Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.
At a glance
| Item | Detail |
|---|---|
| Standard | ISO/IEC 27001:2022, the requirements for an information security management system (ISMS). Third edition, published in October 2022. |
| Amendment | Amendment 1:2024, Climate action changes, published in February 2024. Read it together with the 2022 text. |
| Requirements | Clauses 4 to 10. An organisation that claims conformity has to meet all of them. |
| Annex A | A reference list of 93 information security controls in four themes. You choose controls by risk and justify each decision in a Statement of Applicability. |
| Guidance | ISO/IEC 27002:2022 explains each Annex A control and ISO/IEC 27005:2022 explains information security risk management. Both are guidance; certification is to ISO/IEC 27001 only. |
| Certification | Optional. Carried out by certification bodies, which can be accredited; ISO itself does not certify. A certificate runs on a three-year cycle with yearly surveillance audits. |
| Previous edition | ISO/IEC 27001:2013, now withdrawn. Accredited certificates to it expired or were withdrawn when the transition period ended on 31 October 2025. |
What an ISMS is
An information security management system is the way an organisation runs information security as a managed activity rather than a collection of tools. It sets a scope, a policy and objectives, gives people roles, assesses information security risks, chooses and operates controls to treat them, measures whether they work, audits itself, and has management review the results and correct what falls short.
The point, in ISO's own description of the standard, is to protect the confidentiality, integrity and availability of information through a risk management process, and to show customers and other interested parties that those risks are being managed.
The standard applies to organisations of any size and in any sector. It does not tell you which technologies to use or how much security is enough. It tells you how to decide, and how to show that you decided and followed through.
Certification is a choice. Some organisations use the standard as a framework without certifying; others certify because customers, tenders or partners ask for a certificate.
Clauses 4 to 10
After a short introduction, clauses 1 to 3 set out the standard's scope, refer to ISO/IEC 27000 for vocabulary and define terms. Clauses 4 to 10 hold the requirements. They follow the harmonised structure ISO uses for its management system standards, so anyone who knows ISO 9001 or ISO 14001 will recognise the headings.
| Clause | Title | What it covers |
|---|---|---|
| 4 | Context of the organisation | Internal and external issues, interested parties and their requirements, and the boundaries of the ISMS: its scope. |
| 5 | Leadership | Top management's commitment, the information security policy, and who is responsible for what. |
| 6 | Planning | The risk assessment and risk treatment processes, the Statement of Applicability, security objectives and planned changes to the ISMS. |
| 7 | Support | Resources, competence, awareness, communication and control of documented information. |
| 8 | Operation | Running the planned processes, carrying out risk assessments and putting the risk treatment plan into effect. |
| 9 | Performance evaluation | Monitoring and measurement, internal audit and management review. |
| 10 | Improvement | Continual improvement, and dealing with nonconformities through corrective action. |
The requirements guide takes each clause in turn, with the documents and records an auditor will expect to see.
Annex A at a glance
Annex A is a reference list of information security controls: a number, a short title and a one-line statement for each. ISO/IEC 27002:2022 gives the purpose of each control and guidance on implementing it. The 2022 edition has 93 controls in four themes.
| Theme | Section | Controls | Examples |
|---|---|---|---|
| Organisational | A.5 | 37 | Information security policies, threat intelligence, asset inventory, access control, supplier relationships, incident management |
| People | A.6 | 8 | Screening, terms and conditions of employment, awareness and training, remote working |
| Physical | A.7 | 14 | Physical entry, clear desk and clear screen, equipment siting and protection, secure disposal or re-use of equipment |
| Technological | A.8 | 34 | User endpoint devices, technical vulnerabilities, configuration management, logging, network security, cryptography, secure development |
Annex A is not a list to implement in full. Clause 6.1.3 has you decide which controls your risk treatment needs, from any source, and then compare them with Annex A so that nothing necessary is missed. The Statement of Applicability records every Annex A control, whether it applies, whether it is in place, and why. The Annex A controls guide goes through the four themes.
The 2022 edition and Amendment 1
ISO/IEC 27001:2022 was published on 25 October 2022 and replaced the 2013 edition. The clauses changed little; most edits brought the text into line with the harmonised structure. The main changes were these.
- Annex A was replaced to match ISO/IEC 27002:2022: 93 controls in four themes, where the 2013 edition had 114 controls in 14 groups. Eleven controls are new, among them threat intelligence, information security for use of cloud services, configuration management, data leakage prevention, monitoring activities and secure coding.
- A new clause, 6.3 Planning of changes, asks that changes to the ISMS are made in a planned way.
- Clause 4.2 now also asks which of the interested parties' requirements the ISMS will address.
- Clause 8.1 now covers externally provided processes, products and services, in place of the narrower term outsourced processes.
- Clauses 9.2 and 9.3 were divided into named subclauses, for the internal audit programme and for management review inputs and results.
The International Accreditation Forum (IAF) set a three-year transition in its mandatory document IAF MD 26. From 30 April 2024 certification bodies could carry out initial certification and recertification to the 2022 edition only, and every certificate to the 2013 edition expired or was withdrawn when the transition ended on 31 October 2025. A valid accredited certificate today is to the 2022 edition.
Amendment 1:2024
Amendment 1:2024, Climate action changes, was published in February 2024 as part of a change ISO made to many management system standards at once. It adds two things to clause 4: the organisation decides whether climate change is a relevant issue for its ISMS, and a note that interested parties can have requirements related to climate change. ISO and the IAF said in a joint communiqué that the intent of clauses 4.1 and 4.2 is unchanged; the addition makes sure climate change is considered rather than overlooked.
In practice, make the decision deliberately and keep a note of it, with your reasoning, alongside your analysis of context and interested parties, so you can show an auditor how you reached it.
How certification works
ISO writes the standard; it does not certify anyone and issues no certificates. Certification is carried out by certification bodies. A certification body can in turn be accredited: a national accreditation body, which in the UK is UKAS, assesses it against ISO/IEC 17021-1, the requirements for bodies that audit and certify management systems, and ISO/IEC 27006-1:2024, which adds the requirements specific to information security management systems.
Accreditation is not compulsory, but ISO notes that a certificate from an accredited body carries extra confidence, because an independent body has confirmed the certification body's competence. You can find accredited certification bodies, and check a certificate, through UKAS or through IAF CertSearch. Since 1 January 2026 the IAF's role has been taken over by the Global Accreditation Cooperation Incorporated (Global ACI); CertSearch continues.
The initial audit
- Stage 1. The auditor reviews your ISMS documentation and scope, checks your understanding of the requirements, collects what is needed to plan stage 2, and judges whether you are ready for it, including whether internal audits and management reviews are being planned and carried out. Concerns left unresolved can become nonconformities at stage 2.
- Stage 2. The auditor evaluates whether the ISMS is implemented and effective, usually at your premises: records, interviews, samples of controls in operation, monitoring results, internal audit and management review.
- Nonconformities. Before the certification body decides, major nonconformities must be corrected and their corrective actions verified; for minor ones it reviews and accepts your plan for corrective action.
- Decision. The certification body makes the certification decision and issues a certificate that states the scope of the ISMS and the edition of the standard.
The three-year cycle
| When | Audit | What it does |
|---|---|---|
| Start | Initial audit, stage 1 and stage 2 | Leads to the certification decision, which starts the three-year cycle. |
| First year | Surveillance audit | No later than 12 months after the certification decision. Not a full audit: it samples the ISMS and always looks at internal audit, management review and action on earlier nonconformities. |
| Second year | Surveillance audit | At least once in each calendar year that is not a recertification year, on the same basis. |
| Third year | Recertification audit | Before the certificate expires. Reviews the whole ISMS and its performance over the cycle; a successful recertification starts a new cycle. |
Between audits the certificate depends on the ISMS continuing to run: risk assessments repeated, internal audits and management reviews held, nonconformities closed. A certification body suspends a certificate when, for example, the organisation stops meeting the requirements or does not allow surveillance or recertification audits to take place, and withdraws it if the problem is not resolved.
Where technical evidence helps
Most of ISO 27001 is organisational: decisions, ownership, processes and records. A small part of Annex A concerns technology that can be observed from outside, and there an automated external check gives you dated, repeatable evidence. Whether each item supports a control depends on the controls in your Statement of Applicability.
ISO 27001 evidence
Ironfang can check
- TLS versions, cipher suites and certificates on public services, for cryptography in transit (A.8.24 Use of cryptography).
- HTTP security headers, cookie attributes, DNSSEC and CAA records, as evidence of secure public configuration (A.8.9 Configuration management).
- Software versions visible from outside and known end-of-life releases, as input to technical vulnerability management (A.8.8).
- For a verified domain, whether databases, remote access and other services on a fixed list of ports answer from the internet (A.8.20 Networks security).
- SPF, DKIM and DMARC for your domains, where your controls for information transfer cover email (A.5.14).
- Subdomains in certificate transparency logs and dangling DNS records, to test your asset inventory against what is public (A.5.9).
- A dated history of results and rechecks, usable as monitoring records for these measures (clause 9.1).
The organisation must establish
- The ISMS scope, context and interested parties.
- The information security policy, objectives and roles.
- Risk criteria, the risk assessment, the risk treatment plan and risk owners' approval.
- The Statement of Applicability and the reasoning behind every decision in it.
- Competence, awareness and training records.
- Internal audits, management reviews, nonconformities and corrective actions.
- Every control that cannot be seen from the internet: people, suppliers, physical security, endpoints, internal networks and cloud accounts.
A clean result does not prove conformity with any control. An auditor will want to see how you use the results: who reviews findings, how fixes are prioritised against your risk criteria, and how exceptions are accepted. The External Security Check verifies a domain, reports each finding with evidence, severity and a fix, keeps the history, and can recheck verified domains on a schedule.
- Website security checker Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.
- Email security checker Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- SSL/TLS checker Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- End-of-life software checker See whether a site advertises software versions that no longer receive security fixes.
- Exposed services checker Check your domain for databases, remote desktop and other services open to the internet, once it is verified.
- Subdomain finder Find a domain's subdomains in public certificate transparency logs.
Where to start
- Decide why you are doing it and what the ISMS will cover: its scope.
- Set risk criteria, list your assets and interested parties and carry out a risk assessment.
- Decide on risk treatment and controls, and write the Statement of Applicability.
- Put the controls into operation and keep the records.
- Measure, run an internal audit and hold a management review: performance evaluation.
- Carry out a gap analysis and work through the checklist.
- Choose an accredited certification body and agree dates for stage 1.
Stage 2 tests whether the ISMS is working, not only whether it is written down, so allow time for at least one full round of risk assessment, internal audit and management review before it.
Sources
Checked on the review date above. Standards and schemes change; the source is the authority.
- ISO: ISO/IEC 27001:2022, Information security management systems
- ISO: ISO/IEC 27001:2022/Amd 1:2024, Climate action changes
- ISO and IAF: joint communiqué on the addition of climate change considerations to management system standards (February 2024)
- ISO: ISO/IEC 27002:2022, Information security controls
- ISO: ISO/IEC 27005:2022, Guidance on managing information security risks
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
- ISO: Certification
- ISO: ISO/IEC 17021-1:2015, Requirements for bodies providing audit and certification of management systems
- ISO: ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems
- UKAS: Certification body accreditation
- Global Accreditation Cooperation Incorporated (Global ACI)

