Clause 7 — Support
The clause that decides whether your ISMS is a living system or a binder nobody opens. Clause 7 requires the practical scaffolding that turns the plans from clause 6 into something that actually runs day to day: the right people with the right resources and skills, staff who understand why any of this matters, a plan for who needs to know what, and a disciplined way of managing the documents the whole system depends on. Auditors treat clause 7 as a leading indicator — an ISMS with thin resourcing, no training records, and undisciplined documents rarely survives an audit no matter how good its risk register looks.
The structure of clause 7
What clause 7 covers
Clause 7 answers four practical questions that clause 6’s planning cannot answer on its own. Do you have the people, budget, and tools the ISMS needs (7.1)? Are those people actually qualified to do security-relevant work, and can you prove it (7.2)? Does staff understand what the security policy means for them and why it matters (7.3)? Is there a deliberate plan for who gets told what, when, and how (7.4)? And underneath all four, does your documentation actually work as a system — created consistently, reviewed, and controlled — rather than a scattered pile of files (7.5)?
Why it is central
Documented information (7.5) is the connective tissue of the entire ISMS — every other clause produces something that eventually has to be created, reviewed, and controlled as documented information: the risk register, the SoA, policies, audit reports, management review minutes. An auditor who finds document control is undisciplined will start doubting whether anything else in the file is current or approved.
The documents that come out of clause 7
- Evidence of competence for people doing security-relevant work (7.2)
- The full set of documented information the ISMS requires and generates (7.5.1)
- Records showing documents were properly identified, formatted, and reviewed before release (7.5.2)
- Access, version, and retention controls over documented information (7.5.3)
Frequently asked questions
Is clause 7 mostly about training?
Do 7.1 through 7.4 each require their own document?
What is the difference between 7.5.2 and 7.5.3?
Need hands-on support resourcing, training, and documenting your ISMS? See our ISO 27001 certification support service
Give your ISMS the resources, skills, and documents it needs to run.
Sentrix tracks competence records, awareness completion, and document control in one place — so clause 7 stops being an afterthought.