ISO27K

ISO 27001 clause 7: support and document control

Clause 7 is five requirements and almost none of them can be satisfied retroactively. Competence, awareness and document control all leave dated records, and a record that was never made on the day is a finding you cannot argue your way out of.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Clause 7 of ISO/IEC 27001:2022 carries five requirements: 7.1 resources, 7.2 competence, 7.3 awareness, 7.4 communication and 7.5 documented information. Together with clause 6 it accounts for ten of the 25 mandatory requirements, and it is where evidence is sampled per person rather than per system. An auditor picks five employees from your list, asks for the training record, the acknowledgement and the competence evidence for each, and one gap in five is enough to write a finding.

What clause 7.5 actually requires of a document

Clause 7.5 breaks into three parts and only the third is difficult. 7.5.1 says you keep the documented information the standard requires plus whatever you determine is necessary. 7.5.2 says documents get identified, described, formatted and approved. 7.5.3 is the control regime, and it is a longer list than most people build for.

Clause 7.5 document control obligations and how they get failed
RequirementWhat it means in practiceHow it fails at stage 2
Identification and descriptionTitle, date, author or owner, and a reference or versionA policy in a shared drive with no version and a last-modified date of two years ago
Review and approvalSomeone with authority approved it, and you can show who and whenApproval by email that nobody kept, or a document approved by the person who wrote it
Available and suitable for use where neededThe people who have to follow it can find it without askingThe incident response plan is in a folder only the security lead can open
Adequately protectedAgainst loss of confidentiality, improper use and loss of integrityEverything world-readable inside the company, including the pen test report
Distribution, access, retrieval and useA stated access model, not just permissions that grewNo answer to who is allowed to change the risk register
Storage and preservation, including legibilityIt survives, and it can still be openedRecords in a tool the company stopped paying for
Control of changes, including version controlVersion history, so you can show what applied last MarchOverwriting the file. Common, and it makes historical sampling impossible
Retention and dispositionA stated retention period per record typeNo retention schedule, which also creates a privacy exposure
Control of external documentsDocuments from outside that you rely on are identified and controlledNobody controls the copy of ISO 27002, the cloud provider's shared responsibility model or a client's security schedule

The last row is the one nearly every first-time project misses. Clause 7.5.3 explicitly covers documented information of external origin determined to be necessary. If your operating procedure depends on a vendor's hardening guide, that guide is an external document and it needs to be identified, its version tracked, and someone made responsible for noticing when it changes.

Which documents are actually mandatory

Fewer than most template packs sell. The standard names a specific set of documented information across the clauses, and everything beyond it is whatever you determined necessary under 7.5.1. Work through this list before buying a template pack, because the pack will typically contain forty documents and the requirement is closer to fifteen.

0 of 0 in place ยท

Annex A controls you declared applicable will add their own documents, which is where the access control policy, the supplier policy and the incident procedure come from. The full treatment of the required set, including what a certification body asks to see before stage 1, is on the documentation page.

Competence, and why it is not the same as training

Clause 7.2 asks four things: determine the competence necessary for people whose work affects information security performance, ensure they are competent on the basis of education, training or experience, take action where they are not, and retain documented information as evidence. The word evidence is doing the work. Competence is a conclusion you reached about a person, and the record has to show the basis.

Competence, clause 7.2
Role-specific. Why is this person qualified to run the internal audit, own the risk register, or administer production access. Evidenced by a certification, a qualification, a prior role, or a documented assessment.
Awareness, clause 7.3
Everyone. They know the policy exists, they know how their work contributes, and they know what happens if they do not conform. Evidenced by training completion with a date and a name.
The distinction auditors test
A company with 100 percent security awareness training completion and no competence evidence for the three named ISMS roles has satisfied 7.3 and failed 7.2. That is a common and avoidable finding.

Awareness training does not have to be a purchased platform. An annual session with a slide deck, an attendance list and a short quiz satisfies the clause. What it does have to be is repeated, dated, and extended to contractors and to anyone else doing work under your control, which is the phrase in 7.3 that catches companies who trained employees and skipped the six long-term contractors in the delivery team.

Clause 7.4 in one table

The shortest requirement in the standard and the one most often satisfied with a document written the week before the audit. It asks what you communicate, when, with whom and how. Half a page is enough, provided it is true.

A clause 7.4 communication plan that survives an audit
WhatWhenWith whomHow
Security policy and changes to itOn hire and on changeAll staff and contractorsOnboarding, plus a notice with acknowledgement
ISMS performanceQuarterlyTop managementManagement review pack
Incidents affecting customer dataWithin the contractual windowAffected customersNamed contact, written notice
Privacy breach of real risk of significant harmAs soon as feasibleThe Office of the Privacy Commissioner and affected individualsWritten report under PIPEDA, or the provincial equivalent
Security requirementsAt contracting and at reviewSuppliersSecurity schedule in the agreement
Certificate status and scopeOn requestProspects and customersCertificate copy with the scope statement

Clause 7.1 and what counts as adequate

One sentence in the standard: determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the management system. It is judged by outcome. If the internal audit is late, the access reviews are three quarters behind and the risk register was last touched eleven months ago, the auditor concludes resources were not adequate regardless of what the budget said.

For a Canadian company under 100 staff, adequate usually means one part-time internal owner with real time allocated, plus purchased help at the two points where independence is required: the internal audit at $6,000 to $15,000 CAD a year, and the certification body itself. Where there is no internal owner at all, the honest options are to hire, to retain a fractional security lead, or to accept that the management system will decay between audits and the surveillance visit will find it.

Where clause 7 is worth less than it costs

The counter-case. Two parts of clause 7 attract spending far out of proportion to the finding they prevent. The first is document management tooling. A dedicated compliance platform at $8,000 to $30,000 CAD a year solves document control, and so does a version-controlled repository you already pay for, with an approval step and a retention note. If the platform is being bought mainly for 7.5, it is an expensive answer to a solved problem, and the cost page puts the platform line in context against the rest of the budget.

The second is training content. There is a large market in security awareness subscriptions and clause 7.3 asks for three things a person needs to be aware of. A twenty-person company running one live session a year with an attendance sheet is compliant and is often better attended than a purchased module. Buy the subscription when phishing simulation is genuinely part of your control set, not to satisfy this clause.

The order that avoids rework

  1. Decide where documents live before you write any. Moving forty documents later destroys the version history that clause 7.5.3 asked for.
  2. Set the approval route and the retention schedule at the same time, in one short document control procedure.
  3. Write the competence requirements for the named ISMS roles before you appoint anyone, so the evidence is gathered rather than reconstructed.
  4. Start awareness training immediately, even before the policies are finished, because the clock on dated evidence starts the day you run it.
  5. Write the communication plan last, from what actually happens, rather than first, from what you intend.

Clause 7 evidence accumulates over calendar time, which is the same constraint that governs the whole project. The implementation timeline shows where it sits, and the readiness page covers how to tell whether you have enough of it yet.

Get the clause 7 evidence reviewed

Tell us what you have built and we will match you with Canadian firms who will tell you what an auditor will sample and what is missing.

Get matched

Common questions

How many documents does ISO 27001 actually require?

The clauses name about fifteen pieces of documented information, including the scope, the policy, the risk assessment and treatment processes, the Statement of Applicability, the objectives and the records from clauses 8, 9 and 10. Applicable Annex A controls add more. Template packs commonly contain forty or more documents, and the difference is material rather than mandatory.

Do contractors need security awareness training?

Yes, if they do work under your control that is within scope. Clause 7.3 applies to persons doing work under the organization's control rather than to employees specifically. Long-term contractors in an in-scope delivery team are the group most often missed, and they are the group an auditor is most likely to sample once they see them on the org chart.

Can we use Google Drive or SharePoint for document control?

Yes. Clause 7.5 does not require a compliance platform. It requires identification, approval, availability, protection, version control, retention and control of external documents. A shared drive with a naming convention, an approval record, restricted permissions and version history satisfies all of that. What fails is a shared drive where files are overwritten and nobody can show what applied six months ago.

What retention period should we set for ISMS records?

Long enough to cover the certification cycle, so three years as a floor, and longer where a contract or a statute says so. The practical reason for three years is that a recertification auditor may sample across the whole cycle. Set it in a short retention schedule, apply it consistently, and note that a retention period you never enforce is worse than a longer one you do.

How does an auditor test awareness?

By asking people. A stage 2 auditor will speak to staff who are not on the project team and ask what the security policy says, what they would do if they received a suspicious email, and who they would report an incident to. Completion records prove the training happened. The interview proves whether it worked, and the second is the one that produces findings.

Is a competence matrix mandatory?

No specific format is required. Clause 7.2 requires that you determined the necessary competence, ensured it, and retained evidence. A one-page table listing each ISMS role, the competence required and the basis on which the current holder meets it is the simplest way to show all three at once, which is why it is the common shape rather than the required one.