ISO 27001 Clause 7.4: Communication

Warren Howard
|
Senior Consultant at URM
|
|
PUBLISHED on
30
July
2026
SUMMARY

In this blog, Warren Howard, Senior Consultant at URM, explores the requirements of ISO 27001 Clause 7.4 and explains how they can be met effectively and efficiently.  He examines the links between communication requirements, interested parties, risk management activities and Annex A controls, highlighting the importance of considering these elements together rather than in isolation. The blog also outlines a practical approach to consolidating communications and interested party requirements into a single framework, helping organisations improve traceability, reduce duplication and demonstrate effective information security management system (ISMS) implementation during audits.

ISO 27001 is often associated with risk assessments, security controls and audits, but clear communication across the organisation is equally important; people need to understand their role in protecting information for an ISMS to be successful.  Communication is covered mainly in Clause 7.4 of ISO 27001, but it affects many parts of the ISMS. How information is shared across the organisation can have a significant impact on how well security responsibilities are understood, stakeholder expectations are met, and business objectives are achieved. Taking a joined-up approach to communication can make processes more efficient and provide a clearer record of what has been communicated, when, and to whom.

Clause 7.4 Interactions

Before looking at the ISO 27001 communication requirements in detail, it is worth considering how Clause 7.4 interacts with other parts of the Standard.  All elements of ISO 27001 are linked in some way, and the relationships with Clause 7.4 are particularly important.

Clause 4 lays the groundwork for your ISMS.  Understanding your organisation, its stakeholders, and their expectations helps shape many of the decisions made within the system, including how risks and opportunities are managed.

This links closely to Clause 7.4 on communication. Once you have identified who your stakeholders are and what they need or expect, you can determine what information should be communicated, who it should be communicated to, and how those communications should take place.

ISO defines an interested party as a person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity.  In the 2022 edition of ISO 27001, Clause 4.2 requires you to determine:

  • Interested parties that are relevant to the ISMS
  • The relevant requirements of these interested parties
  • Which of these requirements will be addressed through the ISMS.  

Notes to the clause also specify that interested party requirements include legal and regulatory requirements as well as contractual obligations.  In addition, the Joint ISO / IAF Communique of February 2024 added that relevant interested parties can have requirements related to climate change.  

Meanwhile, Clause 7.4 of the Standard states that organisations ‘shall determine the need for internal and external communications relevant to the ISMS including:

  • On what to communicate
  • When to communicate
  • With whom to communicate
  • How to communicate’.

This is where a practical approach starts to take shape.  If you need to identify who your interested parties are, understand their requirements, determine how those requirements will be addressed through the ISMS, and consider what communication is needed with those parties, it often makes sense to bring all of this information together in one place.

By doing so, you can clearly see the link between stakeholder requirements, your ISMS activities, and the communications that support them.  This not only reduces duplication but also makes it easier to demonstrate that requirements have been considered, addressed, and communicated effectively.

One way of achieving this is using a landscaped table to identify the interested parties, capture their requirements, identify how that requirement will be met, and then completing additional columns to determine what you are going to tell them, when, who you will let know, and how you are going to do so.  In our experience, this approach is well received by auditors and consolidates two documents into one, allowing you to efficiently manage both interest party requirements and communication needs in a single location.

It is important to note that ISO 27001 does not specifically require you to document your communications arrangements or maintain a formal communications plan.  The requirement is simply to determine the need for internal and external communications relevant to the ISMS, including what will be communicated, when, with whom and how.  However, as with many areas of management systems, documenting this information represents good practice, helping to ensure that communication requirements are considered consistently and comprehensively.


Interested parties and their needs and expectations:

For each interested party, record:

  • Column 1: Who they are
  • Column 2: What they need or expect from you
  • Column 3: How the ISMS will meet that need or expectation

Communication

  • Column 4:  On what to communicate
  • Column 5:  When to communicate
  • Column 6:  With whom to communicate
  • Column 7:  How to communicate.  

Including the relevant ISO 27001 clause numbers under each heading can be helpful. This provides clear evidence that the Standard's requirements have been considered, shows how different clauses are linked together, and makes it easier for external auditors to follow your approach.

Here is an example of this approach in practice:

Interested Party

Communication

(a)

(b)

(c)

(d)

(e)

(f)

(g)

Entity (4.2a)

Requirement (4.2b)

How ISMS addresses requirement (4.2c)

On What

(7.4a)

When to (7.4b)

Who with

(7.4c)

How to

(7.4d)

Internal workforce

Notification that their PII has been compromised

ISMS, HR and privacy-related policies, incident management processes

PII breaches

ASAP

All

Town Hall meeting

Internal workforce

Assurance that the company is operating within legal and regulatory boundaries

Control 5.31 (Legal, statutory, regulatory and contractual requirements)

Ongoing legal conformity

Annual refresher training

All

Awareness training

Internal workforce

Assurance that their PII is being protected

Control 5.34 (Privacy and protection of PII)

Ongoing organisational commitment

As required

All

Company portal

ICO

Ongoing legal regulatory conformance

Control 5.31 (Legal, statutory, regulatory and contractual requirements)

GDPR breach

Within 72 hours of becoming aware of a notifiable personal data breach

ICO

Fastest possible means

Using this approach, you can work through the requirements of the Standard in a clear and logical way, identifying how each requirement will be addressed within your ISMS.  The result is a single document that brings everything together, making it easier to understand requirements, plan how to meet them, and manage communications across the organisation.

Additional columns can be added to suit your organisation’s approach (e.g., including details on points of contact), however you will need to be mindful of issues around personal data and GDPR compliance when considering how the document is subsequently classified and handled.   Meanwhile, if your management system is an integrated model which includes other ISO standards, the requirements and content of Clause 7.4 can differ slightly, with many including additional considerations of ‘who will communicate’.  This can be easily addressed by adding an additional column as necessary.

Further additional elements that could be incorporated into this structure include:

  • Control 5.5 (Contact with authorities - the ICO is included in the above example)
  • Control 5.6 (Contact with special interest groups)
  • Control 5.7 (Threat intelligence).

As all of the above entities would fall under the heading of ‘Interested Parties’ and require a degree of incoming / outgoing communication, including them in this capture is a logical and practical extension of the same approach.

Multiple communications vectors can be used to distribute communications, such as:

  • Microsoft Teams
  • WhatsApp / Signal / Telegram / Messenger
  • Email
  • Telephone call.

Taking things a stage further, the data identified in column c (how the ISMS addresses the requirement), can also be cross-referenced to your risk treatment plan.  Each Annex A control can be mapped to risks that you have identified against each entity, demonstrating thoroughness and a full understanding of the connections and links between different aspects of the Standard.

Conclusion

When communication requirements are mapped directly to interested parties, their expectations, applicable controls and risk treatment activities, organisations can show a clear line of sight between stakeholder requirements, security controls and operational activities.  Rather than maintaining these requirements separately and reviewing associated documents in isolation, a consolidated approach creates a single source of truth that demonstrates traceability and provides auditors with clear evidence of how information security requirements are being identified, addressed and communicated.  It also helps reduce duplication and makes the ISMS easier to maintain.

How URM Can Help

With over 20 years of experience supporting organisations in achieving and maintaining ISO 27001 certification, URM provides practical, expert-led guidance across every stage of the Standard’s lifecycle.

Gap analysis and risk assessment

Helping you understand your current position and prioritise action:

  • Conducting an ISO 27001 gap analysis to establish your current conformance level, assessing your information security practices against the Standard, identifying areas for improvement and providing reccommendations
  • Assisting with your ISO 27001 risk assessment using Abriska 27001, our proven risk management tool.

Implementation and internal audit

Delivering hands-on support to build and validate your ISMS:

  • Assisting with ISO 27001 implementation, including development of policies, processes, and ISMS infrastructure tailored to your organisation
  • Delivering ISO 27001 internal audit services, whether as a pre-certification audit, a full three-year audit programme, or focused reviews of specific controls
  • Identifying nonconformities and supporting effective remediation to ensure certification readiness.

Training and ongoing support

Providing continued expertise to maintain and improve your ISMS:

Warren  Howard
Warren Howard
Senior Consultant at URM
Warren is a Senior Consultant at URM with extensive experience implementing, maintaining and continually improving management systems, notably information security, business data protection and quality management systems.

Are you looking to implement ISO 27001? Or certify against the Standard?

URM offers a host of consultancy services to assist you implement and maintain ISO 27001, including gap analyses, risk assessments, policy development, auditing and training.
Thumbnail of the Blog Illustration
Information Security
Published on
4/10/2024
Implementing and Auditing ‘People Controls’ from ISO 27001:2022

URM’s blog explains why ‘people’ warrants its own control theme in ISO 27001 and how to prepare for a people controls audit, offering advice for each control.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
22/5/2023
Top Tips For Implementing an Effective ISO 27001 Information Security Management System (ISMS)

URM provides some top tips for achieving an effective and successful information security management system implementation

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
5/9/2025
ISO 27001 Clause 5.1: Leadership and Commitment Explained

URM’s blog explores Clause 5.1 of ISO 27001, what you must do to meet its requirements, and why leadership & commitment are vital to an effective ISMS.

Read more
From beginning to end URM made achieving PCI compliance incredibly easy & worked with us to educate us on the requirements. They were always available for a call whenever we needed to discuss queries along the way & were always flexible to our internal deadlines. We would highly recommend URM from a consultancy & auditing perspective.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.