Support & Operation of the ISMS (Clauses 7-8)

Learn what clause 7 requires for resources, competence, awareness, communication, and documented information — and how clause 8 turns risk treatment plans into day-to-day operational reality.

Medium 55m 3 tasks

Learning Objectives

  • List the five sub-clauses of clause 7 and what each requires
  • Distinguish 'awareness' from 'competence' as clause 7 requires
  • Explain the version-control and access requirements for documented information
  • Describe what clause 8 requires in terms of executing the risk treatment plan

If clause 6 is about deciding what to do, clauses 7 and 8 are about making sure the organization is actually capable of doing it (Support) and actually doing it day to day (Operation).

Clause 7: Support

7.1 Resources

The organization must determine and provide the resources needed for the ISMS — budget, staff time, tools. This is often where a well-designed ISMS on paper collapses in practice: a risk treatment plan that requires resources nobody actually allocated is not a real plan.

7.2 Competence

People doing work that affects information security performance must be competent — based on appropriate education, training, or experience. Crucially, the standard requires you to retain evidence of competence (certificates, training records), not just assume people know what they're doing.

7.3 Awareness

This is easy to confuse with competence, but they're distinct: awareness is about all staff (not just specialists) understanding the security policy, their contribution to the ISMS, and the consequences of not conforming. A developer needs competence in secure coding; every employee, including the receptionist, needs awareness of the acceptable use policy and what to do if they suspect an incident.

7.4 Communication

The organization must determine what needs to be communicated, when, with whom, and by whom — both internally and externally. This includes, for example, deciding in advance how a data breach would be communicated to affected customers or regulators, rather than improvising during an actual incident.

7.5 Documented information

The ISMS requires documented information both explicitly required by the standard (policies, the SoA, risk assessment results) and whatever else the organization determines is necessary for the ISMS to be effective. Clause 7.5.3 specifically requires that documented information be:
- Available and suitable for use where needed
- Adequately protected (from loss of confidentiality, improper use, or loss of integrity)
- Controlled for distribution, access, retrieval, storage, and version changes

A policy with no version number, no approval date, and multiple conflicting copies floating around different drives is a classic 7.5 finding.

Clause 8: Operation

Clause 8 is deliberately short in the standard's text, but it's where clauses 6 and 7 actually get executed:

  • 8.1 Operational planning and control: implement the plans to achieve the objectives from clause 6.2, and control planned changes while reviewing the consequences of unintended changes. If you outsource any process relevant to the ISMS (e.g., a managed hosting provider), you must determine how that outsourced process is controlled — you can delegate execution, but not accountability.
  • 8.2 Information security risk assessment: perform risk assessments at planned intervals, or when significant changes occur — risk assessment from clause 6 is not a one-time exercise, it's repeated.
  • 8.3 Information security risk treatment: implement the risk treatment plan and retain documented evidence of the results.

The through-line across clauses 6-8: clause 6 plans what needs to happen and sets objectives; clause 7 makes sure the organization has the people, resources, and documentation discipline to do it; clause 8 is where it actually gets done, on a recurring basis, with evidence retained to prove it.

A company trains its developers on secure coding practices (OWASP Top 10, code review checklists) and separately sends a company-wide email reminding everyone not to click suspicious links and to report anything unusual to IT. Classify each activity as primarily addressing 'competence' (7.2) or 'awareness' (7.3), and explain the distinction in your own words.

✦ Answer the questions to complete this task

Is company-wide phishing-link reminder training an 'awareness' or 'competence' activity, and why?

An auditor finds three different versions of the same information security policy stored on three employees' personal drives, none with a version number or approval date, and no way to tell which is current. Identify which clause 7.5.3 requirement this violates and why it matters in practice.

✦ Answer the questions to complete this task

Which clause 7.5.3 control aspect is most clearly violated by having multiple unversioned, undated copies of a policy on personal drives?

A company outsources its data center hosting entirely to a cloud provider. During a certification audit, the auditor asks how the company controls this outsourced process. Explain why 'we don't need to worry about it, the cloud provider handles their own security' is an incomplete answer under clause 8.1.

✦ Answer the questions to complete this task

Under clause 8.1, why can't a company simply say 'the cloud provider handles their own security' and consider the matter closed?

💪 Exercises & Challenges

📝 MCQ Medium +20 XP

Support & Operation — MCQ

Support & Operation — MCQ

Start →
⚙️ Practical Medium +30 XP

Design a Support & Operation Checklist

Design a Support & Operation Checklist

Start →
🚩 Challenge Medium +40 XP

Find the Clause 7 Gap

Find the Clause 7 Gap

Start →