Resources and competence
Determine the resources the ISMS needs and ensure staff with security responsibilities are competent.
Awareness
All staff must know the security policy, their contribution to the system's effectiveness and the consequences of not following procedures.
Documented information
ISMS documents and records controlled with version, approval, access restricted by classification and proper retention.
What an auditor usually asks for
- Information security training records
- Evidence of awareness campaigns (phishing, passwords)
- An up-to-date ISMS master document list
- Document access control based on classification
How to cover support in Kimobox
- 1Log each employee's security training on their record in the employee portal.
- 2Manage ISMS documentation with classification and profile-based access control.
- 3Communicate the policy and relevant incidents directly to each user based on their role.
Security training stops being a PDF sent by email: it stays on record with a date and an expiry.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024