ISO 27001 guide · Clause 7
7.4 — Communication
Clause 7.4 requires you to decide in advance what to communicate about the ISMS, to whom, when, how and by whom, for internal and external audiences alike.
By Sentrix · Published 2026-07-16
Security incidents are rarely made worse by too much communication. They are made worse by nobody having decided in advance who needed to know what.
Mandatory requirement · Documented information required: no
In plain language
7.4 requires you to decide, in advance, what you need to communicate about the ISMS, to whom, when, and how—covering both internal audiences (staff, leadership) and external ones (customers, regulators, certification bodies)—rather than improvising communication in the moment.
Why this requirement exists
When an incident or a significant ISMS change happens, the worst time to figure out who needs to be told is in the middle of it. This requirement forces that planning to happen ahead of time, so a breach notification, a policy update, or a scope change follows a known path instead of an improvised one.
Scenario: a data incident occurs and the response team spends the first critical hours debating who should be told—legal, affected customers, a regulator, the board—instead of executing a plan. A defined communication plan, decided calmly before any incident, would have made those calls automatic.
What the standard expects
The standard expects the organization to determine the need for internal and external communications relevant to the ISMS, including what to communicate, when to communicate, with whom to communicate, who communicates, and the processes by which communication is effected.
In practice
- Build a short communication matrix: trigger event, audience, channel, timing, and owner—for both routine updates and incident scenarios.
- Cover external obligations explicitly—breach notification timelines to regulators or customers are often legally mandated and time-sensitive.
- Keep the plan short enough that people actually remember it exists—a communication plan nobody can find in a crisis does not help.
Evidence the auditor will ask for
- A documented communication plan or matrix covering internal and external audiences.
- Examples of the plan being followed—a policy update actually communicated, an incident notification actually sent per the defined process.
Common pitfalls
- A communication plan that covers internal staff updates but says nothing about external notification obligations.
- No named owner for a given communication—everyone assumes someone else will send it.
Related requirements
- 7.3 Awareness—awareness is what makes ongoing communication land with staff who already understand the context.
- 7.5 Documented information—the communication plan itself is typically kept as documented information.
- Parent clause: Clause 7 Support.
Sources
Frequently asked questions
- Does the communication plan need to be a standalone document?
- Not necessarily. It can live inside your incident response plan or a broader policy, as long as the what, when, who, and how are clearly addressed somewhere an auditor can find. A short matrix—trigger event, audience, channel, timing, and owner—is often enough, provided people actually remember it exists.
- Does the plan have to cover external audiences?
- Yes. The standard covers internal and external communications relevant to the ISMS: staff and leadership on one side, customers, regulators, and certification bodies on the other. Breach notification timelines to regulators or customers are often legally mandated and time-sensitive; a plan that says nothing about those obligations is a common pitfall.
- What evidence will the auditor ask for under 7.4?
- A documented communication plan or matrix covering internal and external audiences, then examples showing the plan is actually followed: a policy update communicated, an incident notification sent per the defined process. The auditor will also check that a named owner exists for each communication, otherwise everyone assumes someone else will send it.
Related pages
ISO 27001 guide · Clause 7
Clause 7 — Support
Resources, competence, awareness, communication and documented information: clause 7 provides the scaffolding that keeps the ISMS running day to day.
ISO 27001 guide · Clause 7
7.3 — Awareness
Clause 7.3 requires everyone working under the organization’s control to know the security policy, their contribution to the ISMS and what nonconformity means.
ISO 27001 guide · Clause 7
7.5 — Documented information
Clause 7.5 requires you to know what documented information the ISMS needs, to create and approve it consistently, and then to control it throughout its life.
Let's talk about your compliance program.
Last updated: 2026-09-17
