GuideGlobalISO/IEC 27001

ISO/IEC 27001 Requirements

ISO/IEC 27001:2022 requires a complete management system, not a universal security-control checklist. Clauses 4–10 cover how the organization governs, operates, evaluates, and improves information security risks.

The ISMS scope can be bounded, but none of Clauses 4–10 can be excluded when claiming conformity. Annex A is a reference set used during risk treatment; necessary controls may also come from other sources.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

ISO/IEC 27001:2022 requires an organization to establish, implement, maintain, and continually improve an information security management system, determine its scope, address information security risks, keep documented information where required, and review performance through internal audit, management review, and corrective action.

Section 1

How do Clauses 4–10 fit together?

For ISO/IEC 27001, the core decisions are not just administrative. The standard requires organizations to determine the ISMS scope, consider external and internal issues, identify interested parties and their requirements, and decide which of those requirements will be addressed through the ISMS.

It also requires top management to show leadership and commitment, establish an information security policy, assign roles and authorities, plan actions to address risks and opportunities, and define a risk assessment and treatment process that leads to controls, a Statement of Applicability, a risk treatment plan, and acceptance of residual risk by risk owners.

ISO/IEC 27001 is useful when it turns those clause-level obligations into repeatable work: establish the ISMS, operate it with documented information where required, monitor and measure controls, conduct internal audits, hold management reviews, and take corrective action when nonconformity occurs.

  • Define the ISMS scope before assigning controls or requesting evidence, as required by Clause 4.3.
  • Tie each requirement to an owner, a documented process, and current evidence so the ISMS can be demonstrated as established, implemented, maintained, and continually improved.
  • Review the record at planned intervals and when significant changes are proposed or occur, because ISO/IEC 27001 requires risk assessments, management review, and corrective action to stay current.
Section 2

Which documented information and operating records matter?

ISO/IEC 27001 names some documented information explicitly: ISMS scope, policy, objectives, risk-assessment and treatment processes, assessment and treatment results, the SoA, treatment plan, competence evidence, monitoring results, internal-audit programme and results, management-review results, and nonconformity and corrective-action evidence.

Other records are kept to the extent needed for confidence that processes operated as planned. The right evidence therefore depends on the scoped process and selected controls; the standard does not prescribe one universal folder or template.

  • Control documented information for identification, format, review, approval, access, distribution, storage, preservation, change control, retention, and disposal.
  • Collect operating records from the real systems of work, with owner, date, scope, and result visible.
  • Keep evidence proportionate: enough to demonstrate the process and result without inventing records the standard does not require.
  • Preserve external documented information needed for the ISMS and control it appropriately.
Section 3

How should teams implement the requirements as one system?

Build the ISMS as connected processes: context and interested parties shape scope; leadership sets direction and resources; planning establishes risks, objectives, treatments, and the SoA; support enables competence and controlled information; operation implements plans; evaluation tests performance; improvement corrects and adapts the system.

Assign process owners and define the inputs and outputs between them. A changed service should flow through context and scope review, risk reassessment, treatment and SoA updates, operational control changes, monitoring, audit coverage, and management review where relevant.

  • Define each ISMS process, owner, criteria, required records, dependencies, and review triggers.
  • Use the same scope and risk identifiers across treatment, SoA, control, audit, and management-review records.
  • Plan changes under Clause 6.3 and control planned and unintended operational changes under Clause 8.1.
Section 4

Which requirement mistakes undermine a conformity claim?

An organization cannot exclude requirements in Clauses 4–10 when claiming conformity. It can define the ISMS boundary, but the scope must consider context, interested-party requirements, and interfaces and dependencies with other organizations.

Annex A is normative as a control reference used in the Clause 6.1.3 process, yet that does not make all 93 controls universally mandatory. Determine necessary controls first, compare them with Annex A, and justify exclusions in the SoA.

  • Do not confuse ISO/IEC 27002 guidance with the certifiable requirements in ISO/IEC 27001.
  • Do not claim certification, legal compliance, or whole-system security from a self-assessment or checklist.
  • Do not mark controls implemented without evidence that they operate in the stated scope.
Section 5

How does the ISMS remain current and improve?

Use monitoring results, objectives, audit findings, management-review outputs, nonconformities, and corrective-action effectiveness to test whether the management system still meets Clauses 4–10—not merely whether documents exist.

When context, interested-party requirements, scope, risk criteria, technology, suppliers, incidents, or objectives change, update the affected ISMS processes and retained documented information as one connected system.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide resourcing, risk appetite, scope changes, and evidence quality.
Recommended next step

Operationalize ISO/IEC 27001 Requirements

This ISO/IEC 27001 guide is the starting point for a tracked workflow: assign owners, request evidence, record decisions, and keep review dates visible instead of leaving the guidance in a document.

Primary sources

References and citations

iso.org
Referenced sections
  • This source is the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
"Information security management systems - Requirements"
iso.org
Referenced sections
  • This source supports control implementation guidance and control-implementation expectations supporting ISO/IEC 27001 governance.
"Information security controls"
iso.org
Referenced sections
  • This source supports risk treatment and monitoring context that informs control decisions and residual risk handling.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How should teams assign Annex A Control Ownership under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
How should teams handle Certification Body Evidence under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 Certification Stage Workflow
A practical ISO/IEC 27001 certification workflow for scope readiness, Stage 1 document review, Stage 2 evidence, nonconformities, corrective action, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001 compliance around ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, audits, management review, and corrective action evidence.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
How should teams handle Management Review under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 Risk Acceptance FAQ
How should teams handle Risk Acceptance under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
How should teams handle Surveillance Audits under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022’s certifiable ISMS requirements with NIST CSF 2.0’s voluntary cybersecurity outcomes, profiles, tiers, functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.