ISO 27001 guide
ISO 27001:2022 clauses guide
Clauses 4 to 10 are the certifiable requirements of ISO/IEC 27001:2022, the ISMS itself. What each clause asks for, in plain language, and what auditors check.
By Sentrix · Published 2026-07-16
Clauses or Annex A? The distinction that changes everything
In plain language: you do not get certified “against Annex A.” You get certified against clauses 4 through 10. Annex A is a toolbox the ISMS draws from to address its own risks.
| Clauses 4 to 10 | Annex A |
|---|---|
| Mandatory, auditable requirements | Catalogue of reference measures (93 controls) |
| Describe the ISMS: how you manage security | Describe controls: what to put in place |
| Written with “shall” — not negotiable | Selected through the Statement of Applicability (SoA) |
| The heart of the certification audit | Justified (included/excluded) based on risk |
Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but contain no auditable requirements. The certifiable requirements start at clause 4.
The thread that ties it together: the PDCA cycle
The seven clauses are not an arbitrary list — they follow the Plan-Do-Check-Act (PDCA) continuous improvement logic shared by every ISO management-system standard. Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.
- Plan — clauses 4 to 6: understand your context, secure leadership commitment, and set objectives and risk treatment.
- Do — clauses 7 and 8: provide resources and competence, then run the system day to day.
- Check — clause 9: measure, audit internally, and review with leadership.
- Act — clause 10: correct gaps and improve continuously.
The 7 certifiable clauses, in plain language
Every clause links to its own page, and from there to each of its sub-clauses. Use this guide as a standing table of contents for the whole standard.
Clause 4 · Context of the organization
Before building anything, you have to understand who you are, what surrounds you, and what your interested parties expect. This clause asks you to identify internal and external issues relevant to your information security, map the parties whose expectations matter (clients, regulators, shareholders), and use that understanding to draw the boundaries of your ISMS — which systems, sites, and services it actually covers.
Clause 5 · Leadership
An ISMS that top management does not actively own is a documentation exercise, not a management system. This clause requires visible leadership commitment, a published information security policy, and clearly assigned roles and responsibilities — so accountability for security does not sit with a single person by default.
Clause 6 · Planning
This is where risk assessment and treatment happen: identifying risks to your information assets, evaluating them, and deciding how to address them. It also covers setting measurable security objectives and producing the Statement of Applicability (SoA) — the document justifying which of the 93 Annex A controls you include or exclude, and why.
Clause 7 · Support
The ISMS needs resources to run: people with the right competence, staff who are aware of their security responsibilities, a communication plan for security matters, and — crucially for the audit — properly controlled documented information (policies, procedures, records) that is current, approved, and accessible to the people who need it.
Clause 8 · Operation
This is where planning turns into practice: executing the risk treatment plan, controlling operational changes so they do not introduce new gaps, and re-running risk assessments at planned intervals or when significant changes occur. It is the clause auditors use to check that the ISMS is actually operating, not just documented.
Clause 9 · Performance evaluation
You have to prove the ISMS works, not just claim it does. This clause requires ongoing monitoring and measurement of security performance, a formal internal audit program covering the whole ISMS on a planned cycle, and a documented management review where leadership examines results and decides what needs to change. Internal audit findings here are usually the single best predictor of how the certification audit will go.
Clause 10 · Improvement
When something does not conform — a control fails, an audit finds a gap, an incident exposes a weakness — this clause requires you to react, correct it, and address the root cause so it does not recur. Combined with clause 9, this is what makes the ISMS a living system rather than a one-time project: nonconformities get logged, treated, and closed, and the cycle starts again.
The mandatory documents the clauses require
Certain clauses explicitly require documented information. An auditor will systematically ask for these. The main ones:
- The ISMS scope (clause 4.3)
- The information security policy (clause 5.2)
- The risk assessment and treatment process (clause 6.1)
- The Statement of Applicability — SoA (clause 6.1.3)
- The information security objectives (clause 6.2)
- Evidence of competence (clause 7.2)
- Documented information necessary for operation (clause 8.1)
- The results of risk assessment and treatment (clauses 8.2 and 8.3)
- Evidence of monitoring and measurement (clause 9.1)
- The internal audit program and results (clause 9.2)
- The results of management reviews (clause 9.3)
- Nonconformities and corrective actions (clause 10.2)
How to use this guide
- You are new to the standard: read the clauses in order — they tell a story, from context (4) to improvement (10).
- You are preparing for the audit: focus on clause 9 (internal audit, management review) and the mandatory documents list above.
- You came from Annex A: remember that controls are worthless without the ISMS these clauses describe.
Going further
The ISO 27001 framework page presents the standard, certification and the 93 Annex A controls. For support on the road to certification, see the ISO 27001 compliance service or contact us.
Sources
ISO 27001 guide · Plan
Clause 4 — Context of the organization
ISO 27001:2022 clause 4 covers your context, your interested parties and the ISMS scope: the foundation every other clause of the standard builds on.
Learn more →
ISO 27001 guide · Clause 4
4.1 — Understanding the organization and its context
ISO 27001:2022 sub-clause 4.1 requires identifying the external and internal issues relevant to your ISMS, including, since Amendment 1:2024, climate change.
Learn more →
ISO 27001 guide · Clause 4
4.2 — Needs and expectations of interested parties
ISO 27001:2022 sub-clause 4.2 requires identifying interested parties and their requirements, and, new in 2022, deciding which ones the ISMS will address.
Learn more →
ISO 27001 guide · Clause 4
4.3 — Determining the scope of the ISMS
ISO 27001:2022 sub-clause 4.3 requires determining the boundaries and applicability of the ISMS to establish its scope, plus the evidence auditors request.
Learn more →
ISO 27001 guide · Clause 4
4.4 — Information security management system
ISO 27001:2022 sub-clause 4.4 requires establishing, implementing, maintaining and improving an ISMS built around defined processes and their interactions.
Learn more →
ISO 27001 guide · Plan
Clause 5 — Leadership
ISO 27001:2022 clause 5 covers leadership commitment, the information security policy and assigned roles: the accountability every other clause depends on.
Learn more →
ISO 27001 guide · Clause 5
5.1 — Leadership and commitment
ISO 27001:2022 sub-clause 5.1 requires top management to demonstrate leadership and commitment to the ISMS through eight specific, checkable actions.
Learn more →
ISO 27001 guide · Clause 5
5.2 — Information security policy
ISO 27001:2022 sub-clause 5.2 requires a published information security policy appropriate to your organization and committed to continual improvement.
Learn more →
ISO 27001 guide · Clause 5
5.3 — Organizational roles, responsibilities and authorities
ISO 27001:2022 sub-clause 5.3 requires security roles, responsibilities and authorities to be assigned, communicated and reported back to top management.
Learn more →
ISO 27001 guide · Plan
Clause 6 — Planning
ISO 27001:2022 clause 6 covers risk assessment and treatment, the Statement of Applicability (SoA) and measurable security objectives, explained in plain terms.
Learn more →
ISO 27001 guide · Clause 6
6.1 — Actions to address risks and opportunities
ISO 27001:2022 sub-clause 6.1 requires assessing and treating information security risks and opportunities: how 6.1.1, 6.1.2 and 6.1.3 fit together.
Learn more →
ISO 27001 guide · Clause 6
6.1.1 — General
ISO 27001:2022 sub-clause 6.1.1 sets the general provisions for how risks and opportunities are addressed: the frame that 6.1.2 and 6.1.3 operate inside.
Learn more →
ISO 27001 guide · Clause 6
6.1.2 — Information security risk assessment
ISO 27001:2022 sub-clause 6.1.2 requires a consistent, repeatable risk assessment process: what it expects, and the evidence auditors will ask to see.
Learn more →
ISO 27001 guide · Clause 6
6.1.3 — Information security risk treatment
ISO 27001:2022 sub-clause 6.1.3 requires a risk treatment process, a risk treatment plan and the Statement of Applicability, plus the supporting evidence.
Learn more →
ISO 27001 guide · Clause 6
6.2 — Security objectives and planning to achieve them
ISO 27001:2022 sub-clause 6.2 requires measurable information security objectives and a plan to achieve each one: what auditors expect to see as evidence.
Learn more →
ISO 27001 guide · Clause 6
6.3 — Planning of changes
ISO 27001:2022 added sub-clause 6.3: changes to the ISMS must be carried out in a planned manner. What that means in practice, and what auditors look for.
Learn more →
ISO 27001 guide · Clause 7
Clause 7 — Support
Resources, competence, awareness, communication and documented information: clause 7 provides the scaffolding that keeps the ISMS running day to day.
Learn more →
ISO 27001 guide · Clause 7
7.1 — Resources
Clause 7.1 requires you to determine what the ISMS needs to be built, run and improved—people, budget, tools, time—and then to actually provide those resources.
Learn more →
ISO 27001 guide · Clause 7
7.2 — Competence
Clause 7.2 requires you to define the skills needed for work that affects security, confirm people have them, close any gaps and keep evidence of all of it.
Learn more →
ISO 27001 guide · Clause 7
7.3 — Awareness
Clause 7.3 requires everyone working under the organization’s control to know the security policy, their contribution to the ISMS and what nonconformity means.
Learn more →
ISO 27001 guide · Clause 7
7.4 — Communication
Clause 7.4 requires you to decide in advance what to communicate about the ISMS, to whom, when, how and by whom, for internal and external audiences alike.
Learn more →
ISO 27001 guide · Clause 7
7.5 — Documented information
Clause 7.5 requires you to know what documented information the ISMS needs, to create and approve it consistently, and then to control it throughout its life.
Learn more →
ISO 27001 guide · Clause 7
7.5.1 — General
Clause 7.5.1 states that the ISMS includes the documented information the standard requires plus whatever the organization deems necessary for effectiveness.
Learn more →
ISO 27001 guide · Clause 7
7.5.2 — Creating and updating
Clause 7.5.2 requires that every time an ISMS document is created or updated it is clearly identified, appropriately formatted, then reviewed and approved.
Learn more →
ISO 27001 guide · Clause 7
7.5.3 — Control of documented information
Clause 7.5.3 requires that once a document exists it stays available, protected and managed: distribution, access, storage, versions, retention and disposal.
Learn more →
ISO 27001 guide · Clause 8
Clause 8 — Operation
Clause 8 turns the plans from clause 6 into practice: processes run under defined criteria, changes are controlled, risk assessment and treatment are repeated.
Learn more →
ISO 27001 guide · Clause 8
8.1 — Operational planning and control
Clause 8.1 requires you to run ISMS processes under defined criteria, keep evidence they ran as planned, and control changes and externally provided services.
Learn more →
ISO 27001 guide · Clause 8
8.2 — Information security risk assessment
Clause 8.2 requires you to repeat the risk assessment at planned intervals or when a significant change occurs, using the 6.1.2 criteria, and keep the results.
Learn more →
ISO 27001 guide · Clause 8
8.3 — Information security risk treatment
Clause 8.3 requires you to actually carry out the risk treatment plan produced under 6.1.3 and to retain evidence that the treatment genuinely happened.
Learn more →
ISO 27001 guide · Clause 9
Clause 9 — Performance evaluation
Clause 9 requires you to prove the ISMS works: monitor and measure your controls, audit the system independently, and have leadership formally review it.
Learn more →
ISO 27001 guide · Clause 9
9.1 — Monitoring, measurement, analysis and evaluation
Clause 9.1 requires you to decide in advance what to measure in security, how, when and by whom, then to evaluate the results, not just collect numbers.
Learn more →
ISO 27001 guide · Clause 9
9.2 — Internal audit
Clause 9.2 requires a periodic, independent internal audit checking that the ISMS conforms to your rules and to the standard, run through a defined programme.
Learn more →
ISO 27001 guide · Clause 9
9.2.1 — General
Clause 9.2.1 sets the goal of internal audits: confirm at planned intervals that the ISMS meets your requirements and the standard, and is really implemented.
Learn more →
ISO 27001 guide · Clause 9
9.2.2 — Internal audit programme
Clause 9.2.2 requires a recurring audit programme: frequency, criteria and scope, impartial auditors, reporting to management and retained evidence.
Learn more →
ISO 27001 guide · Clause 9
9.3 — Management review
Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.
Learn more →
ISO 27001 guide · Clause 9
9.3.1 — General
Clause 9.3.1 requires top management to review the ISMS at planned intervals and judge whether it remains suitable, adequate for its risks and effective.
Learn more →
ISO 27001 guide · Clause 9
9.3.2 — Management review inputs
Clause 9.3.2 spells out the list of inputs leadership must consider during the review, so the meeting is a defined check rather than a vague status update.
Learn more →
ISO 27001 guide · Clause 9
9.3.3 — Management review results
Clause 9.3.3 requires the management review to produce documented decisions about continual improvement opportunities and any changes the ISMS needs.
Learn more →
ISO 27001 guide · Clause 10
Clause 10 — Improvement
Clause 10 requires the ISMS to keep improving and to respond properly to every nonconformity: react, fix the root cause, verify the fix and adjust the system.
Learn more →
ISO 27001 guide · Clause 10
10.1 — Continual improvement
Clause 10.1 requires you to continually improve the suitability, adequacy and effectiveness of the ISMS, as an ongoing posture rather than a task ticked off.
Learn more →
ISO 27001 guide · Clause 10
10.2 — Nonconformity and corrective action
Clause 10.2 requires you to react to each nonconformity, eliminate its root cause, verify that the corrective action worked, and retain evidence of each step.
Learn more →
Frequently asked questions
- What are the mandatory clauses of ISO 27001?
- Clauses 4 through 10 contain the mandatory, auditable requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Clauses 0 to 3 (introduction, references, terms and definitions) are part of the standard but are not auditable. Certification is therefore assessed against the seven clauses 4 to 10, and against those alone.
- What is the difference between the clauses and Annex A?
- Clauses 4 to 10 describe the management system (the ISMS) and are mandatory: they say how you manage security. Annex A is a catalogue of 93 security measures from which you choose the ones that address your risks, through the Statement of Applicability. Certification covers the clauses, not Annex A.
- Can a clause be excluded?
- No. Unlike Annex A controls, which can be excluded with a risk-based justification, the requirements of clauses 4 through 10 are all mandatory and written with shall. You cannot remove a clause from your scope: every one of them is checked during the certification audit.
- What is the PDCA cycle in ISO 27001?
- PDCA (Plan, Do, Check, Act) is the continuous-improvement logic that structures the standard, shared by every ISO management-system standard: plan (clauses 4 to 6), do (clauses 7 and 8), check (clause 9) and act (clause 10). Understanding this cycle helps you see how the clauses connect, rather than memorizing them one by one.
Let's talk about your compliance program.
Last updated: 2026-09-17
