation of time for the role.
- Evidence that resourcing gaps flagged in risk assessments or audits were actually addressed, not just noted.
Common pitfalls
- Treating the ISMS as an unfunded side project layered on top of someone’s existing job.
- A resourcing decision that was adequate at certification but never revisited as the organization grew.
Related requirements
7.2 Competence
Resources include making sure the right people have the right skills.
Clause 6 Planning
Resourcing decisions should trace back to the risk treatment plan and objectives set here.
Parent link: Clause 7 · Support
Frequently asked questions
Does 7.1 require a dedicated full-time security role?
Give your ISMS a real budget, not just a plan.
Sentrix helps you size the resourcing your ISMS actually needs and track whether gaps flagged in risk assessments get closed.