ISO/IEC 27001 FAQISMS implementationISO/IEC 27001:2022

ISO/IEC 27001 FAQ

Clear answers for teams implementing ISO/IEC 27001: define the ISMS scope, assess information security risk, choose treatment options, build the Statement of Applicability, and keep audit evidence current.

This serves as implementation guidance for an information security management system, not for legal interpretation or a substitute for an accredited certification audit.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
FAQ modules
7

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27001:2022 sets requirements for establishing, implementing, maintaining, and continually improving an . Start with five connected decisions: the ISMS scope, risk-assessment criteria and results, risk treatment and necessary controls, the Statement of Applicability, and the evidence used for monitoring, internal audit, management review, and improvement.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items28
Focused FAQ modules
7
Showing 7 of 7
Question 1

What does ISO/IEC 27001 require an ISMS to cover?

The ISMS scope must establish the management system's boundaries and applicability. When setting it, the organization considers relevant internal and external issues, relevant interested-party requirements, and interfaces and dependencies between its activities and activities performed by other organizations. The scope must be available as documented information.

Teams should connect the scope to information handled by the business, not only to departments or platforms. If customer data, production environments, outsourced operations, or critical suppliers support the scoped service, the ISMS record should explain how those interfaces are governed.

  • Keep a current ISMS scope statement with sites, services, products, systems, outsourced processes, and boundary assumptions.
  • Map interested-party requirements such as customer security commitments, legal obligations, contractual clauses, and certification goals.
  • Review the scope after major product launches, acquisitions, infrastructure migrations, supplier changes, or customer-assurance commitments.
Question 2

How should ISO/IEC 27001 risk assessment and risk treatment work?

Risk assessment should identify risks to the confidentiality, integrity, and availability of information within the ISMS scope, analyse them with defined criteria, and prioritize them for treatment. The record should show the asset, threat or weakness, business impact, likelihood or severity logic, risk owner, and current decision.

Risk treatment begins with treatment options selected in light of the assessment results. Common organizational options include modifying, avoiding, sharing, or retaining risk, but ISO/IEC 27001 does not impose that exact four-label taxonomy. The organization determines all necessary controls, checks them against Annex A, produces the SoA, formulates the treatment plan, and obtains risk-owner approval and residual-risk acceptance.

  • Define risk criteria before scoring risks so results are comparable across systems and teams.
  • Tie treatment actions to owners and deadlines, not only to control names.
  • Capture risk-owner approval for the treatment plan and residual-risk acceptance.
  • Reassess when scope, technology, suppliers, incidents, vulnerabilities, or business priorities materially change.
Question 3

What is the Statement of Applicability and why does it matter?

The Statement of Applicability connects risk treatment to the control set. It must contain the necessary controls, justification for their inclusion, whether those controls are implemented, and justification for excluding any Annex A controls. Necessary controls may be designed by the organization or drawn from sources beyond Annex A.

Keep the SoA traceable to risk-assessment results, applicable requirements, treatment options, implementation status, and evidence. Control owners and evidence locations are useful internal fields, but ISO/IEC 27001 does not require those exact fields to appear in the SoA.

  • For included controls, record why the control is needed, who owns it, whether it is implemented, and where evidence is maintained.
  • For excluded controls, provide a clear justification that matches the ISMS scope and risk treatment decision.
  • Update the SoA when the risk register, treatment plan, Annex A evidence, or ISMS scope changes.
  • Do not claim Annex A coverage only because a policy exists; operating evidence should support the claim.
Recommended next step

Operationalize ISO/IEC 27001

This FAQ helps connect your ISMS scope, risk register, treatment plan, Statement of Applicability, Annex A evidence, internal audit results, and management-review actions into one accountable evidence model.

Question 4

Which evidence is useful for certification and surveillance audits?

Certification evidence should show both design and operation. Design evidence explains the ISMS scope, policies, risk process, control selection, SoA, objectives, roles, and procedures. Operating evidence shows the process ran: completed risk reviews, access reviews, security events, supplier reviews, training records, vulnerability handling, incident records, audit reports, management-review minutes, nonconformities, and corrective actions.

A surveillance audit samples continuing conformity during an active certification cycle. A certificate does not prove every control is permanently effective or every system secure; the organization still needs evidence that the scoped ISMS operated, changes were assessed, findings were handled, and management reviewed performance.

  • Keep an evidence index that maps each SoA control to owner, system, evidence type, sample frequency, and storage location.
  • Separate policy approval from operating proof; a policy is not the same as a completed review or control sample.
  • Track nonconformities and corrective actions through closure with cause, action owner, due date, and effectiveness check.
  • Verify certificates through an accredited certification body or public certification database when relying on a supplier certificate.
Question 5

How do internal audit and management review keep the ISMS alive?

Internal audit must determine whether the ISMS conforms to ISO/IEC 27001 and to the organization's own requirements, and whether it is effectively implemented and maintained. The audit programme must consider process importance and previous audit results, so high-risk or repeatedly weak areas receive appropriate attention.

Management review is where leadership decides whether the ISMS remains suitable, adequate, and effective. Useful inputs include actions from previous reviews, changes in context, ISMS performance, audit results, risk assessment results, risk-treatment status, opportunities for improvement, and resource needs.

  • Plan internal audits by scope, criteria, method, auditor objectivity and impartiality, areas covered, and reporting path.
  • Use management review to decide scope changes, risk appetite, resourcing, corrective actions, objectives, and improvement priorities.
  • Retain documented evidence of audit results and management-review outputs.
  • Feed surveillance-audit findings and customer-assurance gaps back into the ISMS improvement cycle.
Question 6

What misconceptions cause ISO/IEC 27001 programmes to fail?

Treating ISO/IEC 27001 as a certificate project leaves the management system stale after the audit. Certification is separate from the organization's continuing duties to maintain scope, risk treatment, control operation, performance evaluation, and improvement records.

Another common mistake is copying every Annex A control into the SoA without risk-based reasoning. ISO/IEC 27001 expects teams to determine necessary controls from risk treatment, compare them with Annex A so controls are not overlooked, and justify exclusions. That is different from implementing every control identically across every environment.

  • Do not confuse ISO/IEC 27002 with a certifiable standard; it guides controls, while ISO/IEC 27001 contains ISMS requirements.
  • Do not rely on a vendor certificate without checking scope, expiry, certification body, and whether the certified services match your dependency.
  • Do not let the SoA, risk register, and evidence folders drift apart; they should tell the same story.
  • Do not wait for the external audit to discover stale evidence; internal audit and management review should surface gaps earlier.
Primary sources

References and citations

iafcertsearch.org
Referenced sections
  • This source supports the recommendation to verify and monitor management-system certifications through a public certification database.
"verify and monitor certifications"
iso.org
Referenced sections
  • This source supports the internal-audit, management-review, performance-evaluation, and improvement framing for the ISMS.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • Official ISO listing for the 2024 Climate action changes amendment to ISO/IEC 27001:2022.
"Climate action changes"
iso.org
Referenced sections
  • This source supports the distinction between ISO/IEC 27002 control guidance and ISO/IEC 27001 certification requirements.
"Information security controls"
iso.org
Referenced sections
  • This source supports the point that risk treatment and monitoring should remain part of ongoing ISMS operation.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • This source supports the certification-body credibility and audit-practice context for ISO/IEC 27001 certification.
"audit and certification"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.