Clause 7 · Support

7.3 — Awareness

Not training on how to do a job — awareness of why the job matters to security, and what happens when the rules are not followed.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 7.3 requires everyone doing work under the organization’s control to know three things: what the security policy says, how their own work contributes to the ISMS actually working, and what it means — for them, personally — if they do not follow the rules.

Position in the standard

Clause 7 · Support
7.3 · Awareness ← you are here
See also: 7.1 · 7.2 · 7.4 · 7.5

Why this requirement exists

Most security incidents involve an ordinary employee doing something that made sense to them in the moment — clicking a link, sharing a password to help a colleague, skipping a step under deadline pressure. Awareness exists because a well-designed control that nobody understands the point of will get worked around the first time it is inconvenient.

Scenario: an employee disables a security tool that keeps flagging a legitimate business file as suspicious, because nobody ever explained why the tool matters or who to call instead of working around it. Awareness training that covers "here is the policy, here is why it exists, here is what happens if you bypass it, and here is who to contact" prevents exactly this.

What the standard expects

The standard expects persons doing work under the organization’s control to be aware of the information security policy; their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; and the implications of not conforming with ISMS requirements.

In practice

  • Run awareness for everyone with access to organizational systems or data, not just employees with "security" in their title — contractors and temporary staff included.
  • Make the content role-relevant: what developers need to know about secure coding differs from what finance needs to know about invoice fraud.
  • Refresh awareness regularly, not just at onboarding — a one-time session at hire date does not satisfy an ongoing requirement.

Evidence the auditor will ask for

  • Completion records for awareness sessions, covering all relevant staff including contractors.
  • The actual awareness content, showing it covers the policy, individual contribution, and consequences of nonconformity — not just generic cyber-hygiene tips.

Common pitfalls

  • Generic, off-the-shelf awareness content with no mention of the organization’s own policy or consequences.
  • Contractors and temporary staff excluded from awareness because they are not on the formal payroll.

Related requirements

Parent link: Clause 7 · Support

Frequently asked questions

How is awareness different from competence (7.2)?
Awareness is a baseline everyone needs — knowing the policy exists and matters. Competence (7.2) is a deeper, role-specific skill requirement for people whose work directly affects security controls.

Make security awareness role-relevant, not generic.

Sentrix tracks awareness completion by role and keeps the records an auditor will ask for.