7.3 Awareness
It
is ensured that the people working in any area are aware of the followings:
(1)The information security
policy
(2)Responsibility to fulfil the
requirements including benefits for the
improvement in the information security management systems.
(3)The implication of not
conforming with the information security management systems.
7.4 Communication
The
organization shall determine the need for internal and external
communication relevant to the
information security management systems including :
1) On what to communicate
2) When to communicate
3) With whom to communicate
4) Who shall communicate
5) The processes by which the communication
will be effective
User questions & answers