The ultimate audit guide to ISO 27001 Clause 7.1 Resources
Table of contents
- 1. Resource Identification Process Verified
- 2. Competence & Skills Matrix Validated
- 3. Infrastructure Capacity Provision Confirmed
- 4. Financial Budget Allocation Verified
- 5. Top Management Support Evidence Present
- 6. Resource Maintenance & Upkeep Verified
- 7. Outsourced Resource Management Verified
- 8. Documentation of Resource Allocation
- 9. Regular Resource Adequacy Review Confirmed
- 10. Continual Improvement of Resource Use Verified
1. Resource Identification Process Verified
- Verification Criteria: A documented methodology exists to identify the resources (financial, human, technical) required to implement and maintain the ISMS based on risk.
- Required Evidence: Management Review minutes or a Business Case document where resource needs were explicitly discussed and defined.
Pass/Fail Test: If the organization cannot show how they calculated the security budget (e.g., it was just “copied from last year”), mark as Non-Compliant.
2. Competence & Skills Matrix Validated
- Verification Criteria: The organization has determined the necessary competence for people doing work under its control and verified they possess these skills.
- Required Evidence: A “Skills Matrix” or “Competency Framework” mapping ISMS roles (e.g., CISO, Admin) to required certifications or experience.
Pass/Fail Test: If the “Security Manager” role requires a CISM certification but the current holder has no qualifications or relevant experience, mark as Non-Compliant.
3. Infrastructure Capacity Provision Confirmed
- Verification Criteria: Adequate infrastructure (servers, networks, secure facilities) is provided to support the ISMS objectives.
- Required Evidence: Capacity planning reports or infrastructure purchase orders showing investment in required hardware/software.
Pass/Fail Test: If the security team complains of “server lag” preventing log analysis and no budget request was approved to fix it, mark as Non-Compliant.
4. Financial Budget Allocation Verified
- Verification Criteria: A dedicated budget for information security is formally approved and is sufficient to cover identified risks.
- Required Evidence: The approved Annual Budget showing specific line items for “Information Security” (tools, training, audits).
Pass/Fail Test: If the CISO has a risk treatment plan requiring a $50k firewall but the approved budget is $0, mark as Non-Compliant.
5. Top Management Support Evidence Present
- Verification Criteria: Senior management actively demonstrates support by providing the requested resources rather than just signing a policy.
- Required Evidence: Email correspondence or meeting minutes where Leadership approves a resource request to address a non-conformity.
Pass/Fail Test: If a critical resource gap (e.g., lack of staff) has been raised in Management Reviews for 2 years with no action, mark as Non-Compliant.
6. Resource Maintenance & Upkeep Verified
- Verification Criteria: Resources are maintained over time (e.g., software subscriptions renewed, hardware refreshed), not just purchased once.
- Required Evidence: Asset lifecycle logs or a “Renewals Calendar” showing active maintenance contracts for security tools.
Pass/Fail Test: If the core SIEM tool license expired 3 months ago and hasn’t been renewed due to “lack of funds,” mark as Non-Compliant.
7. Outsourced Resource Management Verified
- Verification Criteria: Where resources are outsourced (e.g., MSSP, Consultants), the organization retains control and monitors their performance.
- Required Evidence: Service Level Agreements (SLAs) and monthly performance review meetings with third-party providers.
Pass/Fail Test: If the organization relies entirely on an external MSP but has never audited their performance or checked if they are delivering, mark as Non-Compliant.
8. Documentation of Resource Allocation
- Verification Criteria: The allocation of resources is recorded (e.g., who is responsible for what), ensuring no ambiguity in duties.
- Required Evidence: An “Accountability Matrix” (RACI) or Organizational Chart with clear security reporting lines.
Pass/Fail Test: If the Incident Response plan lists “Security Analyst” as the lead, but no one in the company actually holds that job title, mark as Non-Compliant.
9. Regular Resource Adequacy Review Confirmed
- Verification Criteria: The sufficiency of resources is reviewed at planned intervals (at least annually) during Management Review.
- Required Evidence: Minutes from the Annual Management Review meeting specifically answering the agenda item: “Are resources adequate?”
Pass/Fail Test: If the meeting minutes are silent on resources or simply say “Yes” without data to back it up, mark as Non-Compliant.
10. Continual Improvement of Resource Use Verified
- Verification Criteria: The organization looks for ways to optimize resource use (e.g., automation) to improve ISMS efficiency.
- Required Evidence: Project plans showing automation of manual tasks (e.g., automated patching) to free up human resources.
Pass/Fail Test: If the security team is drowning in manual log reviews and management has rejected all requests for automation tools, mark as Non-Compliant.