ISO 27001:2022 Clause 7.3 Awareness Explained

ISO 27001 Clause 7.3 Awareness Certification Guide

In this guide you will learn how to implement ISO 27001 Clause 7.3 Awareness and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

Purpose and Definition

The purpose of ISO 27001 clause 7.3 Awareness is to make sure people are aware of information security and what they need to do. It is part of implementing a culture of information security into the organisation.

The ISO 27001 standard defines ISO 27001 clause 7.3 Awareness as:

Persons doing work under the organisation’s control shall be aware of: a) the information security policy; b) their contribution to the effectiveness of the information security management system, including the benefits of improved information security performance; and c) the implications of not conforming with the information security management system requirements.

ISO 27001:2022 Clause 7.3 Awareness
Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

FREE ISO 27001 Clause 7.3 Training Video

What is ISO 27001 Clause 7.3?

ISO 27001 Clause 7.3 is a security control that mandates personnel doing work under the organization’s control remain aware of the information security policy and their role. The primary implementation requirement involves structured communication and verified training to ensure a robust business benefit of human-centric risk mitigation.

ISO 27001 Clause 7.3 is awareness and requires you to communicate and make people aware of the information security policy, how they contribute to information security and the consequences of not conforming to information security.

The ISO 27001 standard for ISO 27001 certification wants you to let people know what you expect, educate them and have processes in place for if things go wrong.

Requirement

The requirement is to tell people what is expected of them and explain to them the consequences of not doing what is expected when it comes to information security.

ISO 27001 Toolkit Business Edition

Implementation Guide

There are distinct phases in the journey of staff, contractors and third parties.

Each of those phases potentially requires a different level of communication.

It is possible that one approach will work but the likelihood is you are going to have different communication styles and approaches depending on the ‘who’ and the ‘where’ they are in their journey with you.

Implementing ISO 27001 Clause 7.3 requires a transition from passive information delivery to a proactive culture of security accountability. By aligning awareness activities with specific risk profiles and technical controls, you ensure that every individual understands their role in protecting the Information Security Management System (ISMS).

How to implement ISO 27001 Clause 7.3

Define Objectives and Formalise Policy

Provision clear, measurable goals for your awareness programme that align with the broader ISMS objectives and results from your latest risk assessment.

  • Formalise an Information Security Training and Awareness Policy to set expectations for staff, auditors, and clients.
  • Conduct workshops across departments to identify specific awareness needs based on functional roles and responsibilities.
  • Establish Key Performance Indicators (KPIs) to track success, such as a targeted percentage reduction in successful simulated phishing clicks.

Identify Target Audiences and Role-Based Requirements

Categorise all personnel, including contractors and third-party stakeholders, to deliver tailored security content relevant to their specific access levels.

  • Audit the Asset Register and IAM roles to identify high-risk groups, such as System Administrators or Finance teams.
  • Provision specialised training for technical staff covering secure configuration, log monitoring, and incident response.
  • Formalise requirements for “interested parties” and contractors, ensuring they are aware of the Rules of Engagement (ROE) and Non-Disclosure Agreements (NDAs).

Develop and Distribute High-Impact Content

Formalise a diverse suite of awareness materials that communicate the Information Security Policy and the personal consequences of non-conformity.

  • Provision accessible versions of the Information Security Policy, highlighting sections on Acceptable Use, Home Working, and Multi-Factor Authentication (MFA) protocols.
  • Create engaging, jargon-free content using gamification, micro-learning modules, and real-world scenarios to increase retention.
  • Utilise various channels, such as internal newsletters, posters, and digital prompts, to ensure continuous engagement throughout the year.

Execute Lifecycle-Based Training

Provision mandatory security training at every stage of the employee lifecycle, from initial onboarding to final offboarding.

  • Execute a dedicated face-to-face induction session for new starters covering incident reporting, policy locations, and their specific contribution to security.
  • Provision annual refresher courses for general security and Data Protection (GDPR) to maintain a baseline level of vigilance across the workforce.
  • Communicate contractual obligations and remaining security requirements during the offboarding process for ending employment or engagements.

Provision Technical Training Tools and Automation

Implement a dedicated information security training tool to automate scheduling, verify understanding, and generate compliance reports.

  • Provision an online platform to deliver pre-built, annually refreshed content that staff can access from any location.
  • Execute simulated threat exercises, such as mock phishing campaigns, to test real-world behavioural responses.
  • Audit training completion logs and verification results automatically to ensure 100% participation across all departments.

Audit Effectiveness and Promote Culture

Audit the effectiveness of your awareness initiatives by measuring behavioural changes and fostering a culture of collective responsibility.

  • Document all awareness activities, including attendance logs and evaluation results, within a centralised system for ISO 27001 audit readiness.
  • Review incident logs to determine if training has led to an increase in proactive security event reporting and a decrease in human-error risks.
  • Revoke or update outdated training materials based on emerging threats, industry trends, and lessons learned from internal security incidents.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Clause 7.3 Awareness Templates

For ISO 27001 Clause 7.3 Awareness the entire ISO 27001 toolkit is relevant but in particular the following templates directly support this ISO 27001 clause:

ISO 27001 Training and Awareness Policy Template

The ISO 27001 Training and Awareness Policy template sets out what you do and what must be done For ISO 27001 clause 7.3.

ISO27001 Training and Awareness Policy-Black

ISO 27001 Communication Plan Template

The ISO 27001 Communication Plan Template is used to plan communications on information security including training and awareness for the year ahead and to record evidence that those communications happened which will be required at the ISO 27001 certification audit.

ISO27001 Communication Plan Template

How to use an Awareness and Training tool

In this day and age, one of the few times we would recommend using a tool is for information security training. These tools come with pre-built courses and allow for the automation of many required awareness tasks. Scheduling awareness training, verifying understanding, and reporting capabilities are must-haves. These tools refresh content annually, saving you time and effort, and include popular modules on relevant topics. Being online, they can be accessed by staff from anywhere. While not the only way to raise and manage awareness, they do the lion’s share of the work.

Of course, you should consider your company culture and supplement the training accordingly. Emails are useful, as are stand-up meetings, presentations at company meetings, and perhaps bringing in external resources. There’s no one-size-fits-all answer, but training tools go a long way for those who are time-poor and simply want to get the job done efficiently.

How to pass the ISO 27001 Clause 7.3 audit

The easiest way is to have a training tool that records people’s understanding by presenting with training and what you want them to be aware of and then has them take a test which you can report.

Having a communication plan that records what you communicated, when, to whom and the evidence that you did is also part of showing compliance to the clause.

There is a place for the signing of policies to accept them and the way you do this can be via traditional signature (which is clunky but doable), electronic signature, or an email to you that they have read and accept them. There are many ways to skin a cat.

ISO 27001 Clause 7.3 FAQ

What is ISO 27001 Clause 7.3 Awareness?

ISO 27001 Clause 7.3, titled “Awareness,” requires an organisation to ensure that all persons doing work under its control are aware of specific information security aspects. This isn’t just about providing training; it’s about embedding a security-conscious culture within the organisation.

What are the ISO 27001:2022 Changes to Clause 7.3 Awareness?

Great news. There are no changes to ISO 27001 Clause 7.3 in the 2022 update. The requirements for awareness remain consistent with the previous version of the standard.

Who needs to be aware according to Clause 7.3?

The standard states that “persons doing work under the organisation’s control” must be aware. This includes more than just full-time employees. It extends to contractors, temporary staff, and volunteers who have access to the organisation’s information and assets within the ISMS scope.

What specific topics must people be aware of?

According to the standard, individuals must be aware of: The information security policy of the organisation. Their contribution to the effectiveness of the ISMS, including the benefits of improved security performance. The implications of not conforming with the ISMS requirements.

How can an organisation demonstrate compliance with Clause 7.3?

Compliance is demonstrated through documented evidence of awareness activities. This isn’t about creating a single document, but rather showing a structured, ongoing programme. Examples include: Training attendance records (e.g., sign-in sheets, e-learning completion logs). Records of communications like emails, newsletters, and posters. Results from awareness quizzes or assessments. Minutes from meetings where security topics were discussed.

Who is responsible for ISO 27001 Awareness?

While the Information Security Officer (ISO) or a similar role is typically responsible for planning and overseeing the awareness programme, implementing it is a shared responsibility. The standard emphasises that it’s everyone’s duty to contribute to the effectiveness of the ISMS. Top management must also show commitment to the programme.

Is one-time training enough to meet the requirements of Clause 7.3?

No, one-time training is generally not sufficient. The standard implies an ongoing process. Threats and risks evolve, and so must awareness. An effective programme includes initial training for new hires, periodic refresher training for all staff, and continuous communication to keep security top-of-mind.

What’s the difference between “competence” (Clause 7.2) and “awareness” (Clause 7.3)?

Competence (Clause 7.2) is about having the necessary knowledge and skills to perform a specific job function. Awareness (Clause 7.3) is a more general requirement for everyone to understand their role in protecting information, regardless of their specific technical competence. You can think of competence as specialised knowledge, while awareness is universal knowledge.

Can ISO 27001 Clause 7.3 be met through simple emails or posters?

While emails, newsletters, and posters can be excellent tools for continuous communication, they are generally not enough on their own. Auditors look for a structured programme that demonstrates that the organisation is actively trying to make people aware. A combination of formal training, documented communication, and interactive methods is a more robust approach.

How do you measure the effectiveness of an awareness programme?

Measuring effectiveness goes beyond simply checking a box. It involves assessing whether the awareness programme actually changes behaviour. Methods include: Conducting mock phishing exercises to test if employees can spot and report suspicious emails. Analysing IT help desk tickets to see if the number of reported security incidents changes over time. Using surveys or quizzes to gauge understanding of key security policies.

Why is ISO 27001 Awareness important?

It’s a fundamental part of a successful Information Security Management System (ISMS), requiring an organisation to ensure that everyone under its control is aware of the information security policy, their contribution to the ISMS, and the consequences of not conforming. This clause is a key differentiator, as a strong security posture isn’t just about technology, but also about the people using it.

What are the consequences of not meeting the requirements of Clause 7.3?

Failing to meet Clause 7.3 can lead to a nonconformity during an ISO 27001 audit, which could prevent the organisation from achieving or maintaining its certification. More importantly, it creates a significant security risk. A workforce that isn’t aware of its security responsibilities is more likely to fall victim to social engineering attacks, phishing scams, or accidental data breaches.

Further Reading

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top