GuideGlobalISO/IEC 27001

ISO/IEC 27001 Requirements

ISO/IEC 27001:2022 requires an information security management system, not a universal control checklist. Clauses 4-10 govern context, leadership, planning, support, operation, evaluation, and improvement.

An organization can define a bounded ISMS scope, but it cannot exclude any requirement in Clauses 4-10 when claiming conformity. Annex A is a required comparison set during risk treatment, not a mandate to implement all 93 controls.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Apply the October 2022 third edition together with ISO/IEC 27001:2022/Amd 1:2024, published in February 2024. The IAF transition from the 2013 edition ended on 31 October 2025. The requirements are generic and apply to organizations of any type, size, or nature. To claim conformity, establish, implement, maintain, and continually improve every required process within the documented scope, and retain the documented information that the standard or the organization determines is necessary.

Section 1

What does each requirement group do?

Clauses 4-10 form one management system. Clause 4 determines context, relevant interested parties and requirements, scope, and the processes and interactions. The 2024 amendment adds a decision on whether climate change is a relevant issue and notes that relevant interested parties can have climate-change requirements.

Clause 5 makes top management responsible for leadership, policy, resources, integration into organizational processes, and assigned authorities. Clause 6 covers risks and opportunities for the , information-security risk assessment and treatment, objectives, and planned ISMS changes.

Clause 7 provides resources, competence, awareness, communication, and control of documented information. Clause 8 requires operational criteria and controls, implementation of the treatment plan, assessment at planned intervals and after significant change, and retention of assessment and treatment results.

Clause 9 requires monitoring and measurement, internal audit, and top-management review. Clause 10 requires continual improvement and a defined response to nonconformity, including cause evaluation and effectiveness review.

  • Clause 4 - Context: determine issues, interested parties, requirements, scope, processes, and interactions.
  • Clause 5 - Leadership: establish policy and accountability, integrate the , and provide direction and support.
  • Clause 6 - Planning: address risks and opportunities, assess and treat information-security risks, set objectives, and plan ISMS changes.
  • Clause 7 - Support: provide resources and competence, create awareness, plan communications, and control documented information.
  • Clause 8 - Operation: run planned processes, control relevant external provision and changes, reassess risk, and implement treatment.
  • Clauses 9 and 10 - Evaluation and improvement: measure performance, audit, review, correct nonconformities, and improve the .
Section 2

Which documented information and operating records matter?

ISO/IEC 27001 explicitly requires documented information for the scope; information security policy and objectives; risk-assessment and treatment processes and results; the SoA; treatment plan; competence; monitoring and measurement results; internal-audit program and results; management-review results; and nonconformity and corrective-action results.

Clause 8.1 also requires documented information to the extent needed for confidence that operational processes ran as planned. Clause 7.5 adds any documented information the organization decides is necessary for effectiveness. Evidence for selected controls therefore depends on the actual control design and scope; the standard does not prescribe one folder structure or template.

  • Give documented information appropriate identification, description, format, media, review, and approval.
  • Control availability and protection and, as applicable, distribution, access, retrieval, use, storage, preservation, change, retention, and disposition.
  • Collect operating records from the real systems of work, with owner, date, scope, and result visible.
  • Keep enough evidence to demonstrate the applicable process and result without treating optional governance fields as requirements.
  • Preserve external documented information needed for the and control it appropriately.
Section 3

How should teams implement the requirements as one system?

Implement the requirements as connected processes. Context and interested parties shape scope; leadership sets direction and resources; planning establishes risks and opportunities, information-security risks, objectives, treatments, and the SoA; support supplies competence and controlled information; operation implements plans; evaluation tests performance; improvement corrects and adapts the system.

Define each process and its interactions. For example, a material service change can require context and scope review, risk reassessment, treatment and SoA updates, operational changes, revised monitoring, and later audit or management-review attention. Which steps apply depends on the change and the organization's planned processes.

  • Define each process, owner, criteria, required records, dependencies, and review triggers.
  • Use consistent scope and risk references across treatment, SoA, control, audit, and management-review records.
  • Carry out needed changes in a planned manner under Clause 6.3; under Clause 8.1, control planned operational changes and review unintended changes.
Section 4

Which requirement mistakes undermine a conformity claim?

An organization cannot exclude requirements in Clauses 4-10 when claiming conformity. It can define the boundary, but the scope must consider context, relevant interested-party requirements, and interfaces and dependencies with other organizations.

Annex A is normative as a control reference used in the Clause 6.1.3 process, yet that does not make all 93 controls universally mandatory. Determine necessary controls first, compare them with Annex A, and justify exclusions in the SoA.

  • Do not confuse ISO/IEC 27002 guidance with the certifiable requirements in ISO/IEC 27001.
  • Do not claim certification from a self-assessment. Certification requires an audit by a certification body, and neither a checklist nor certification automatically establishes compliance with every law or contract.
  • Do not mark controls implemented without evidence that they operate in the stated scope.
Section 5

How does the ISMS remain current and improve?

Clause 9.1 requires the organization to decide what to monitor and measure, the methods, timing, and responsible roles, then evaluate information-security performance and effectiveness. Internal audits test conformity and effective implementation; management review tests continuing suitability, adequacy, and effectiveness.

When a nonconformity occurs, Clause 10.2 requires correction and consequence handling as applicable, cause evaluation, needed action, effectiveness review, and changes where necessary. Continual improvement applies to the ISMS's suitability, adequacy, and effectiveness, not to document volume.

  • Set monitoring methods, responsibilities, and timing so results are valid and can be evaluated.
  • Run internal audits at planned intervals with defined criteria and scope, objective and impartial auditors, management reporting, and retained results.
  • Give management review every required input and retain its decisions on improvement opportunities and needed changes.
  • Do not relabel a nonconformity as accepted risk; correct the conformity failure and address the related risk through the risk process.
Recommended next step

Connect each requirement to the operating ISMS

Assign process owners, retain the records required by each clause, connect risk and control decisions, and keep monitoring, audit, review, and corrective-action results current.

Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 9 and 10 establish performance evaluation, internal audit, management review, continual improvement, and nonconformity and corrective-action requirements.
"suitability, adequacy and effectiveness"
iso.org
Referenced sections
  • Official listing for the February 2024 amendment. It applies to ISO/IEC 27001:2022 and adds climate-change consideration to Clauses 4.1 and 4.2.
"This amendment applies to ISO/IEC 27001:2022"
iso.org
Referenced sections
  • ISO/IEC 27002 is control guidance. It can support implementation but is not the certifiable requirements standard.
"Information security controls"
iso.org
Referenced sections
  • Official listing for optional information-security risk-management guidance that can support the ISO/IEC 27001 risk process.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.