In this blog, Warren Howard, Senior Consultant at URM, explores the requirements of ISO 27001 Clause 7.4 and explains how they can be met effectively and efficiently. He examines the links between communication requirements, interested parties, risk management activities and Annex A controls, highlighting the importance of considering these elements together rather than in isolation. The blog also outlines a practical approach to consolidating communications and interested party requirements into a single framework, helping organisations improve traceability, reduce duplication and demonstrate effective information security management system (ISMS) implementation during audits.
ISO 27001 is often associated with risk assessments, security controls and audits, but clear communication across the organisation is equally important; people need to understand their role in protecting information for an ISMS to be successful. Communication is covered mainly in Clause 7.4 of ISO 27001, but it affects many parts of the ISMS. How information is shared across the organisation can have a significant impact on how well security responsibilities are understood, stakeholder expectations are met, and business objectives are achieved. Taking a joined-up approach to communication can make processes more efficient and provide a clearer record of what has been communicated, when, and to whom.
Clause 7.4 Interactions
Before looking at the ISO 27001 communication requirements in detail, it is worth considering how Clause 7.4 interacts with other parts of the Standard. All elements of ISO 27001 are linked in some way, and the relationships with Clause 7.4 are particularly important.
Clause 4 lays the groundwork for your ISMS. Understanding your organisation, its stakeholders, and their expectations helps shape many of the decisions made within the system, including how risks and opportunities are managed.
This links closely to Clause 7.4 on communication. Once you have identified who your stakeholders are and what they need or expect, you can determine what information should be communicated, who it should be communicated to, and how those communications should take place.
ISO defines an interested party as a person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. In the 2022 edition of ISO 27001, Clause 4.2 requires you to determine:
- Interested parties that are relevant to the ISMS
- The relevant requirements of these interested parties
- Which of these requirements will be addressed through the ISMS.
Notes to the clause also specify that interested party requirements include legal and regulatory requirements as well as contractual obligations. In addition, the Joint ISO / IAF Communique of February 2024 added that relevant interested parties can have requirements related to climate change.
Meanwhile, Clause 7.4 of the Standard states that organisations ‘shall determine the need for internal and external communications relevant to the ISMS including:
- On what to communicate
- When to communicate
- With whom to communicate
- How to communicate’.
This is where a practical approach starts to take shape. If you need to identify who your interested parties are, understand their requirements, determine how those requirements will be addressed through the ISMS, and consider what communication is needed with those parties, it often makes sense to bring all of this information together in one place.
By doing so, you can clearly see the link between stakeholder requirements, your ISMS activities, and the communications that support them. This not only reduces duplication but also makes it easier to demonstrate that requirements have been considered, addressed, and communicated effectively.
One way of achieving this is using a landscaped table to identify the interested parties, capture their requirements, identify how that requirement will be met, and then completing additional columns to determine what you are going to tell them, when, who you will let know, and how you are going to do so. In our experience, this approach is well received by auditors and consolidates two documents into one, allowing you to efficiently manage both interest party requirements and communication needs in a single location.
It is important to note that ISO 27001 does not specifically require you to document your communications arrangements or maintain a formal communications plan. The requirement is simply to determine the need for internal and external communications relevant to the ISMS, including what will be communicated, when, with whom and how. However, as with many areas of management systems, documenting this information represents good practice, helping to ensure that communication requirements are considered consistently and comprehensively.
Interested parties and their needs and expectations:
For each interested party, record:
- Column 1: Who they are
- Column 2: What they need or expect from you
- Column 3: How the ISMS will meet that need or expectation
Communication
- Column 4: On what to communicate
- Column 5: When to communicate
- Column 6: With whom to communicate
- Column 7: How to communicate.
Including the relevant ISO 27001 clause numbers under each heading can be helpful. This provides clear evidence that the Standard's requirements have been considered, shows how different clauses are linked together, and makes it easier for external auditors to follow your approach.
Here is an example of this approach in practice:
Using this approach, you can work through the requirements of the Standard in a clear and logical way, identifying how each requirement will be addressed within your ISMS. The result is a single document that brings everything together, making it easier to understand requirements, plan how to meet them, and manage communications across the organisation.
Additional columns can be added to suit your organisation’s approach (e.g., including details on points of contact), however you will need to be mindful of issues around personal data and GDPR compliance when considering how the document is subsequently classified and handled. Meanwhile, if your management system is an integrated model which includes other ISO standards, the requirements and content of Clause 7.4 can differ slightly, with many including additional considerations of ‘who will communicate’. This can be easily addressed by adding an additional column as necessary.
Further additional elements that could be incorporated into this structure include:
- Control 5.5 (Contact with authorities - the ICO is included in the above example)
- Control 5.6 (Contact with special interest groups)
- Control 5.7 (Threat intelligence).
As all of the above entities would fall under the heading of ‘Interested Parties’ and require a degree of incoming / outgoing communication, including them in this capture is a logical and practical extension of the same approach.
Multiple communications vectors can be used to distribute communications, such as:
- Microsoft Teams
- WhatsApp / Signal / Telegram / Messenger
- Telephone call.
Taking things a stage further, the data identified in column c (how the ISMS addresses the requirement), can also be cross-referenced to your risk treatment plan. Each Annex A control can be mapped to risks that you have identified against each entity, demonstrating thoroughness and a full understanding of the connections and links between different aspects of the Standard.
Conclusion
When communication requirements are mapped directly to interested parties, their expectations, applicable controls and risk treatment activities, organisations can show a clear line of sight between stakeholder requirements, security controls and operational activities. Rather than maintaining these requirements separately and reviewing associated documents in isolation, a consolidated approach creates a single source of truth that demonstrates traceability and provides auditors with clear evidence of how information security requirements are being identified, addressed and communicated. It also helps reduce duplication and makes the ISMS easier to maintain.
How URM Can Help
With over 20 years of experience supporting organisations in achieving and maintaining ISO 27001 certification, URM provides practical, expert-led guidance across every stage of the Standard’s lifecycle.
Gap analysis and risk assessment
Helping you understand your current position and prioritise action:
- Conducting an ISO 27001 gap analysis to establish your current conformance level, assessing your information security practices against the Standard, identifying areas for improvement and providing reccommendations
- Assisting with your ISO 27001 risk assessment using Abriska 27001, our proven risk management tool.
Implementation and internal audit
Delivering hands-on support to build and validate your ISMS:
- Assisting with ISO 27001 implementation, including development of policies, processes, and ISMS infrastructure tailored to your organisation
- Delivering ISO 27001 internal audit services, whether as a pre-certification audit, a full three-year audit programme, or focused reviews of specific controls
- Identifying nonconformities and supporting effective remediation to ensure certification readiness.
Training and ongoing support
Providing continued expertise to maintain and improve your ISMS:
- Offering flexible ISO 27001 support, including our virtual Chief Information Security Officer (vCISO) service for senior-level information security guidance and leadership
- Delivering ISO 27001 training courses to build internal capability and strengthen your organisation’s security culture.
A short, free, non‑commitment call can help you clarify scope, understand regulatory expectations, and align your approach across standards such as ISO 42001 and NIST AI RMF. Early guidance often saves time and avoids fragmented compliance efforts.
Whether you are at an early planning stage or preparing for audit and assurance activities, we offer a free introductory call to help you assess risks, responsibilities, and the most proportionate route forward.
You do not need a fully defined programme to start the conversation. We offer a free, no‑obligation call to help you understand SOC 2 requirements, assess your current position, and identify practical next steps.
Due to the increased use of technologies and the ‘human’ involvement, it is inevitable we are all going to face more and more information security incidents.
URM’s blog explains the importance of the 5 supplier management controls in ISO 27001 & provides practical guidance on how to implement each control.
The answer depends on your goals and knowledge of your current position. This blog will look at which is best and when.


