Competence, Awareness and Communication
In ISO/IEC 27001, Competence, Awareness and Communication are support requirements in Clause 7 (Support). They make sure the people running the ISMS can operate it effectively. A Lead Auditor checks that each is planned, carried out and backed by evidence. Clause 7.2 Competence requires the organiz… In ISO/IEC 27001, Competence, Awareness and Communication are support requirements in Clause 7 (Support). They make sure the people running the ISMS can operate it effectively. A Lead Auditor checks that each is planned, carried out and backed by evidence. Clause 7.2 Competence requires the organization to determine the competence needed by people whose work affects information security performance. It must ensure they are competent through appropriate education, training or experience. Where gaps exist, it must take action to close them, such as training, mentoring, reassignment or hiring, and then evaluate whether that action worked. Documented information must be retained as evidence of competence. Auditors typically sample job descriptions, competence matrices, training records, certificates and effectiveness evaluations. Clause 7.3 Awareness requires that people working under the organization's control know three things. They must know the information security policy. They must understand how they contribute to the effectiveness of the ISMS, including the benefits of improved security performance. They must also understand the implications of not conforming to ISMS requirements. Annex A control 6.3 (Information security awareness, education and training) supports this clause. Auditors interview staff at different levels to confirm real understanding rather than mere attendance at sessions. Clause 7.4 Communication requires the organization to determine its internal and external communications relevant to the ISMS. This covers what to communicate, when, with whom and how. Common examples include communications with employees, top management, customers, suppliers, regulators and incident response contacts. Auditors look for a communication plan or matrix and evidence that it is followed, such as meeting minutes, notices and incident notifications. Together, these clauses link people to the ISMS. Competence means people can perform their roles. Awareness means they understand why security matters. Communication means the right information reaches the right parties at the right time. Weaknesses here often lead to nonconformities elsewhere, such as poor incident handling or ineffective controls.
Competence, Awareness and Communication (ISO/IEC 27001 Clauses 7.2, 7.3 and 7.4): A Lead Auditor Guide
Introduction
Clause 7 of ISO/IEC 27001:2022 is titled Support. It covers the resources, people and information needed to run an Information Security Management System (ISMS). Three of its sub-clauses are about people and how information moves between them:
• Clause 7.2 Competence
• Clause 7.3 Awareness
• Clause 7.4 Communication
For a Lead Auditor candidate, these clauses are heavily examined. They are easy to confuse, and they appear in almost every audit scenario. Most security incidents involve a human element, and these three clauses are the standard's main defence against it.
Part 1: Why Competence, Awareness and Communication Are Important
An ISMS can have excellent policies, risk assessments and controls and still fail. This happens when the people running it do not know what they are doing, do not understand why it matters, or do not receive the right information at the right time.
• People operate the controls. Firewalls are configured, access is reviewed, incidents are reported and backups are tested by people. Incompetent or unaware staff make controls ineffective.
• Human error is a leading cause of breaches. Phishing, misdirected emails, weak passwords and misconfigurations are all reduced through competence and awareness.
• Leadership commitment needs a channel. Clause 5 requires top management to communicate the importance of information security. Clause 7.4 provides the mechanism for doing so.
• Stakeholder expectations must be met. Regulators, customers, suppliers and authorities may need specific information, such as breach notifications or security commitments. Unplanned communication creates legal and reputational risk.
• The PDCA cycle depends on them. Without competent people you cannot plan, operate, monitor or improve. Without communication, results of monitoring and audits never reach decision-makers.
• Certification bodies look for evidence. Auditors routinely sample training records, interview staff about the policy and check communication plans. Weaknesses here are among the most common nonconformities raised.
Part 2: What the Requirements Are
Clause 7.2 Competence
The organization shall:
a) determine the necessary competence of person(s) doing work under its control that affects its information security performance;
b) ensure that these persons are competent on the basis of appropriate education, training, or experience;
c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken;
d) retain appropriate documented information as evidence of competence.
Note: Applicable actions can include providing training, mentoring or reassigning current employees, or hiring or contracting competent persons.
Key points:
• Scope of people: the phrase is 'persons doing work under its control'. This includes employees, temporary staff, contractors and, where relevant, outsourced personnel, not just permanent employees.
• Competence vs. training: competence is the ability to apply knowledge and skills to achieve intended results (ISO definition). Training is only one way to achieve it. Attendance at a course does not prove competence.
• Effectiveness evaluation: the organization must check whether its actions actually worked. Examples include tests, observed performance, certification exams, supervisor review and reduced error rates.
• Documented information is mandatory: 7.2 explicitly requires retained evidence, such as CVs, certificates, training records, competence matrices and appraisal results.
Clause 7.3 Awareness
Persons doing work under the organization's control shall be aware of:
a) the information security policy;
b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance;
c) the implications of not conforming with the ISMS requirements.
Key points:
• Awareness applies to everyone within scope, not only those in security roles.
• Awareness is knowing and understanding. Competence is being able to do. A receptionist needs awareness. A firewall administrator needs both awareness and competence.
• Clause 7.3 does not explicitly require documented information. However, organizations normally keep records (e-learning completion, signed acknowledgements), and auditors verify awareness mainly through interviews.
• Implications of nonconformity can include security incidents, harm to customers, legal consequences and the disciplinary process (linked to Annex A control 6.4).
Clause 7.4 Communication
The organization shall determine the need for internal and external communications relevant to the ISMS, including:
a) on what to communicate;
b) when to communicate;
c) with whom to communicate;
d) how to communicate.
Key points:
• The 2022 edition lists four elements: what, when, with whom and how. The 2013 edition also included 'who shall communicate' and 'the processes by which communication shall be effected'. Exam questions based on the 2022 edition use the four-item list, although assigning responsibility remains good practice.
• Communication covers both internal parties (staff, management, ISMS team) and external parties (customers, regulators, suppliers, authorities, certification bodies).
• It must be consistent with the needs of interested parties identified in Clause 4.2.
• No documented information is explicitly mandated. A communication plan or matrix is the most common way to demonstrate conformity.
Related Annex A controls (ISO/IEC 27001:2022)
• 5.2 Information security roles and responsibilities (defines who needs what competence)
• 5.5 Contact with authorities and 5.6 Contact with special interest groups (external communication)
• 6.1 Screening (verifying background and qualifications)
• 6.2 Terms and conditions of employment
• 6.3 Information security awareness, education and training
• 6.4 Disciplinary process (implications of nonconformity)
• 6.8 Information security event reporting (an internal communication channel)
• 5.24 to 5.26 Incident management planning and response (including notification)
Related clauses
• 5.1 and 5.2: top management communicates the importance of security, and the policy must be communicated.
• 5.3: roles and responsibilities must be assigned and communicated.
• 6.2: information security objectives must be communicated.
• 9.2 and 9.3: audit results are reported to management.
• 7.5: control of documented information, which applies to competence records.
Part 3: How It Works in Practice
Implementing competence (7.2)
1. Identify roles that affect information security, such as CISO, ISMS manager, system administrators, developers, HR, internal auditors, risk owners and help desk staff.
2. Define competence requirements for each role in job descriptions or a competence matrix. These can cover qualifications, certifications, skills and years of experience.
3. Perform a gap analysis comparing current staff competence against the requirements.
4. Close gaps through training, mentoring, reassignment, recruitment or outsourcing.
5. Evaluate effectiveness through exams, practical assessments, supervisor observation, KPIs and post-training reviews.
6. Retain records, such as certificates, training logs, CVs, appraisal outcomes and the updated matrix.
7. Review periodically, for example when technology changes, new risks emerge or people change roles.
Implementing awareness (7.3)
• Induction programmes for new joiners that include the security policy.
• Annual or periodic e-learning with quizzes.
• Phishing simulations, posters, newsletters, intranet pages and screen savers.
• Signed acknowledgement of the policy and acceptable use rules.
• Targeted briefings after incidents or policy changes.
• Messages that cover all three required topics: the policy, each person's contribution, and the consequences of nonconformity.
Implementing communication (7.4)
A typical communication matrix has these columns:
What | When | With whom | How | Responsible
Example rows:
• ISMS policy updates | On approval | All staff | Intranet and email | ISMS Manager
• Security incident affecting personal data | Within regulatory deadlines (e.g. 72 hours under GDPR) | Supervisory authority and affected customers | Formal notification | DPO or Legal
• ISMS performance | Quarterly | Top management | Management review meeting | CISO
• Supplier security requirements | At contract and on change | Suppliers | Contract clauses and meetings | Procurement
• Security alerts | As needed | IT staff | Ticketing system and chat | SOC
How an auditor audits these clauses
Following ISO 19011 principles, an auditor gathers objective evidence through documents, interviews and observation.
Auditing competence (7.2):
• Ask for the competence requirements for a sample of roles.
• Select a sample of individuals (including contractors) and trace each from requirement, to evidence of competence, to records.
• Check whether training effectiveness was evaluated, not just whether training was delivered.
• Verify that internal auditors are competent and independent, which links to 9.2.
• Example nonconformity: 'A system administrator with privileged access had no defined competence requirements and no records of relevant training or experience.'
Auditing awareness (7.3):
• Interview staff at different levels: 'Where can you find the security policy?', 'How does your job affect information security?', 'What would happen if you did not follow the clear desk rule?', 'How would you report a suspected incident?'
• Observe behaviour, such as unlocked screens, tailgating or passwords on sticky notes.
• Review awareness programme content and completion rates.
• Example nonconformity: 'Three of five interviewed staff were unaware of the information security policy or how to report incidents, despite records showing completion of awareness training.'
Auditing communication (7.4):
• Request evidence that communication needs have been determined (what, when, with whom, how).
• Verify that communications actually happened as planned, such as policy announcements, management review inputs and customer notifications.
• Check alignment with interested parties' requirements (4.2) and legal obligations.
• Example nonconformity: 'The organization had not determined external communication needs for security incidents, although contractual obligations require customer notification within 24 hours.'
Grading findings
• Major nonconformity: a total absence or systemic failure of the requirement. Examples are no competence determination at all, or widespread lack of awareness across the organization.
• Minor nonconformity: an isolated lapse. An example is one missing training record in an otherwise effective system.
• Opportunity for improvement: the requirement is met, but it could be done better. An example is making awareness content more engaging.
Part 4: Common Confusions to Avoid
• Competence ≠ Training. Training is one input. Competence is the demonstrated ability.
• Competence vs. Awareness. Competence applies to persons whose work affects information security performance. Awareness applies to all persons doing work under the organization's control. Awareness has three fixed topics.
• Documented information. It is mandatory for 7.2 (evidence of competence). It is not explicitly required by 7.3 or 7.4.
• Effectiveness evaluation is required only in 7.2(c). It is a frequent exam trap.
• Communication is two-way and covers internal and external parties. It is not only top-down messaging.
• Contractors and outsourced staff are within scope when they work under the organization's control.
Exam Tips: Answering Questions on Competence, Awareness and Communication
1. Memorise the exact elements.
• 7.2: Determine, Ensure, Act and evaluate effectiveness, Retain evidence. The mnemonic is D-E-A-R.
• 7.3: Policy, Contribution (and benefits), Implications of nonconformity. The mnemonic is P-C-I.
• 7.4: What, When, With whom, How. Think of it as 3 Ws and an H.
2. Identify the clause from the scenario.
• If staff cannot perform a technical task, the issue is 7.2.
• If staff do not know the policy, their role or the consequences, the issue is 7.3.
• If information did not reach the right party at the right time, the issue is 7.4.
• If training records exist but people still fail, the likely issue is 7.2(c), because effectiveness was not evaluated.
• If the topic is training programme content specifically, Annex A 6.3 may also apply.
3. Write nonconformity statements properly. Include three parts:
• Requirement: cite the clause, e.g. 'ISO/IEC 27001:2022 clause 7.2(d) requires...'
• Evidence: state facts observed, e.g. 'For 2 of 6 sampled developers, no records of secure coding competence were available.'
• Statement of nonconformity: e.g. 'The organization has not retained documented information as evidence of competence.'
Use objective, verifiable language. Avoid opinions and blame.
4. Justify the grading. Explain whether the issue is isolated (minor) or systemic, or causes doubt about the ISMS's ability to achieve its intended results (major).
5. Look for the trap of 'training done therefore compliant'. Exam scenarios often show 100% training completion while interviews reveal ignorance. The correct answer usually points to a failure to evaluate effectiveness (7.2) or to achieve awareness (7.3).
6. Remember who is in scope. If a scenario mentions contractors, temporary staff or outsourced IT, they are 'persons doing work under the organization's control'. Their competence and awareness count.
7. Know what evidence to request. For audit-planning questions, list specific evidence:
• competence matrices
• job descriptions
• CVs and certificates
• training plans and records
• effectiveness evaluations
• awareness materials and completion logs
• policy acknowledgements
• communication plans
• meeting minutes
• customer notifications
Also name the people you would interview.
8. Use interview questions as evidence-gathering tools. Good answers show open questions that test understanding. Ask 'Can you tell me how you would report a lost laptop?' rather than 'Do you know the incident procedure?'
9. Distinguish mandatory from optional documentation. If asked whether a missing awareness record is a nonconformity, the answer is that 7.3 does not explicitly require documented information. The auditor should therefore verify awareness through interviews. Only raise a finding if awareness itself is lacking, or if the organization's own procedures require such records.
10. Link to other clauses for higher marks. Strong answers connect the issue to the wider system:
• 5.3 roles
• 6.2 objectives communication
• 4.2 interested parties
• 9.2 auditor competence
• 10.2 corrective action, where root cause analysis may reveal competence gaps
11. Stay in the auditor's role. In Lead Auditor exams, do not recommend specific solutions like 'buy this training platform'. Auditors identify nonconformities. The auditee determines corrections and corrective actions.
12. Manage your time with a structure. For long scenario questions, use this sequence: Identify the clause, then state the requirement, then cite the evidence, then grade, then justify. This structure earns marks consistently.
Sample Exam Question and Model Answer
Scenario: During an audit, you find that all staff completed online security awareness training last year. When interviewed, a finance clerk could not explain how her work contributes to information security and did not know where the policy was published. The ISMS manager says the training is sufficient because completion is 100%.
Model answer:
• Requirement: ISO/IEC 27001:2022 clause 7.3 requires persons doing work under the organization's control to be aware of the information security policy and their contribution to the effectiveness of the ISMS.
• Evidence: The interviewed finance clerk was unaware of the policy location and of her contribution, despite records of training completion.
• Finding: Nonconformity against 7.3, because awareness has not been achieved for all relevant persons.
• Grading: Minor, if isolated. The auditor should extend sampling. If several staff show the same gap, it indicates a systemic failure and may be graded major.
• Additional consideration: Completion records alone do not demonstrate awareness. If the clerk's role affects information security performance, this may also link to 7.2(c), the failure to evaluate the effectiveness of training actions.
Summary
• Competence (7.2) ensures people can do their security-related jobs, backed by evidence and effectiveness checks.
• Awareness (7.3) ensures everyone knows the policy, their contribution and the consequences of not conforming.
• Communication (7.4) ensures the right information reaches the right people, internally and externally, at the right time and in the right way.
Master the exact wording, recognise the scenario triggers and write evidence-based findings. With those skills, you will handle any exam question on these clauses with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!