Reviewed October 2026. Applies to: ISO/IEC 27001:2022, with Amendment 1:2024.
How the standard is organised
After a short introduction, clauses 1 to 3 set out the standard's scope, its one normative reference (ISO/IEC 27000, for vocabulary) and its terms. Clauses 4 to 10 contain the requirements. Annex A lists the reference controls.
An organisation that claims conformity has to meet every requirement in clauses 4 to 10; none of them can be left out. Annex A works differently: a control in it can be excluded where your risk treatment does not need it, as long as the Statement of Applicability says why.
The clauses follow the harmonised structure shared by ISO management system standards, so the same headings appear in ISO 9001 and ISO 14001. The information security specifics sit mostly in clauses 6 and 8 and in Annex A.
Context and interested parties (clauses 4.1, 4.2 and 4.4)
Clause 4.1 asks you to work out the internal and external issues that affect what your ISMS is meant to achieve: your business model, where you operate, your technology and suppliers, the threats you face, legal and regulatory pressure. Since Amendment 1:2024 it also asks you to decide whether climate change is one of those issues.
Clause 4.2 asks who has a stake in your information security (customers, staff, regulators, suppliers, insurers, owners), what they require of you, and which of those requirements the ISMS will address. Contracts, data protection law and sector rules usually supply most of the list. The amendment adds a note that some of these requirements may relate to climate change.
Clause 4.4 is the overall requirement to set up, run, maintain and keep improving the ISMS as a set of processes that work together.
No document is mandatory for 4.1 and 4.2, but a short register of issues and interested parties shows the analysis was done and carries it into the scope and the risk assessment.
Scope of the ISMS (clause 4.3)
The scope sets the boundaries of the ISMS: which parts of the organisation, which locations, which services and products, which systems and which information it covers. When you set it, take account of the issues from 4.1, the requirements from 4.2, and the points where your work connects to or depends on other organisations, such as cloud platforms, outsourced IT and payment processors. The scope has to be written down.
The scope matters beyond the ISMS itself. It is what a certificate states, and what a customer reads to see whether the service they buy is covered. A scope that leaves out the systems customers care about can produce a certificate that answers the wrong question.
Writing a scope statement
- Name the organisation, or the part of it, and the services or products in scope.
- Name the locations, including remote working if staff work from home.
- Describe the information and the main systems, including the cloud services you run on.
- Describe the interfaces: what suppliers do for you, and where your responsibility ends.
- State any exclusions and why they do not weaken the ISMS.
An example: "The ISMS covers the design, development, operation and support of the company's online invoicing service, delivered from its London office and by staff working remotely, including the production environment hosted on a public cloud platform. Office facilities management is outside the scope."
Before you settle the scope, check what is actually public. Subdomains in certificate transparency logs and DNS records often show services nobody listed, and each one either belongs in the scope or needs a reason to be outside it.
- Subdomain finder Find a domain's subdomains in public certificate transparency logs.
- DNS checker Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.
- Technology detector See the web server, CDN and frameworks a site's home page discloses.
Leadership (clause 5)
Clause 5.1 asks top management to lead the ISMS, not just approve it: set the policy and objectives in line with the organisation's direction, build the ISMS into everyday business processes, provide resources, explain why information security matters, make sure the ISMS delivers what it is for, support the people who run it and push for improvement.
Clause 5.2 asks top management to set an information security policy that fits the organisation, either contains the security objectives or gives a framework for setting them, and commits to meeting the requirements that apply and to continual improvement. The policy is written down, communicated inside the organisation and made available to interested parties where that is appropriate.
Clause 5.3 asks top management to assign security responsibilities and authorities and make them known, including who makes sure the ISMS conforms to the standard and who reports on its performance to top management.
Auditors test this clause by talking to top management; minuted decisions, approved budgets and management review records are the evidence.
Planning (clause 6)
Clause 6.1.1 asks you to use the issues and requirements from clause 4 to decide which risks and opportunities the ISMS itself must deal with, plan actions for them, and plan how you will tell whether those actions worked.
Clause 6.1.2 is the information security risk assessment process. You set risk criteria, including when a risk is acceptable; make the method repeatable so that results can be compared over time; identify risks to the confidentiality, integrity and availability of information in scope; give each risk an owner; judge consequence and likelihood to reach a level of risk; and compare that level with your criteria to set priorities.
Clause 6.1.3 is the risk treatment process. You choose how to treat each risk, work out which controls that needs, compare them with Annex A so nothing necessary is missed, produce a Statement of Applicability, write a risk treatment plan, and have risk owners approve the plan and accept the risk that remains.
Clause 6.2 asks for information security objectives that follow from the policy and the risk results, can be measured where that is practical, and are tracked, shared and revised. Each needs a plan saying what will be done, by whom, with what resources, by when, and how success will be judged.
Clause 6.3, new in 2022, asks that changes to the ISMS are planned rather than made as they come up.
The risk assessment guide sets out a method for 6.1.2 and 6.1.3, and the Annex A controls guide covers the Statement of Applicability.
Support (clause 7)
| Subclause | What it asks | Typical evidence |
|---|---|---|
| 7.1 Resources | Provide the people, time, budget and tools the ISMS needs. | Budget and staffing decisions, often recorded at management review. |
| 7.2 Competence | Decide what competence roles affecting information security need, make sure people have it through education, training or experience, and act on gaps. | Role descriptions, training and qualification records. |
| 7.3 Awareness | Make sure people know the policy, how their work contributes, and what follows if they do not keep to the ISMS. | Induction and awareness training records, policy acknowledgements. |
| 7.4 Communication | Decide what is communicated about information security, when, to whom and how. | A communication plan or matrix. |
| 7.5 Documented information | Create, review, approve and control the documents and records the ISMS needs, including those from outside sources. | A document register, version history, access rules for documents. |
Controlling documented information means the right version is available where it is needed, protected, and changed, kept and disposed of in a managed way. How much you write is yours to decide: the standard accepts that it depends on the organisation's size, complexity and people. A small company can run an ISMS on a handful of documents.
Operation (clause 8)
Clause 8 is where the plans from clause 6 are carried out. It is short in the standard and large in practice, because it covers running every control you chose.
- 8.1 Operational planning and control: plan and run the processes the ISMS needs, set criteria for them and control them against those criteria. Keep enough records to show they ran as planned. Manage planned changes, deal with the effects of unplanned ones, and control the externally provided processes, products and services that matter to the ISMS, such as cloud hosting, managed IT and software suppliers.
- 8.2 Information security risk assessment: carry out risk assessments at planned intervals and whenever significant changes are proposed or happen, using the criteria set under 6.1.2. Keep the results.
- 8.3 Information security risk treatment: put the risk treatment plan into effect and keep the results.
Evidence here is operational: change records, access reviews, supplier assessments, backup and restore tests, vulnerability scans and patch records, incident tickets, training logs. At stage 2 an auditor samples these to see whether the controls in the Statement of Applicability are actually working. The Annex A controls guide describes the controls themselves.
Performance evaluation (clause 9)
Monitoring and measurement (9.1)
Decide what you will monitor and measure, including processes and controls; the methods, chosen so that results are sound and comparable; when it happens and who does it; and when and by whom the results are analysed. Keep the results, and use them to judge both how well information security is performing and whether the ISMS is effective.
A few measures that change decisions are worth more than many that do not: the share of critical vulnerabilities fixed within target, accounts without multi-factor authentication, phishing reports, overdue access reviews, time to close incidents.
Internal audit (9.2)
Audit the ISMS at planned intervals to find out whether it meets your own requirements and the standard's, and whether it is implemented and maintained effectively. Plan an audit programme covering how often, by what method, who is responsible and how results are reported, giving weight to the processes that matter most and to what earlier audits found. Set criteria and scope for each audit, choose auditors who are objective and impartial, report results to the managers concerned, and keep evidence of the programme and its results.
Nobody should audit their own work. Small organisations often bring in an outside auditor to run the internal audit, or have people audit areas they are independent of.
Management review (9.3)
Top management reviews the ISMS at planned intervals to make sure it still fits the organisation, is sufficient and works. The review looks at:
- progress on actions from earlier reviews;
- changes in internal and external issues, and in interested parties' needs and expectations, that affect the ISMS;
- information security performance: nonconformities and corrective actions, monitoring and measurement results, audit results and progress on objectives;
- feedback from interested parties;
- the results of risk assessment and the state of the risk treatment plan;
- opportunities to improve.
The outputs are decisions on improvement and on any changes the ISMS needs, and a record of the results is kept. Stage 1 of a certification audit checks whether internal audits and management reviews are being planned and carried out, so complete at least one of each before it.
Monitoring evidence
Ironfang can check
- Dated results for the public side of technical controls: DNS, email authentication, TLS, HTTP security headers, detected technologies and end-of-life software.
- For a verified domain, whether services on a fixed list of high-risk ports answer from the internet.
- Rechecks that show when a finding was fixed, and notifications from continuous monitoring when something changes.
The organisation must establish
- What to monitor and measure, and why, linked to objectives and risks.
- Who analyses the results, when, and what happens next.
- The internal audit programme, audit reports and the auditors' independence.
- Management review inputs, decisions and actions.
Results from the External Security Check can be one input to 9.1 for the controls they cover. They do not measure the ISMS as a whole.
Improvement (clause 10)
Clause 10.1 asks you to keep improving how well the ISMS fits the organisation, whether it is sufficient and how well it works.
Clause 10.2 covers nonconformities: any failure to meet a requirement of the standard or of your own ISMS, whether found by an audit, by monitoring or through an incident. Deal with it and its consequences; find out why it happened and whether it has happened, or could happen, elsewhere; take action in proportion to its effects so it does not recur; check the action worked; and change the ISMS if needed. Keep a record of what went wrong, what you did and the outcome.
A corrective action log kept up to date is one of the most useful records an auditor can see: it shows the ISMS finding and fixing its own problems.
Documented information the standard requires
The standard uses the term documented information for both the documents you maintain, such as the policy, and the records you keep as evidence, such as audit results. Clauses 4 to 10 call for the following. Annex A controls you select may call for more, such as operating procedures or an asset inventory.
| Clause | Documented information | Kind |
|---|---|---|
| 4.3 | The scope of the ISMS | Document |
| 5.2 | The information security policy | Document |
| 6.1.2 | The risk assessment process, including the risk criteria | Document |
| 6.1.3 | The risk treatment process | Document |
| 6.1.3 | The Statement of Applicability | Document |
| 6.2 | The information security objectives | Document |
| 7.2 | Evidence of competence | Record |
| 7.5.1 | Any other documents and records you decide the ISMS needs | Either |
| 8.1 | Enough information to show processes ran as planned | Record |
| 8.2 | The results of risk assessments | Record |
| 8.3 | The results of risk treatment | Record |
| 9.1 | Monitoring and measurement results | Record |
| 9.2.2 | Evidence the audit programme was carried out, and the audit results | Record |
| 9.3.3 | The results of management reviews | Record |
| 10.2 | Nonconformities, the action taken and the results of corrective action | Record |
The risk treatment plan and the risk owners' approval of it are not listed on their own, but you will need to show both: clause 6.1.3 requires them and clause 8.3 requires a record of the results.
Some documents are worth having even though no clause names them: an asset inventory, a register of issues and interested parties, a risk register, and procedures for the controls that need them. The ISO 27001 checklist covers them in a readiness review.
Sources
Checked on the review date above. Standards and schemes change; the source is the authority.

