Home/ ISO 27001 clauses guide/ Clause 7 · Support
Requirement 7 · “Do” phase of the PDCA cycle

Clause 7 — Support

The clause that decides whether your ISMS is a living system or a binder nobody opens. Clause 7 requires the practical scaffolding that turns the plans from clause 6 into something that actually runs day to day: the right people with the right resources and skills, staff who understand why any of this matters, a plan for who needs to know what, and a disciplined way of managing the documents the whole system depends on. Auditors treat clause 7 as a leading indicator — an ISMS with thin resourcing, no training records, and undisciplined documents rarely survives an audit no matter how good its risk register looks.

The structure of clause 7

What clause 7 covers

Clause 7 answers four practical questions that clause 6’s planning cannot answer on its own. Do you have the people, budget, and tools the ISMS needs (7.1)? Are those people actually qualified to do security-relevant work, and can you prove it (7.2)? Does staff understand what the security policy means for them and why it matters (7.3)? Is there a deliberate plan for who gets told what, when, and how (7.4)? And underneath all four, does your documentation actually work as a system — created consistently, reviewed, and controlled — rather than a scattered pile of files (7.5)?

Why it is central

Documented information (7.5) is the connective tissue of the entire ISMS — every other clause produces something that eventually has to be created, reviewed, and controlled as documented information: the risk register, the SoA, policies, audit reports, management review minutes. An auditor who finds document control is undisciplined will start doubting whether anything else in the file is current or approved.

The documents that come out of clause 7

  • Evidence of competence for people doing security-relevant work (7.2)
  • The full set of documented information the ISMS requires and generates (7.5.1)
  • Records showing documents were properly identified, formatted, and reviewed before release (7.5.2)
  • Access, version, and retention controls over documented information (7.5.3)

Frequently asked questions

Is clause 7 mostly about training?
Training is part of it (7.2 and 7.3), but clause 7 is broader — it also covers whether the ISMS is properly resourced (7.1), how information flows internally and externally (7.4), and how every document the ISMS relies on is created and controlled (7.5).
Do 7.1 through 7.4 each require their own document?
No — only 7.2 explicitly requires retained documented evidence of competence. The others are typically demonstrated through records that live elsewhere: budget approvals, training logs, or a communication plan, rather than a standalone mandatory document.
What is the difference between 7.5.2 and 7.5.3?
7.5.2 governs how a document is created and approved in the first place — identification, format, review. 7.5.3 governs what happens to it afterward — access, storage, version control, and retention.

Need hands-on support resourcing, training, and documenting your ISMS? See our ISO 27001 certification support service

↑ Back to the 7-clause guide

Give your ISMS the resources, skills, and documents it needs to run.

Sentrix tracks competence records, awareness completion, and document control in one place — so clause 7 stops being an afterthought.