Information security management

Evidence the ISO 27001 awareness control

ISO/IEC 27001 asks you to prove that your people are aware, competent, and trained. Claro turns phishing simulations and micro-training into the documented, auditable evidence certification bodies look for.

Regulator
International Organization for Standardization
Applies to
Any organization operating an information security management system

Overview

ISO/IEC 27001 is the international standard for an information security management system, or ISMS. It defines how an organization establishes, operates, monitors, and continually improves a structured set of controls that protect the confidentiality, integrity, and availability of information. Many Indonesian enterprises adopt it because customers, partners, and regulated industries increasingly expect certification before they will share data or sign a contract. The standard is technology-neutral, so it applies equally to banks, SaaS exporters, government suppliers, and manufacturers.

The 2022 revision of the standard sharpened its focus on the human layer. Annex A now includes a dedicated people control, 6.3, covering information security awareness, education, and training, which requires that personnel receive appropriate awareness education and regular updates relevant to their role. This consolidated the awareness expectation that older versions expressed through control A.7.2.2. In practice, it means awareness is no longer a footnote; it is an explicit control that must be planned, delivered, and reviewed.

Beyond Annex A, the management-system clauses carry their own human-layer obligations. Clause 7.2 on competence requires you to determine the competence needed for roles that affect information security and to keep documented evidence of it. Clause 7.3 on awareness requires that everyone under the organization's control understands the information security policy, their contribution to the ISMS, and the implications of not conforming. These clauses are audited every cycle, so the evidence has to be current and specific to your people.

This page is general information to help you plan, not legal or audit advice. For the definitive requirements, refer to the authoritative ISO/IEC 27001 standard and work with a qualified certification body or ISMS consultant. Claro supports the human-layer and awareness controls with measurable, exportable evidence, but it does not by itself implement the full ISMS or grant certification. Certification is an outcome of your entire management system, assessed by an accredited auditor.

What the rule expects

Annex A 6.3 awareness, education, and training

Personnel must receive appropriate information security awareness education and training, with regular updates that stay relevant to their role. The control expects a planned program rather than a one-off induction session. Auditors will ask how you deliver it, who receives it, and how often it is refreshed.

Clause 7.2 competence

You must determine the competence required for roles that affect information security performance and ensure people are competent through training, mentoring, or experience. Documented evidence of that competence is mandatory. For security behavior, this often means records that link individuals to the training they completed and how they performed.

Clause 7.3 awareness of policy and responsibilities

Everyone working under the organization's control must be aware of the information security policy, how they contribute to the effectiveness of the ISMS, and the consequences of not conforming. This is broader than the security team and includes contractors where relevant. Awareness has to be demonstrable, not assumed.

Evidence of effectiveness, not just activity

Auditors increasingly look for proof that awareness training actually works, not just that a policy or a slide deck exists. That means metrics showing behavior change over time, such as who still clicks simulated phishing and who reports it. Records that only prove attendance are a common source of nonconformities.

Reaching the right people at the right cadence

Training must reach all relevant personnel and repeat on a defined schedule, with attention to new joiners and role changes. A control that covers only headquarters staff or that lapses after year one will not satisfy an auditor. You need coverage records that map training to your current workforce.

Continual improvement of the human control

The ISMS operates on a plan-do-check-act cycle, so the awareness control must be measured, reviewed, and improved over successive cycles. Management reviews expect trend data, not a static snapshot. You should be able to show what changed and why after each assessment period.

Documented information and retention

ISO/IEC 27001 requires documented information to be controlled, retained, and retrievable on demand during an audit. Awareness and competence evidence falls squarely within this obligation. If you cannot produce the records quickly and in an organized form, the control is effectively unproven.

How Claro helps you comply

  • Deliver the awareness program Annex A 6.3 expects

    Claro runs the ongoing awareness program the control describes through bilingual micro-modules, learning paths, and assignment rules that repeat on a defined cadence. Content ships in English and Bahasa Indonesia so it stays relevant to Indonesian personnel. SCORM 1.2 import lets you bring existing courseware into the same system of record.

  • Prove effectiveness with phishing simulations

    Localized phishing simulations with per-recipient tracking of opens, clicks, submissions, and reports give you evidence of behavior, not just attendance. Because results are measured over time, you can demonstrate the effectiveness auditors expect under a plan-do-check-act cycle. This is the difference between activity and outcome.

  • Turn failures into just-in-time competence building

    When a user fails a simulation, Claro shows an instant awareness page and auto-enrolls them in role-relevant training. This directly supports the competence expectation of Clause 7.2 by closing the gap at the moment of the mistake. Every intervention is logged as evidence.

  • Map coverage to ISO 27001 in the compliance module

    Claro's compliance module includes ISO 27001 framework logic, so control coverage is mapped rather than assembled by hand. You can see at a glance which awareness and competence obligations are supported by current activity. This makes management reviews and audit preparation far faster.

  • Export audit-ready evidence packages

    Claro generates evidence packages as ZIP bundles of Claro-style PDF reports plus CSV exports, along with per-user completion records. Scheduled report delivery keeps the evidence current between audits. When a certification body asks for records, they are ready to hand over.

  • Track risk by user and department

    Per-user and per-department risk scoring, with a gamification and behavior engine, shows where the human control is strong and where it needs continual improvement. That trend data feeds directly into ISMS management reviews. Audit logs and per-tenant data isolation keep the evidence trustworthy.

Frequently asked questions

  • No. Certification is granted by an accredited certification body after it audits your entire ISMS, not any single tool. Claro supports the human-layer controls, specifically awareness, training, and competence evidence, which are one part of that broader system. Think of it as strengthening and documenting a portion of what the auditor will assess.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo