ISMS Communication

1. Purpose and Context

This policy implements the requirements of ISO/IEC 27001:2022, Section 7.4. It defines what is communicated, when, with whom, and by which roles within the Information Security Management System (ISMS).

Scope: All employees, managers, external partners, customers, and third parties who exchange information within the context of the ISMS.

2. Referenced Documents

ISO/IEC 27001 Standard, Sections:

  • 5.2 Policy

  • 5.3 Organizational roles, responsibilities and authorities

  • 7.3 Awareness

  • 7.4 Communication

  • 9.3 Management review

  • A.5.1 Policies for information security

  • A.5.4 Management responsibilities

Note: Additional specific references to standards (for example, regarding incident reporting, crisis communication, and monitoring) are listed directly in the ISO Ref column of the matrix below for each communication scenario and are not listed here to avoid redundancy.

3. Roles & Responsibilities

Roles and associated responsibilities are described in more detail in the handbook.

4. Communication Matrix

Communication (both external and internal) takes place primarily through the ticket system. Additional communication channels are described in the Handbook under Communication Channels.

Table 1. Communication Matrix
ISO-Ref.Topic (On What)Trigger (When)Target Audience (With Whom)Responsible (Who)Channel (How)

5.2

Information Security Policy

Upon enrollment / Annually / Upon adjustments

All employees, relevant suppliers

CISO / People-OPS

Odoo, Mail

7.3

Awareness Campaign (for example, Phishing)

Every six months

All Employees

CISO / Corp-IT

E-Mail-Newsletter, Chat

9.3

Management Review (ISMS Status Report)

Annually (or as needed)

Board

CISO

Formal meeting, presentation, signed minutes

A.6.8

Reporting Security Incidents

Immediately upon discovery

CISO / ISM-Governance

All Employees

Chat, Ticket-System

A.5.24

External crisis communication (for example, data breach)

Following confirmation of a critical incident

Authorities, affected customers, the media

Customer Account-Manager, Marketing, Legal & Compliance

Ticket System, Press Release, Official Emails

A.5.29

Emergency Communication (for example, Total IT Outage)

Failure of primary ICT systems

All Employees, Crisis Management Team, Board

Incident Commander

Out-of-Band-Messenger (Threema)

A.8.16

Critical system alerts (monitoring)

Threshold Exceeded (for example, CPU 99%)

Responsible-OPS, On-Call

IT-Monitoring System (Automated, Escalation to On-Call Engineer)

OPS-Genie, SMS, Call

Table 2. Review

Approval date

2026-08-31

Approved with

vshnwiki.atlassian.net/wiki/x/EwBBMw

Last reviewed

2026-08-31

Classification

Public