The organization shall determine which issues related to the information security management system need to be communicated on a regular basis. The plan must include the answers, e.g. to the following points:
- What issues are communicated? These can be e.g. new or changed security objectives
- How and when to communicate?What channels are used and how often?
- To whom is communicated? How often for security executives, how often for the entire organization or partners.
- Who takes part? Who has the right to message and from whom, for example, messages should be approved.
Task owner will take care of the implementation of the plan and regular evaluation of its effectiveness.