The ultimate audit guide to ISO 27001 Clause 7.3 Awareness
Table of contents
- 1. Policy Accessibility & Communication Verified
- 2. Personal Contribution Understanding Confirmed
- 3. Knowledge of Non-Conformity Consequences Verified
- 4. Structured Awareness Programme Plan Verified
- 5. Content Relevance & Targeting Verified
- 6. Lifecycle Integration (Onboarding/Offboarding) Verified
- 7. Ongoing Communication Evidence Present
- 8. Programme Effectiveness Measured
- 9. Comprehension Testing Verified
- 10. Continual Improvement of Programme Verified
1. Policy Accessibility & Communication Verified
- Verification Criteria: The Information Security Policy is not just “stored” but actively communicated to all personnel in a way that is easily accessible (e.g., Intranet, Knowledge Base).
- Required Evidence: System logs showing policy distribution emails or Intranet analytics proving active access by staff.
Pass/Fail Test: If an employee is asked “Where is the security policy?” and cannot locate it within 30 seconds, mark as Non-Compliant.
2. Personal Contribution Understanding Confirmed
- Verification Criteria: Employees can articulate how their specific daily role contributes to the effectiveness of the ISMS (e.g., “I verify invoices to prevent fraud”).
- Required Evidence: Interview notes from random staff sampling (3-5 employees) linking job descriptions to security responsibilities.
Pass/Fail Test: If staff view security solely as “IT’s job” and cannot name one security responsibility they personally hold, mark as Non-Compliant.
3. Knowledge of Non-Conformity Consequences Verified
- Verification Criteria: Staff are aware of the specific disciplinary actions or business risks that result from failing to follow security rules.
- Required Evidence: The “Sanctions” or “Disciplinary Policy” section in the Employee Handbook, signed by the employee.
Pass/Fail Test: If an employee believes there are no formal consequences for sharing their password, mark as Non-Compliant.
4. Structured Awareness Programme Plan Verified
- Verification Criteria: A formal, scheduled “Awareness Plan” exists that outlines activities throughout the year, rather than ad-hoc, reactive emails.
- Required Evidence: The “Annual Awareness Schedule” document showing planned dates for phishing tests, newsletters, and training modules.
Pass/Fail Test: If the only evidence of awareness is the initial induction training with no follow-up scheduled, mark as Non-Compliant.
5. Content Relevance & Targeting Verified
- Verification Criteria: Awareness content is tailored to the audience (e.g., Developers get secure coding training; HR gets PII handling training).
- Required Evidence: Training matrices showing different content assigned to “High Risk” vs. “General” staff roles.
Pass/Fail Test: If the Finance team and the Cleaning staff receive the exact same generic technical training, mark as Non-Compliant.
6. Lifecycle Integration (Onboarding/Offboarding) Verified
- Verification Criteria: Security awareness is embedded into the HR lifecycle, from day-one induction to exit interviews.
- Required Evidence: Onboarding checklists showing “Security Training” as a mandatory gate before full system access is granted.
Pass/Fail Test: If a new starter has access to sensitive data before completing their security induction, mark as Non-Compliant.
7. Ongoing Communication Evidence Present
- Verification Criteria: Security messaging is integrated into regular business communications (newsletters, Town Halls) and is not silent for months at a time.
- Required Evidence: Copies of the last 3 internal newsletters or All-Hands meeting agendas featuring a security update.
Pass/Fail Test: If the last communication regarding security is dated older than 3 months, mark as Non-Compliant.
8. Programme Effectiveness Measured
- Verification Criteria: The organisation measures behaviour change (e.g., click rates on phishing sims), not just “attendance” or “completion.”
- Required Evidence: Phishing simulation reports showing a trend line of improved reporting rates or reduced click rates over time.
Pass/Fail Test: If you have 100% training completion but phishing click rates are increasing, mark effectiveness as Non-Compliant.
9. Comprehension Testing Verified
- Verification Criteria: Staff are tested on their understanding of the training material via quizzes or practical assessments.
- Required Evidence: LMS (Learning Management System) reports showing quiz scores (e.g., “Pass mark 80% required”).
Pass/Fail Test: If the training allows users to click “Next” without any knowledge check or quiz, mark as Non-Compliant.
10. Continual Improvement of Programme Verified
- Verification Criteria: The awareness programme is updated based on feedback, new threats, or incidents.
- Required Evidence: Management Review minutes discussing awareness metrics and authorising updates to the content.
Pass/Fail Test: If the training slides have not been updated in 2 years despite new threat landscapes (e.g., AI risks), mark as Non-Compliant.