Clause 7.3 Awareness
Clause 7.3 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Awareness. People working under the organization's control need to know about the information security policy, the part they play in making the ISMS effective (including what better security performance brings), and what follows from not conforming with ISMS requirements.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 7.3 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 7), in our words, not a statement of the standard and not binding on an assessor.
- An awareness programme covering the policy, individual contribution and consequences of non-conformity
- Completion records and knowledge checks
- Interview evidence that staff can describe the policy and their role
- Coverage of contractors and temporary staff