Structure of ISO/IEC 27001:2022
ISO/IEC 27001:2022 follows the ISO Harmonized Structure (formerly Annex SL), the common framework shared by management system standards such as ISO 9001 and ISO 14001. This makes integration and combined audits easier. The standard has ten clauses plus a normative Annex A. Clauses 0 to 3 are intro… ISO/IEC 27001:2022 follows the ISO Harmonized Structure (formerly Annex SL), the common framework shared by management system standards such as ISO 9001 and ISO 14001. This makes integration and combined audits easier. The standard has ten clauses plus a normative Annex A. Clauses 0 to 3 are introductory. Clause 0 is the Introduction. Clause 1 sets out the Scope. Clause 2 lists Normative References, chiefly ISO/IEC 27000. Clause 3 covers Terms and Definitions, which refers readers to ISO/IEC 27000. Clauses 4 to 10 contain the mandatory requirements, expressed as 'shall' statements: Clause 4, Context of the Organization: understand internal and external issues and the needs of interested parties, define the ISMS scope, and establish the ISMS. Amendment 1:2024 added the consideration of climate change. Clause 5, Leadership: top management commitment, the information security policy, and roles, responsibilities and authorities. Clause 6, Planning: actions to address risks and opportunities, information security risk assessment and risk treatment, the Statement of Applicability (SoA), and security objectives. The 2022 edition also added 6.3 Planning of Changes. Clause 7, Support: resources, competence, awareness, communication and documented information. Clause 8, Operation: operational planning and control, plus carrying out the risk assessments and risk treatment. Clause 9, Performance Evaluation: monitoring, measurement, analysis and evaluation, internal audit and management review. Clause 10, Improvement: continual improvement, nonconformity and corrective action. These clauses map to the Plan-Do-Check-Act cycle. Clauses 4 to 7 correspond to Plan, Clause 8 to Do, Clause 9 to Check, and Clause 10 to Act. Annex A lists 93 controls grouped into four themes: - Organizational controls (A.5, 37 controls) - People controls (A.6, 8 controls) - Physical controls (A.7, 14 controls) - Technological controls (A.8, 34 controls) The 2013 edition had 114 controls in 14 domains. The 2022 edition consolidated these and added 11 new controls, including threat intelligence, cloud services security and data leakage prevention. For a Lead Auditor, the key point is that no requirement in Clauses 4 to 10 may be excluded. Annex A controls may be excluded only if the SoA gives a justification grounded in the risk assessment.
Structure of ISO/IEC 27001:2022: A Complete Guide for ISO 27001 Lead Auditors
Introduction
Every audit an ISO/IEC 27001 Lead Auditor performs is built on the structure of the standard. Audit plans, checklists, findings and nonconformity reports all refer to specific clauses and Annex A controls. Knowing exactly how ISO/IEC 27001:2022 is organized lets you cite requirements correctly, write defensible nonconformities and answer a large share of exam questions quickly and accurately.
Why the Structure Is Important
1. It is the basis of audit evidence and findings. A nonconformity must be traced to a specific requirement, for example clause 9.2.2 (internal audit programme) or clause 6.1.3 d) (Statement of Applicability). If you misquote the clause, the finding is weak and can be challenged.
2. It separates mandatory from selectable requirements. Clauses 4 to 10 are mandatory. Annex A controls are selected through risk treatment and can be excluded with justification. This distinction appears in exams again and again.
3. It enables integration with other management systems. The standard follows the ISO Harmonized Structure, so it shares a common skeleton with ISO 9001, ISO 14001, ISO 22301 and ISO 45001. This makes integrated audits and integrated management systems possible.
4. It supports transition audits. Auditors must know what changed from the 2013 to the 2022 edition. The transition deadline was 31 October 2025.
5. It reflects the PDCA logic. Even though PDCA is no longer named explicitly, the clause sequence follows a Plan-Do-Check-Act flow. This helps auditors follow the management system end to end.
What It Is: The Overall Layout
ISO/IEC 27001:2022 (Information security, cybersecurity and privacy protection: Information security management systems: Requirements) was published in October 2022. Amendment 1 was issued in 2024 to add climate change considerations. The document is organized as follows:
Clause 0: Introduction (informative). Covers the general purpose of the standard and its compatibility with other management system standards. The order of requirements does not imply importance or order of implementation.
Clause 1: Scope. The standard specifies requirements for establishing, implementing, maintaining and continually improving an ISMS. It also states that excluding any of the requirements in Clauses 4 to 10 is not acceptable when claiming conformity.
Clause 2: Normative references. ISO/IEC 27000 is indispensable.
Clause 3: Terms and definitions. Points to ISO/IEC 27000. No definitions are listed in 27001 itself.
Clauses 4 to 10: Requirements (mandatory, 'shall' statements).
Annex A (normative): Information security controls reference, with 93 controls.
Bibliography.
The Harmonized Structure (formerly Annex SL / High Level Structure)
Clauses 4 to 10 follow the Harmonized Structure (HS) defined in Annex SL of the ISO/IEC Directives, Part 1. The HS provides identical clause titles, core text and common terms. Discipline-specific requirements are added on top, such as the information security risk assessment and risk treatment in clauses 6.1.2, 6.1.3, 8.2 and 8.3.
Clause-by-Clause Breakdown
Clause 4: Context of the organization
4.1 Understanding the organization and its context (internal and external issues; Amd 1:2024 adds that the organization shall determine whether climate change is a relevant issue)
4.2 Understanding the needs and expectations of interested parties (2022 adds 4.2 c): which of these requirements will be addressed through the ISMS; Amd 1 adds a note on climate-related requirements)
4.3 Determining the scope of the ISMS (must be available as documented information)
4.4 Information security management system (2022 adds the processes needed and their interactions)
Clause 5: Leadership
5.1 Leadership and commitment
5.2 Policy (information security policy, documented)
5.3 Organizational roles, responsibilities and authorities (2022 clarifies communication within the organization)
Clause 6: Planning
6.1 Actions to address risks and opportunities
6.1.1 General
6.1.2 Information security risk assessment (criteria, identification, analysis, evaluation, risk owners)
6.1.3 Information security risk treatment (select options, determine controls, compare with Annex A, produce the Statement of Applicability, prepare the risk treatment plan, obtain risk owner approval)
6.2 Information security objectives and planning to achieve them (2022 adds that objectives shall be monitored and available as documented information)
6.3 Planning of changes (new in 2022)
Clause 7: Support
7.1 Resources
7.2 Competence
7.3 Awareness
7.4 Communication
7.5 Documented information (7.5.1 General, 7.5.2 Creating and updating, 7.5.3 Control of documented information)
Clause 8: Operation
8.1 Operational planning and control (2022 adds establishing criteria for processes and controlling externally provided processes, products or services)
8.2 Information security risk assessment (performed at planned intervals or when significant changes occur)
8.3 Information security risk treatment (implement the risk treatment plan)
Clause 9: Performance evaluation
9.1 Monitoring, measurement, analysis and evaluation
9.2 Internal audit (9.2.1 General, 9.2.2 Internal audit programme)
9.3 Management review (9.3.1 General, 9.3.2 Management review inputs, 9.3.3 Management review results; 2022 adds changes in the needs and expectations of interested parties as an input)
Clause 10: Improvement
10.1 Continual improvement
10.2 Nonconformity and corrective action
Note: in 2022 the order is swapped compared with 2013 (Clauses 10.1 and 10.2 were reversed).
Annex A: Structure of Controls
Annex A contains 93 controls in 4 themes:
Clause 5 Organizational controls: 37 (5.1 to 5.37)
Clause 6 People controls: 8 (6.1 to 6.8)
Clause 7 Physical controls: 14 (7.1 to 7.14)
Clause 8 Technological controls: 34 (8.1 to 8.34)
By comparison, the 2013 edition had 114 controls in 14 domains (A.5 to A.18) with 35 control objectives. In 2022, controls were merged and updated, and 11 new controls were added:
5.7 Threat intelligence
5.23 Information security for use of cloud services
5.30 ICT readiness for business continuity
7.4 Physical security monitoring
8.9 Configuration management
8.10 Information deletion
8.11 Data masking
8.12 Data leakage prevention
8.16 Monitoring activities
8.23 Web filtering
8.28 Secure coding
Control objectives no longer appear in Annex A. Control attributes (control type, information security properties, cybersecurity concepts, operational capabilities, security domains) and implementation guidance are found in ISO/IEC 27002:2022, not in ISO/IEC 27001.
How It Works: The Logic Linking the Parts
Plan (Clauses 4 to 7). Understand the context and interested parties, define the scope, secure leadership commitment and policy, assess risks, select controls, set objectives and provide resources.
Do (Clause 8). Operate the processes, perform risk assessments and implement the risk treatment plan.
Check (Clause 9). Monitor and measure, conduct internal audits and hold management reviews.
Act (Clause 10). Correct nonconformities and continually improve.
Annex A is linked to the clauses through clause 6.1.3. The organization determines the controls needed to treat its risks, from any source. It then compares them with Annex A to verify that no necessary controls have been omitted. The Annex A controls are not exhaustive, and additional controls may be added. The Statement of Applicability must contain:
the necessary controls
the justification for their inclusion
whether they are implemented
the justification for excluding any Annex A controls
Key Documented Information Mandated by the Clauses
4.3 Scope
5.2 Information security policy
6.1.2 Risk assessment process
6.1.3 Risk treatment process, Statement of Applicability and risk treatment plan
6.2 Information security objectives
7.2 Evidence of competence
7.5.1 b) Documentation the organization determines is necessary
8.1 Evidence that processes are carried out as planned
8.2 Results of risk assessments
8.3 Results of risk treatment
9.1 Evidence of monitoring and measurement results
9.2.2 Evidence of the audit programme and audit results
9.3.3 Evidence of management review results
10.2 Evidence of nonconformities, actions taken and the results of corrective action
Exam Tips: Answering Questions on Structure of ISO/IEC 27001:2022
1. Memorize the 7 HS clause titles in order: Context, Leadership, Planning, Support, Operation, Performance evaluation, Improvement. A useful mnemonic is 'Can Leaders Plan Sensible Operations, Evaluate and Improve'.
2. Know the numbers cold. There are 93 controls and 4 themes, split 37/8/14/34, with 11 new controls. The 2013 edition had 114 controls, 14 domains and 35 objectives. Distractor answers often use 114 or 14.
3. Mandatory vs optional. If a question asks whether an organization can exclude clause 9.2 or 7.5, the answer is no: clauses 4 to 10 cannot be excluded. Annex A controls can be excluded only with justification in the SoA.
4. Locate requirements precisely.
Risk assessment is planned in 6.1.2 and performed in 8.2.
Risk treatment is planned in 6.1.3 and implemented in 8.3.
The SoA is in 6.1.3 d).
Planning of changes is in 6.3.
Exam scenarios often test this plan-versus-operate distinction.
5. Recognize what is new in 2022:
clause 6.3
4.2 c)
4.4 processes and their interactions
monitoring of objectives in 6.2
8.1 criteria and externally provided processes
new input in 9.3.2 c)
swapped order of 10.1 and 10.2
restructured Annex A
Amd 1:2024 climate change additions to 4.1 and 4.2
6. Do not confuse 27001 with 27002. Attributes, guidance and purpose statements belong to ISO/IEC 27002. ISO/IEC 27001 is the certifiable requirements standard. Annex A is normative.
7. Clause 3 trap. Definitions are in ISO/IEC 27000, which is the only normative reference listed in clause 2.
8. Use PDCA mapping for process-flow questions. Plan is 4 to 7, Do is 8, Check is 9 and Act is 10. Note that PDCA is no longer explicitly referenced in the 2022 text.
9. In scenario questions, always cite the clause. When writing a nonconformity, quote the requirement (for example, 'contrary to clause 9.2.2, no audit programme was established'). Do the same for an Annex A control (for example, 'control 5.23 is marked as applicable in the SoA but not implemented').
10. Harmonized Structure questions. Expect to explain that a common structure enables integrated management systems. Expect also that clause titles 4 to 10 are identical across ISO management system standards.
11. Read the wording carefully. 'Shall' is a requirement, 'should' is a recommendation, 'may' is a permission and 'can' is a possibility. ISO/IEC 27001 clauses use 'shall'.
12. Eliminate distractors systematically. Wrong options often include:
outdated A.x numbering such as A.12.4
a claim that control objectives are still listed in Annex A
a claim that Annex A is informative
Summary
ISO/IEC 27001:2022 comprises introductory clauses 0 to 3, mandatory Harmonized Structure clauses 4 to 10, and a normative Annex A with 93 controls in 4 themes. Clauses 6.1.3 and the Statement of Applicability tie these elements together. Mastering this structure lets a Lead Auditor plan audits, trace evidence to requirements and answer structure-related exam questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!