User
What evidence to look for regarding clause 7.4?
Experta
During the audit, an auditor might ask for the following evidence regarding 7.4 Communication:
- If the company has defined relevant interested parties to whom it needs to communicate regarding security.
- If the company has defined what will be communicated to those interested parties.
- If the company has defined when this communication will take place.
- If the company has defined which communication channels will be used.
It is not mandatory to write a document for this clause, so the auditor might interview people and look for records of written communication (e.g., email).
These are the things the auditor will be looking for, if they are not found this is considered a nonconformity.