Sentrix

ISO 27001 guide · Clause 7

7.4 — Communication

Clause 7.4 requires you to decide in advance what to communicate about the ISMS, to whom, when, how and by whom, for internal and external audiences alike.

By Sentrix · Published 2026-07-16

Security incidents are rarely made worse by too much communication. They are made worse by nobody having decided in advance who needed to know what.

Mandatory requirement · Documented information required: no

In plain language

7.4 requires you to decide, in advance, what you need to communicate about the ISMS, to whom, when, and how—covering both internal audiences (staff, leadership) and external ones (customers, regulators, certification bodies)—rather than improvising communication in the moment.

Why this requirement exists

When an incident or a significant ISMS change happens, the worst time to figure out who needs to be told is in the middle of it. This requirement forces that planning to happen ahead of time, so a breach notification, a policy update, or a scope change follows a known path instead of an improvised one.

Scenario: a data incident occurs and the response team spends the first critical hours debating who should be told—legal, affected customers, a regulator, the board—instead of executing a plan. A defined communication plan, decided calmly before any incident, would have made those calls automatic.

What the standard expects

The standard expects the organization to determine the need for internal and external communications relevant to the ISMS, including what to communicate, when to communicate, with whom to communicate, who communicates, and the processes by which communication is effected.

In practice

  • Build a short communication matrix: trigger event, audience, channel, timing, and owner—for both routine updates and incident scenarios.
  • Cover external obligations explicitly—breach notification timelines to regulators or customers are often legally mandated and time-sensitive.
  • Keep the plan short enough that people actually remember it exists—a communication plan nobody can find in a crisis does not help.

Evidence the auditor will ask for

  • A documented communication plan or matrix covering internal and external audiences.
  • Examples of the plan being followed—a policy update actually communicated, an incident notification actually sent per the defined process.

Common pitfalls

  • A communication plan that covers internal staff updates but says nothing about external notification obligations.
  • No named owner for a given communication—everyone assumes someone else will send it.

Related requirements

Sources

Frequently asked questions

Does the communication plan need to be a standalone document?
Not necessarily. It can live inside your incident response plan or a broader policy, as long as the what, when, who, and how are clearly addressed somewhere an auditor can find. A short matrix—trigger event, audience, channel, timing, and owner—is often enough, provided people actually remember it exists.
Does the plan have to cover external audiences?
Yes. The standard covers internal and external communications relevant to the ISMS: staff and leadership on one side, customers, regulators, and certification bodies on the other. Breach notification timelines to regulators or customers are often legally mandated and time-sensitive; a plan that says nothing about those obligations is a common pitfall.
What evidence will the auditor ask for under 7.4?
A documented communication plan or matrix covering internal and external audiences, then examples showing the plan is actually followed: a policy update communicated, an incident notification sent per the defined process. The auditor will also check that a named owner exists for each communication, otherwise everyone assumes someone else will send it.

Let's talk about your compliance program.

Last updated: 2026-09-17