ISO 27001:2022 Requirements: Clause 7.3 Awareness
Read the requirements of ISO 27001 Clause 7.3: Awareness, which builds on the information security policy detailed in clause 5.2 to ensure ISMS awareness for interested parties.

Awareness can be linked to competence in the standard, as a person cannot be competent if they are not aware of their ISMS roles and responsibilities. As per the standard, any person working in the organisation must be aware of the information security policy that is in force at the time, as per clause 5.2.
Senior leadership must, therefore, ensure that they communicate clearly and regularly with all relevant interested parties. It is also vital that the senior leadership of an organisation communicate any changes to the information security policy, or update the interested parties if a new policy is implemented.
Individuals should know what and how much they are contributing to the effectiveness of the ISMS and what this improved efficiency will bring to the information security performance, in line with the ISO 27001 focus on continual improvement.
{{snapshot}}
Operational checklist in brief
- Awareness can be linked to competence in the standard, as a person cannot be competent if they are not aware of their ISMS roles and responsibilities.
- As per the standard, any person working in the organisation must be aware of the information security policy that is in force at the time, as per clause 5.2 .
- Senior leadership must, therefore, ensure that they communicate clearly and regularly with all relevant interested parties.
- It is also vital that the senior leadership of an organisation communicate any changes to the information security policy, or update the interested parties if a new policy is implemented.
{{/snapshot}}
{{snapshot}}
Operational checklist in brief
- Awareness can be linked to competence in the standard, as a person cannot be competent if they are not aware of their ISMS roles and responsibilities.
- As per the standard, any person working in the organisation must be aware of the information security policy that is in force at the time, as per clause 5.2 .
- Senior leadership must, therefore, ensure that they communicate clearly and regularly with all relevant interested parties.
{{/snapshot}}
Anyone working under the organisation's control must also be aware of the consequences if they are not conforming to the ISMS requirements.
| Point | What it requires |
|---|---|
| Point 1 | Awareness can be linked to competence in the standard, as a person cannot be competent if they are not aware of their ISMS roles and responsibilities. |
| Point 2 | Senior leadership must, therefore, ensure that they communicate clearly and regularly with all relevant interested parties. |
| Point 3 | Individuals should know what and how much they are contributing to the effectiveness of the ISMS and what this improved efficiency will bring to the information security performance, in line with the ISO 27001 focus on continual improvement. |
| Point 4 | Anyone working under the organisation's control must also be aware of the consequences if they are not conforming to the ISMS requirements. |
{{snapshot}}
From the Hicomply team
In our experience, Clause 7.3 Awareness works best when it is maintained as living evidence inside the ISMS, not recreated before each audit. Keep ownership, approvals, and version history clear, then use automation to reuse the same evidence across ISO 27001 and related frameworks. See how that works in a platform tour.
{{/snapshot}}
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.




