Clause 7 · Support

7.1 — Resources

A one-sentence requirement that a surprising number of ISMS projects quietly fail — because the plan was solid but nobody actually funded it.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 7.1 requires you to figure out what the ISMS actually needs to be built, run, maintained, and continually improved — people, budget, tools, time — and then provide it, not just acknowledge that it would be nice to have.

Position in the standard

Clause 7 · Support
7.1 · Resources ← you are here
See also: 7.2 · 7.3 · 7.4 · 7.5

Why this requirement exists

A risk treatment plan with no budget behind it is a wish list. This requirement exists because it is easy to build an ISMS that looks complete on paper while starving it of the actual time and money needed to keep it running — and an auditor who sees resourcing gaps will expect to see them show up as unclosed risks and stale documentation elsewhere in the file.

Scenario: a company assigns ISMS ownership to an IT manager as a side responsibility, with no dedicated hours and no tooling budget. Risk assessments slip, the SoA goes stale, and internal audits get postponed indefinitely — not because anyone lacks knowledge, but because nobody was ever actually resourced to do the work.

What the standard expects

The standard expects the organization to determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS. It does not specify what those resources are or how much is enough — that is left to the organization’s own context and risk appetite, but the determination and provision both have to be deliberate and traceable.

In practice

  • Name an ISMS owner with dedicated time allocated for the role, not just a title added to an already full job description.
  • Attach a budget line to the ISMS covering tooling, training, and any external support (audits, consulting) it needs.
  • Revisit resourcing whenever scope or risk changes significantly — a resourcing decision made at certification does not automatically stay adequate.

Evidence the auditor will ask for

  • An approved budget or resource plan covering the ISMS.
  • A named ISMS owner with a defined allocation of time for the role.
  • Evidence that resourcing gaps flagged in risk assessments or audits were actually addressed, not just noted.

Common pitfalls

  • Treating the ISMS as an unfunded side project layered on top of someone’s existing job.
  • A resourcing decision that was adequate at certification but never revisited as the organization grew.

Related requirements

Parent link: Clause 7 · Support

Frequently asked questions

Does 7.1 require a dedicated full-time security role?
No — the standard scales to the organization. A small company may satisfy this with a part-time allocation, as long as it is deliberate, sufficient for the ISMS scope, and documented.

Give your ISMS a real budget, not just a plan.

Sentrix helps you size the resourcing your ISMS actually needs and track whether gaps flagged in risk assessments get closed.