- IAF confirms that the 2022 reference set contains 93 controls in four clauses and explains that the Annex A comparison checks for omitted necessary controls.
"93 controls in 4 clauses"
ISO/IEC 27001:2022 requires an information security management system, not a universal control checklist. Clauses 4-10 govern context, leadership, planning, support, operation, evaluation, and improvement.
An organization can define a bounded ISMS scope, but it cannot exclude any requirement in Clauses 4-10 when claiming conformity. Annex A is a required comparison set during risk treatment, not a mandate to implement all 93 controls.
Structured answer sets in this page tree.
Cited legal and guidance references.
Apply the October 2022 third edition together with ISO/IEC 27001:2022/Amd 1:2024, published in February 2024. The IAF transition from the 2013 edition ended on 31 October 2025. The requirements are generic and apply to organizations of any type, size, or nature. To claim conformity, establish, implement, maintain, and continually improve every required process within the documented scope, and retain the documented information that the standard or the organization determines is necessary.
Clauses 4-10 form one management system. Clause 4 determines context, relevant interested parties and requirements, scope, and the processes and interactions. The 2024 amendment adds a decision on whether climate change is a relevant issue and notes that relevant interested parties can have climate-change requirements.
Clause 5 makes top management responsible for leadership, policy, resources, integration into organizational processes, and assigned authorities. Clause 6 covers risks and opportunities for the , information-security risk assessment and treatment, objectives, and planned ISMS changes.
Clause 7 provides resources, competence, awareness, communication, and control of documented information. Clause 8 requires operational criteria and controls, implementation of the treatment plan, assessment at planned intervals and after significant change, and retention of assessment and treatment results.
Clause 9 requires monitoring and measurement, internal audit, and top-management review. Clause 10 requires continual improvement and a defined response to nonconformity, including cause evaluation and effectiveness review.
ISO/IEC 27001 explicitly requires documented information for the scope; information security policy and objectives; risk-assessment and treatment processes and results; the SoA; treatment plan; competence; monitoring and measurement results; internal-audit program and results; management-review results; and nonconformity and corrective-action results.
Clause 8.1 also requires documented information to the extent needed for confidence that operational processes ran as planned. Clause 7.5 adds any documented information the organization decides is necessary for effectiveness. Evidence for selected controls therefore depends on the actual control design and scope; the standard does not prescribe one folder structure or template.
Implement the requirements as connected processes. Context and interested parties shape scope; leadership sets direction and resources; planning establishes risks and opportunities, information-security risks, objectives, treatments, and the SoA; support supplies competence and controlled information; operation implements plans; evaluation tests performance; improvement corrects and adapts the system.
Define each process and its interactions. For example, a material service change can require context and scope review, risk reassessment, treatment and SoA updates, operational changes, revised monitoring, and later audit or management-review attention. Which steps apply depends on the change and the organization's planned processes.
An organization cannot exclude requirements in Clauses 4-10 when claiming conformity. It can define the boundary, but the scope must consider context, relevant interested-party requirements, and interfaces and dependencies with other organizations.
Annex A is normative as a control reference used in the Clause 6.1.3 process, yet that does not make all 93 controls universally mandatory. Determine necessary controls first, compare them with Annex A, and justify exclusions in the SoA.
Clause 9.1 requires the organization to decide what to monitor and measure, the methods, timing, and responsible roles, then evaluate information-security performance and effectiveness. Internal audits test conformity and effective implementation; management review tests continuing suitability, adequacy, and effectiveness.
When a nonconformity occurs, Clause 10.2 requires correction and consequence handling as applicable, cause evaluation, needed action, effectiveness review, and changes where necessary. Continual improvement applies to the ISMS's suitability, adequacy, and effectiveness, not to document volume.
Assign process owners, retain the records required by each clause, connect risk and control decisions, and keep monitoring, audit, review, and corrective-action results current.
Convert ISO/IEC 27001 requirements into accountable tasks, evidence requests, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
"93 controls in 4 clauses"
"suitability, adequacy and effectiveness"
"This amendment applies to ISO/IEC 27001:2022"
"Information security controls"
"Guidance on managing information security risks"