ISMS Communication
1. Purpose and Context
This policy implements the requirements of ISO/IEC 27001:2022, Section 7.4. It defines what is communicated, when, with whom, and by which roles within the Information Security Management System (ISMS).
Scope: All employees, managers, external partners, customers, and third parties who exchange information within the context of the ISMS.
2. Referenced Documents
ISO/IEC 27001 Standard, Sections:
5.2 Policy
5.3 Organizational roles, responsibilities and authorities
7.3 Awareness
7.4 Communication
9.3 Management review
A.5.1 Policies for information security
A.5.4 Management responsibilities
Note: Additional specific references to standards (for example, regarding incident reporting, crisis communication, and monitoring) are listed directly in the ISO Ref column of the matrix below for each communication scenario and are not listed here to avoid redundancy.
3. Roles & Responsibilities
Roles and associated responsibilities are described in more detail in the handbook.
4. Communication Matrix
Communication (both external and internal) takes place primarily through the ticket system. Additional communication channels are described in the Handbook under Communication Channels.
| ISO-Ref. | Topic (On What) | Trigger (When) | Target Audience (With Whom) | Responsible (Who) | Channel (How) |
|---|---|---|---|---|---|
5.2 | Upon enrollment / Annually / Upon adjustments | All employees, relevant suppliers | Odoo, Mail | ||
7.3 | Awareness Campaign (for example, Phishing) | Every six months | All Employees | CISO / Corp-IT | E-Mail-Newsletter, Chat |
9.3 | Management Review (ISMS Status Report) | Annually (or as needed) | CISO | Formal meeting, presentation, signed minutes | |
A.6.8 | Reporting Security Incidents | Immediately upon discovery | CISO / ISM-Governance | All Employees | Chat, Ticket-System |
A.5.24 | External crisis communication (for example, data breach) | Following confirmation of a critical incident | Authorities, affected customers, the media | Customer Account-Manager, Marketing, Legal & Compliance | Ticket System, Press Release, Official Emails |
A.5.29 | Emergency Communication (for example, Total IT Outage) | Failure of primary ICT systems | All Employees, Crisis Management Team, Board | Out-of-Band-Messenger (Threema) | |
A.8.16 | Critical system alerts (monitoring) | Threshold Exceeded (for example, CPU 99%) | IT-Monitoring System (Automated, Escalation to On-Call Engineer) | OPS-Genie, SMS, Call |
Approval date | 2026-08-31 |
|---|---|
Approved with | |
Last reviewed | 2026-08-31 |
Classification | Public |