Sentrix

ISO 27001 guide · Clause 7

7.3 — Awareness

Clause 7.3 requires everyone working under the organization’s control to know the security policy, their contribution to the ISMS and what nonconformity means.

By Sentrix · Published 2026-07-16

Not training on how to do a job—awareness of why the job matters to security, and what happens when the rules are not followed.

Mandatory requirement · Documented information required: no

In plain language

7.3 requires everyone doing work under the organization’s control to know three things: what the security policy says, how their own work contributes to the ISMS actually working, and what it means—for them, personally—if they do not follow the rules.

Why this requirement exists

Most security incidents involve an ordinary employee doing something that made sense to them in the moment—clicking a link, sharing a password to help a colleague, skipping a step under deadline pressure. Awareness exists because a well-designed control that nobody understands the point of will get worked around the first time it is inconvenient.

Scenario: an employee disables a security tool that keeps flagging a legitimate business file as suspicious, because nobody ever explained why the tool matters or who to call instead of working around it. Awareness training that covers "here is the policy, here is why it exists, here is what happens if you bypass it, and here is who to contact" prevents exactly this.

What the standard expects

The standard expects persons doing work under the organization’s control to be aware of the information security policy; their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; and the implications of not conforming with ISMS requirements.

In practice

  • Run awareness for everyone with access to organizational systems or data, not just employees with "security" in their title—contractors and temporary staff included.
  • Make the content role-relevant: what developers need to know about secure coding differs from what finance needs to know about invoice fraud.
  • Refresh awareness regularly, not just at onboarding—a one-time session at hire date does not satisfy an ongoing requirement.

Evidence the auditor will ask for

  • Completion records for awareness sessions, covering all relevant staff including contractors.
  • The actual awareness content, showing it covers the policy, individual contribution, and consequences of nonconformity—not just generic cyber-hygiene tips.

Common pitfalls

  • Generic, off-the-shelf awareness content with no mention of the organization’s own policy or consequences.
  • Contractors and temporary staff excluded from awareness because they are not on the formal payroll.

Related requirements

  • 7.2 Competence—awareness is the baseline for everyone; competence is a deeper skill requirement for specific roles.
  • 7.4 Communication—ongoing communication reinforces what awareness training establishes.
  • Parent clause: Clause 7 Support.

Sources

Frequently asked questions

How is awareness different from competence (7.2)?
Awareness is a baseline everyone needs: knowing the policy exists and matters, understanding their own contribution and the consequences of not conforming. Competence (7.2) is a deeper, role-specific skill requirement for people whose work directly affects security controls, and it requires retained documented evidence.
Who has to receive awareness?
Everyone doing work under the organization’s control with access to its systems or data, not just employees with "security" in their title. Contractors and temporary staff are included; excluding them because they are not on the formal payroll is one of the most common pitfalls found at audit.
Is a single session at onboarding enough?
No. Awareness is an ongoing requirement: refresh it regularly, not just at onboarding. The auditor will ask for completion records covering all relevant staff and for the actual session content, which has to cover the policy, individual contribution, and consequences of nonconformity rather than generic cyber-hygiene tips.

Let's talk about your compliance program.

Last updated: 2026-09-17