ISO 27001 guide · Clause 7
7.1 — Resources
Clause 7.1 requires you to determine what the ISMS needs to be built, run and improved—people, budget, tools, time—and then to actually provide those resources.
By Sentrix · Published 2026-07-16
A one-sentence requirement that a surprising number of ISMS projects quietly fail—because the plan was solid but nobody actually funded it.
Mandatory requirement · Documented information required: no
In plain language
7.1 requires you to figure out what the ISMS actually needs to be built, run, maintained, and continually improved—people, budget, tools, time—and then provide it, not just acknowledge that it would be nice to have.
Why this requirement exists
A risk treatment plan with no budget behind it is a wish list. This requirement exists because it is easy to build an ISMS that looks complete on paper while starving it of the actual time and money needed to keep it running—and an auditor who sees resourcing gaps will expect to see them show up as unclosed risks and stale documentation elsewhere in the file.
Scenario: a company assigns ISMS ownership to an IT manager as a side responsibility, with no dedicated hours and no tooling budget. Risk assessments slip, the SoA goes stale, and internal audits get postponed indefinitely—not because anyone lacks knowledge, but because nobody was ever actually resourced to do the work.
What the standard expects
The standard expects the organization to determine and provide the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS. It does not specify what those resources are or how much is enough—that is left to the organization’s own context and risk appetite, but the determination and provision both have to be deliberate and traceable.
In practice
- Name an ISMS owner with dedicated time allocated for the role, not just a title added to an already full job description.
- Attach a budget line to the ISMS covering tooling, training, and any external support (audits, consulting) it needs.
- Revisit resourcing whenever scope or risk changes significantly—a resourcing decision made at certification does not automatically stay adequate.
Evidence the auditor will ask for
- An approved budget or resource plan covering the ISMS.
- A named ISMS owner with a defined allocation of time for the role.
- Evidence that resourcing gaps flagged in risk assessments or audits were actually addressed, not just noted.
Common pitfalls
- Treating the ISMS as an unfunded side project layered on top of someone’s existing job.
- A resourcing decision that was adequate at certification but never revisited as the organization grew.
Related requirements
- 7.2 Competence—resources include making sure the right people have the right skills.
- Clause 6 Planning—resourcing decisions should trace back to the risk treatment plan and objectives set here.
- Parent clause: Clause 7 Support.
Sources
Frequently asked questions
- Does 7.1 require a dedicated full-time security role?
- No. The standard scales to the organization. A small company may satisfy this with a part-time allocation, as long as it is deliberate, sufficient for the ISMS scope, and documented. What fails at audit is the title added to an already full job description, with no dedicated hours and no tooling budget behind it.
- What evidence will the auditor ask for under 7.1?
- An approved budget or resource plan covering the ISMS, a named ISMS owner with a defined allocation of time for the role, and evidence that resourcing gaps flagged in risk assessments or audits were actually addressed rather than just noted. No standalone mandatory document is required: these records often live in budget approvals.
- Does the resourcing decided at certification stay adequate?
- Not automatically. The standard expects the determination and provision of resources to be deliberate and traceable, which means revisiting them whenever scope or risk changes significantly. A resourcing decision that was adequate at certification but never revisited as the organization grew is one of the most common pitfalls.
Related pages
ISO 27001 guide · Clause 7
Clause 7 — Support
Resources, competence, awareness, communication and documented information: clause 7 provides the scaffolding that keeps the ISMS running day to day.
ISO 27001 guide · Clause 7
7.2 — Competence
Clause 7.2 requires you to define the skills needed for work that affects security, confirm people have them, close any gaps and keep evidence of all of it.
ISO 27001 guide · Plan
Clause 6 — Planning
ISO 27001:2022 clause 6 covers risk assessment and treatment, the Statement of Applicability (SoA) and measurable security objectives, explained in plain terms.
Let's talk about your compliance program.
Last updated: 2026-09-17
