Learn ISMS and ISO/IEC 27001 Requirements (ISO 27001 LA) with Interactive Flashcards
Master key concepts in ISMS and ISO/IEC 27001 Requirements through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.
Structure of ISO/IEC 27001:2022
ISO/IEC 27001:2022 follows the ISO Harmonized Structure (formerly Annex SL), the common framework shared by management system standards such as ISO 9001 and ISO 14001. This makes integration and combined audits easier. The standard has ten clauses plus a normative Annex A.
Clauses 0 to 3 are introductory. Clause 0 is the Introduction. Clause 1 sets out the Scope. Clause 2 lists Normative References, chiefly ISO/IEC 27000. Clause 3 covers Terms and Definitions, which refers readers to ISO/IEC 27000.
Clauses 4 to 10 contain the mandatory requirements, expressed as 'shall' statements:
Clause 4, Context of the Organization: understand internal and external issues and the needs of interested parties, define the ISMS scope, and establish the ISMS. Amendment 1:2024 added the consideration of climate change.
Clause 5, Leadership: top management commitment, the information security policy, and roles, responsibilities and authorities.
Clause 6, Planning: actions to address risks and opportunities, information security risk assessment and risk treatment, the Statement of Applicability (SoA), and security objectives. The 2022 edition also added 6.3 Planning of Changes.
Clause 7, Support: resources, competence, awareness, communication and documented information.
Clause 8, Operation: operational planning and control, plus carrying out the risk assessments and risk treatment.
Clause 9, Performance Evaluation: monitoring, measurement, analysis and evaluation, internal audit and management review.
Clause 10, Improvement: continual improvement, nonconformity and corrective action.
These clauses map to the Plan-Do-Check-Act cycle. Clauses 4 to 7 correspond to Plan, Clause 8 to Do, Clause 9 to Check, and Clause 10 to Act.
Annex A lists 93 controls grouped into four themes:
- Organizational controls (A.5, 37 controls)
- People controls (A.6, 8 controls)
- Physical controls (A.7, 14 controls)
- Technological controls (A.8, 34 controls)
The 2013 edition had 114 controls in 14 domains. The 2022 edition consolidated these and added 11 new controls, including threat intelligence, cloud services security and data leakage prevention.
For a Lead Auditor, the key point is that no requirement in Clauses 4 to 10 may be excluded. Annex A controls may be excluded only if the SoA gives a justification grounded in the risk assessment.
Management System Concepts and Principles
A management system is a set of interrelated or interacting elements of an organization that establishes policies, objectives and processes to achieve those objectives. In ISO/IEC 27001, the Information Security Management System (ISMS) preserves the confidentiality, integrity and availability of information through a risk management process, giving interested parties confidence that risks are adequately managed. Several core concepts underpin the standard. First, ISO/IEC 27001 follows the Harmonized Structure (formerly Annex SL), which uses common clauses, terms and definitions across ISO management system standards. This allows integration with ISO 9001, ISO 14001 and others. Clauses 4 to 10 cover Context of the Organization, Leadership, Planning, Support, Operation, Performance Evaluation and Improvement. Second, the Plan-Do-Check-Act (PDCA) cycle drives the system. Plan establishes scope, policy, risk assessment and objectives. Do implements risk treatment and controls. Check monitors, measures, audits and reviews performance. Act corrects nonconformities and drives continual improvement. Third, the process approach treats activities as interrelated processes with defined inputs, outputs, owners and measures, producing consistent and predictable results. Fourth, risk-based thinking is central. Organizations identify information security risks, evaluate them against defined criteria, and select controls, using Annex A as a reference to ensure nothing necessary is omitted, documented in the Statement of Applicability. Fifth, leadership and commitment require top management to set policy, assign roles, provide resources and integrate the ISMS into business processes. Sixth, understanding context and interested parties ensures the ISMS addresses internal and external issues and relevant requirements, including legal, regulatory and contractual obligations. Seventh, documented information provides evidence of conformity and effective operation. Finally, continual improvement ensures the ISMS stays suitable, adequate and effective. For a Lead Auditor, these principles form the audit criteria. The auditor gathers objective evidence to verify that the ISMS conforms to the requirements, is effectively implemented and maintained, and delivers its intended outcomes.
Integrated Management Systems
An Integrated Management System (IMS) combines two or more management system standards, such as ISO/IEC 27001 (information security), ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety) and ISO 22301 (business continuity), into a single coherent framework instead of running separate, parallel systems. Integration is made practical by the Harmonized Structure (formerly the High-Level Structure defined in Annex SL of the ISO/IEC Directives). It gives all modern ISO management system standards the same clause sequence, core text and common terms. These are Clause 4 Context of the organization, 5 Leadership, 6 Planning, 7 Support, 8 Operation, 9 Performance evaluation and 10 Improvement. Because ISO/IEC 27001:2022 follows this structure, many ISMS processes can be shared with other systems. Examples include determining interested parties and scope, setting policy and objectives, risk-based planning, competence and awareness, documented information control, internal audit, management review, and corrective action and continual improvement. Benefits include reduced duplication and documentation, consistent governance, a unified view of risk, better resource use, and combined or integrated certification audits that may reduce total audit time. For a Lead Auditor, integration requires care. Shared processes can be audited once, but evidence must still demonstrate conformity with each standard's specific requirements. For ISO/IEC 27001, the auditor must verify discipline-specific elements that generic integration may overlook. These include the information security risk assessment and treatment process (6.1.2 and 6.1.3), the Statement of Applicability, the justified inclusion and exclusion of Annex A controls, and information security objectives. The auditor should check that integration has not diluted information security, for example by merging risk registers so that confidentiality, integrity and availability are no longer clearly assessed. Guidance comes from ISO 19011 for auditing management systems, ISO/IEC 27006-1 for certification body requirements, and IAF MD 11 for integrated audits. Audit teams need combined competence across all the standards being audited. Ultimately, an effective IMS embeds information security into overall business processes and strategic direction.
Context of the Organization: Internal and External Issues
Clause 4.1 of ISO/IEC 27001 requires an organization to determine the external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcomes of its Information Security Management System (ISMS). This clause is the foundation of the whole ISMS, because these issues shape the scope (Clause 4.3), the risk assessment (Clause 6.1), the information security objectives (Clause 6.2) and leadership decisions. Following Amendment 1 (2024), the organization must also determine whether climate change is a relevant issue.
External issues come from outside the organization. Examples include legal, regulatory and contractual requirements such as GDPR or sector rules, the threat landscape and cybercrime trends, technological change like cloud adoption and AI, market competition, economic and political conditions, supply chain dependencies, natural disasters and the expectations of society. Internal issues come from within. Examples include governance structure, roles and accountabilities, organizational culture and security awareness, strategy and business objectives, resources and budget, staff competence, existing processes, information systems and infrastructure, legacy technology, and contractual relationships. The standard notes that ISO 31000 clause 5.4.1 provides further guidance on establishing this context.
The standard does not explicitly require documented information for Clause 4.1, but organizations commonly use tools such as PESTLE, SWOT or strategic planning records to demonstrate how issues were identified. Issues should be reviewed periodically, and changes in them must be considered as an input to management review under Clause 9.3.
From a Lead Auditor perspective, the goal is to obtain objective evidence that top management understands the context and that it genuinely drives the ISMS. Auditors interview leadership, review strategy documents, risk registers and management review minutes, and check traceability between identified issues, the ISMS scope, risks and controls. Typical nonconformities include generic issue lists copied from templates, issues never updated after major changes such as mergers or new regulations, or no visible link between context and risk treatment decisions.
Interested Parties and Their Requirements
In ISO/IEC 27001:2022, Clause 4.2, 'Understanding the needs and expectations of interested parties', requires an organization to determine three things. First, it must identify the interested parties that are relevant to the information security management system (ISMS). Second, it must identify the relevant requirements of those parties. Third, it must decide which of these requirements will be addressed through the ISMS. That third point was introduced in the 2022 revision. Amendment 1:2024 also added a note that relevant interested parties can have requirements related to climate change. An interested party, sometimes called a stakeholder, is any person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity. Typical examples include customers, employees, shareholders, regulators, suppliers, outsourcing partners, insurers, certification bodies and the local community. Their requirements may be legal, regulatory or contractual obligations, such as data protection laws, sector regulations, service level agreements and confidentiality clauses. Other requirements may be voluntary expectations, such as customer assurance or reputational commitments. Some of these requirements become compliance obligations, and they feed directly into the ISMS scope (Clause 4.3), risk assessment (Clause 6.1), the information security objectives and the selection of Annex A controls, such as A.5.31 on legal, statutory, regulatory and contractual requirements. Clause 4.2 does not explicitly require documented information. However, organizations usually keep a stakeholder register or requirements matrix to show that this analysis exists and is kept current. From a Lead Auditor perspective, auditors look for evidence that the analysis is systematic and reviewed periodically, especially at management review (Clause 9.3), where changes in the needs of interested parties are a required input. Auditors also check that requirements are traceable to risks, controls and objectives, and that top management understands them. During interviews, auditors may sample a contract or regulation to verify that the obligations it contains are reflected in the ISMS. Common nonconformities include generic stakeholder lists, missing regulators or key suppliers, and identified requirements that are never linked to risk treatment.
Determining the ISMS Scope
Determining the ISMS scope is a core requirement of ISO/IEC 27001, Clause 4.3. It defines the boundaries and applicability of the Information Security Management System and establishes exactly what the organization is protecting and what the certification will cover. The organization must decide which parts of the business are included, such as departments, processes, locations, assets, technologies, people and information.
When defining the scope, the standard requires the organization to consider three inputs. First, the external and internal issues identified under Clause 4.1, such as legal, regulatory, technological, cultural and competitive factors. Second, the needs and expectations of interested parties under Clause 4.2, including customers, regulators, suppliers and employees. Third, the interfaces and dependencies between activities performed by the organization and those performed by other organizations, such as outsourced IT services, cloud providers or shared facilities. The scope must be available as documented information.
A well-defined scope typically describes organizational units, physical locations, business processes and services, information assets, technology infrastructure, and any exclusions with justification. Exclusions are acceptable only if they do not affect the organization's ability or responsibility to provide information security that meets risk assessment results and applicable requirements. Any Annex A control that is excluded must be justified separately in the Statement of Applicability.
From a Lead Auditor's perspective, verifying the scope is one of the first and most critical audit activities. The auditor assesses whether the scope is clearly documented, logical and consistent with the organization's context, risks and strategic objectives. Auditors watch for artificially narrow scopes designed to avoid difficult areas, unclear boundaries, and unmanaged interfaces with third parties. The auditor also confirms that the certification scope statement accurately reflects the operational reality observed during the audit. A poorly defined scope can undermine the risk assessment, control selection and overall credibility of the ISMS, making scope determination the foundation on which the entire management system is built.
Leadership, Commitment and the Information Security Policy
In ISO/IEC 27001, Clause 5 (Leadership) makes top management directly accountable for the Information Security Management System (ISMS). Clause 5.1, Leadership and Commitment, requires top management to show active, visible involvement rather than simply delegate responsibility. Top management must: ensure the information security policy and objectives are established and compatible with the organization's strategic direction; integrate ISMS requirements into business processes; provide the necessary resources; communicate the importance of effective information security management and of conforming to ISMS requirements; ensure the ISMS achieves its intended outcomes; direct and support people who contribute to its effectiveness; promote continual improvement; and support other relevant management roles in demonstrating leadership in their areas. Clause 5.2, Information Security Policy, requires top management to establish a policy that is appropriate to the organization's purpose. The policy must include information security objectives or provide a framework for setting them. It must also include a commitment to satisfy applicable requirements related to information security and a commitment to continual improvement of the ISMS. The policy must be available as documented information, communicated within the organization, and made available to interested parties as appropriate. Clause 5.3 complements this by requiring top management to assign and communicate responsibilities and authorities, including for ensuring conformity with the standard and for reporting on ISMS performance. From a Lead Auditor's perspective, evidence of leadership is gathered by interviewing top management, reviewing management review minutes, resource allocations, approved and communicated policies, and records showing how security objectives align with business goals. Auditors also check whether staff understand the policy and their roles. Common nonconformities include policies that are generic or outdated, lack the required commitments, are not communicated, or lack genuine management involvement, such as when the ISMS is treated as an IT-only project. Strong leadership is the foundation of an effective, sustainable ISMS.
ISMS Roles, Responsibilities and Authorities
In ISO/IEC 27001:2022, clause 5.3 (Organizational roles, responsibilities and authorities) requires top management to ensure that responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. This clause sits under Leadership (clause 5), which shows that accountability for the ISMS cannot be delegated away entirely. Top management keeps ultimate accountability, even when operational tasks are assigned to others.
The standard explicitly requires top management to assign responsibility and authority for two things. First, ensuring that the ISMS conforms to the requirements of ISO/IEC 27001. Second, reporting on the performance of the ISMS to top management. These tasks are often given to an ISMS Manager or CISO, but the standard does not prescribe job titles. An organization may assign them to one person, a committee, or several functions, depending on its size and complexity.
Other clauses define further roles. Clause 6.1.2 requires the identification of risk owners, who are accountable for managing specific risks and for approving risk treatment plans and the acceptance of residual risk. Annex A control 5.2 addresses information security roles and responsibilities more broadly. Control 5.3 requires segregation of conflicting duties. Control 5.4 requires management to ensure that personnel apply security in line with policy. Clause 7.2 adds that people in these roles must be competent, and clause 7.3 requires that they are aware of their contribution to the ISMS.
From a Lead Auditor perspective, auditors seek objective evidence that roles are clearly defined, documented where necessary, communicated, and understood. Typical evidence includes:
- organization charts
- job descriptions
- appointment letters
- RACI matrices
- ISMS committee terms of reference
- interview results
Auditors check that the assigned people actually hold the necessary authority and resources. They also check that reporting to top management really happens, for example through management review records under clause 9.3. Common nonconformities include:
- undefined risk ownership
- responsibilities that exist only on paper
- conflicting duties without compensating controls
- staff who are unaware of their security responsibilities
Information Security Risk Assessment Process
In ISO/IEC 27001, the information security risk assessment process is defined mainly in Clause 6.1.2 (Planning) and carried out under Clause 8.2 (Operation). It is the foundation of the ISMS because it determines which controls are needed and why. The organization must define and apply a process that does the following. First, it must establish and maintain information security risk criteria, including risk acceptance criteria and criteria for performing assessments. Second, the process must produce consistent, valid and comparable results when repeated, so a documented, repeatable methodology is essential. Third, risks must be identified, meaning risks associated with the loss of confidentiality, integrity and availability of information within the ISMS scope, and a risk owner must be assigned to each risk. Fourth, risks must be analysed by assessing the realistic likelihood and potential consequences if they materialize, and then determining risk levels. Fifth, risks must be evaluated by comparing the results against the established criteria and prioritizing them for treatment. The standard does not prescribe a specific method. Organizations may use asset-based, scenario-based or event-based approaches, often guided by ISO/IEC 27005. Under Clause 8.2, assessments must be performed at planned intervals and whenever significant changes are proposed or occur. Documented information on the process (6.1.2) and on its results (8.2) must be retained. The outputs feed directly into risk treatment (6.1.3), the Statement of Applicability, and the risk treatment plan, which risk owners must approve, including acceptance of residual risks. From a Lead Auditor perspective, auditors verify several things. They check that the methodology is documented and that the criteria are clearly defined. They check that results are reproducible and that risk owners are identified with appropriate authority. They confirm that reassessment is triggered by change, and that there is clear traceability from identified risks to selected controls and SoA justifications. Common nonconformities include outdated assessments, inconsistent scoring, missing risk owners, and controls in the SoA that are not linked to assessed risks.
Information Security Risk Treatment and Risk Owners
Information security risk treatment is defined in ISO/IEC 27001 clause 6.1.3 and implemented under clause 8.3. After risks are identified, analysed and evaluated in the risk assessment (clause 6.1.2), the organization must define and apply a risk treatment process. This involves selecting appropriate treatment options: modifying the risk by applying controls, avoiding the risk by stopping the activity, sharing or transferring it (for example through insurance or outsourcing), or retaining it through informed acceptance. The organization then determines all controls needed to implement the chosen options. It may design its own controls or take them from any source, but it must compare them with Annex A to verify that no necessary controls have been omitted. The result is the Statement of Applicability (SoA), which lists the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A controls. The organization must also formulate a risk treatment plan stating what will be done, by whom, with what resources, by when, and how results will be evaluated. Documented information about the treatment process and its results must be retained. Risk owners are the persons or entities with the accountability and authority to manage a risk. Clause 6.1.2 requires the risk assessment to identify risk owners, linking each risk to someone who has decision-making power rather than to an asset custodian alone. Under clause 6.1.3 f), risk owners must approve the risk treatment plan and formally accept the residual information security risks. This ensures that treatment decisions reflect business priorities and the organization's risk acceptance criteria. For a Lead Auditor, key audit evidence includes a documented treatment methodology, an SoA consistent with the risk assessment, traceability from each risk to its selected controls, clearly named risk owners with appropriate authority, recorded approval of the treatment plan, documented acceptance of residual risk, and proof that planned treatments have been implemented and monitored. Missing owner approval or an SoA inconsistent with the risk assessment are common nonconformities.
Statement of Applicability
The Statement of Applicability (SoA) is a mandatory documented information requirement of ISO/IEC 27001, specified in Clause 6.1.3(d) as part of the information security risk treatment process. It links the organization's risk assessment and treatment decisions to the reference controls in Annex A, which in the 2022 edition contains 93 controls grouped into four themes: organizational, people, physical and technological. After identifying risks and selecting treatment options, the organization determines all controls needed to implement those options. It then compares them with Annex A to make sure no necessary control has been overlooked. The SoA must contain four elements: the necessary controls (whether from Annex A or other sources), the justification for including them, whether each control is implemented or not, and the justification for excluding any Annex A control. Justifications usually come from risk assessment results, legal, regulatory or contractual requirements, business needs, or best practice. Exclusions are acceptable only when properly justified, for example where no relevant risk exists or an activity is outside the ISMS scope. The SoA is a living document that must be controlled, approved by management, kept current and updated when risks, scope or controls change. Many organizations also record the version, owner, implementation status and references to policies or procedures for each control. From a Lead Auditor's perspective, the SoA is a key audit document and a roadmap for the audit. During Stage 1, the auditor checks that it exists, is complete and is consistent with the scope and risk treatment plan. During Stage 2, the auditor samples controls declared as implemented and seeks objective evidence of their effectiveness, while challenging weak exclusion justifications. Inconsistencies between the SoA, risk assessment and actual practice are common sources of nonconformities. The certificate issued typically references the SoA version, which demonstrates its central role in certification and in providing assurance to interested parties.
Annex A Controls and Their Themes
Annex A of ISO/IEC 27001:2022 is a normative reference list of information security controls. Organizations use it during risk treatment under Clause 6.1.3. Annex A is not a mandatory checklist. Organizations first determine the controls they need to treat identified risks, then compare those controls against Annex A to ensure no necessary control has been overlooked. The result is documented in the Statement of Applicability (SoA). The SoA lists each necessary control, states whether it is implemented, and justifies its inclusion or exclusion. The 2022 revision reduced the controls from 114 (in 14 domains) to 93, grouped into four themes. 1) Organizational controls (A.5, 37 controls) cover governance and management topics. Examples include information security policies, roles and responsibilities, asset inventory, access control, supplier relationships, incident management, business continuity, legal compliance and threat intelligence. 2) People controls (A.6, 8 controls) address the human factor. They cover screening, terms of employment, awareness and training, the disciplinary process, responsibilities after termination, confidentiality agreements, remote working and event reporting. 3) Physical controls (A.7, 14 controls) protect premises and equipment. They include security perimeters, entry controls, physical security monitoring, clear desk and clear screen, equipment siting, storage media handling and secure disposal. 4) Technological controls (A.8, 34 controls) cover technical safeguards. Examples include endpoint devices, privileged access, malware protection, vulnerability management, configuration management, backup, logging, monitoring, network security, cryptography, secure development and data leakage prevention. The revision introduced 11 new controls, including cloud services security, data masking, information deletion, web filtering and secure coding. ISO/IEC 27002 supports these controls with implementation guidance and optional attributes, such as control type (preventive, detective, corrective) and the confidentiality, integrity and availability properties each control supports. For a Lead Auditor, the focus is on the following points. Verify that control selection is traceable to the risk assessment. Confirm that exclusions in the SoA are justified. Gather objective evidence that the selected controls are implemented and operating effectively, through interviews, observation and records review. Always keep in mind that the controls serve the overall ISMS requirements in Clauses 4 to 10.
Information Security Objectives and Planning of Changes
In ISO/IEC 27001:2022, Information Security Objectives (Clause 6.2) and Planning of Changes (Clause 6.3) are part of Clause 6, Planning. They turn the information security policy and the risk assessment into measurable action, and they keep the ISMS stable as it evolves.
Clause 6.2 requires the organization to set information security objectives at relevant functions and levels. Objectives must be consistent with the information security policy, measurable where practicable, and based on applicable security requirements and the results of risk assessment and risk treatment. They must also be monitored, communicated, updated as appropriate, and kept as documented information. The 2022 revision added the explicit requirement for monitoring. To plan how objectives will be achieved, the organization must determine what will be done, what resources are needed, who is responsible, when it will be completed, and how results will be evaluated. Examples include reducing critical vulnerabilities older than 30 days to zero, or reaching 95 percent completion of security awareness training.
A Lead Auditor checks that objectives exist and are SMART. The auditor confirms they trace back to the policy and the risk treatment plan, and that owners and deadlines are assigned. The auditor also looks for evidence of progress tracking feeding into performance evaluation (Clause 9.1) and management review (Clause 9.3). Vague aspirations, or objectives without measurement, are common nonconformities.
Clause 6.3, new in the 2022 edition, states that when the organization determines a need for changes to the ISMS, those changes shall be carried out in a planned manner. Such changes may involve scope, processes, controls, technology, or organizational structure. Planned change avoids unintended weakening of security. Good practice is to consider the purpose and potential consequences of the change, the continued integrity of the ISMS, resource availability, and the allocation of responsibilities. Auditors seek evidence such as change records, impact assessments, and approvals. They also check links to operational control of planned changes (Clause 8.1) and Annex A control 8.32, Change Management.
Competence, Awareness and Communication
In ISO/IEC 27001, Competence, Awareness and Communication are support requirements in Clause 7 (Support). They make sure the people running the ISMS can operate it effectively. A Lead Auditor checks that each is planned, carried out and backed by evidence. Clause 7.2 Competence requires the organization to determine the competence needed by people whose work affects information security performance. It must ensure they are competent through appropriate education, training or experience. Where gaps exist, it must take action to close them, such as training, mentoring, reassignment or hiring, and then evaluate whether that action worked. Documented information must be retained as evidence of competence. Auditors typically sample job descriptions, competence matrices, training records, certificates and effectiveness evaluations. Clause 7.3 Awareness requires that people working under the organization's control know three things. They must know the information security policy. They must understand how they contribute to the effectiveness of the ISMS, including the benefits of improved security performance. They must also understand the implications of not conforming to ISMS requirements. Annex A control 6.3 (Information security awareness, education and training) supports this clause. Auditors interview staff at different levels to confirm real understanding rather than mere attendance at sessions. Clause 7.4 Communication requires the organization to determine its internal and external communications relevant to the ISMS. This covers what to communicate, when, with whom and how. Common examples include communications with employees, top management, customers, suppliers, regulators and incident response contacts. Auditors look for a communication plan or matrix and evidence that it is followed, such as meeting minutes, notices and incident notifications. Together, these clauses link people to the ISMS. Competence means people can perform their roles. Awareness means they understand why security matters. Communication means the right information reaches the right parties at the right time. Weaknesses here often lead to nonconformities elsewhere, such as poor incident handling or ineffective controls.
Documented Information Requirements
In ISO/IEC 27001, documented information means information that an organization must control and maintain, along with the medium that holds it. Clause 7.5 sets the core requirements, and a Lead Auditor must assess whether the ISMS documentation is adequate, controlled and used in practice. Clause 7.5.1 requires two types of documented information: what the standard explicitly requires, and what the organization itself decides is necessary for an effective ISMS. The extent varies with organizational size, the complexity of processes and interactions, and the competence of personnel. The standard uses two verbs. 'Maintain' refers to documents such as policies and procedures. 'Retain' refers to records that serve as evidence. Mandatory documented information includes the ISMS scope (4.3), the information security policy (5.2), the risk assessment and risk treatment processes (6.1.2, 6.1.3), the Statement of Applicability (6.1.3 d), the risk treatment plan, and information security objectives (6.2). Mandatory records include evidence of competence (7.2), operational planning and control information (8.1), risk assessment results (8.2), risk treatment results (8.3), monitoring and measurement results (9.1), the internal audit programme and its results (9.2), management review results (9.3), and nonconformities with their corrective actions (10.2). Clause 7.5.2 requires appropriate identification, such as titles, dates, authors or reference numbers. It also requires a suitable format and medium, and review and approval for suitability and adequacy. Clause 7.5.3 requires control so that documented information is available, suitable for use, and adequately protected against loss of confidentiality, improper use or loss of integrity. Controls address distribution, access, retrieval, storage, preservation of legibility, version control, retention and disposition. Documented information of external origin, such as legal requirements or supplier contracts, must also be identified and controlled. During audits, a Lead Auditor checks that documents are current, approved and accessible. The auditor also confirms that records provide objective evidence that the ISMS conforms to requirements and operates effectively.
Operational Planning and Control
Operational Planning and Control is Clause 8.1 of ISO/IEC 27001:2022. It is where the ISMS moves from planning to execution. Clause 6 identifies information security risks, opportunities and objectives. Clause 8.1 requires the organization to plan, implement and control the processes needed to meet those requirements and to carry out the actions decided in Clause 6. The 2022 edition adds that organizations must set criteria for these processes and control them against those criteria, so that operations are measurable and consistent rather than informal.
Key requirements include:
1) Process criteria and control: define how security processes should work, such as access provisioning, backup or incident handling, and make sure they run as defined.
2) Documented information: keep records to the extent needed to show that processes were carried out as planned.
3) Change control: control planned changes, review the consequences of unintended changes and act to reduce any adverse effects.
4) Externally provided processes, products or services: make sure outsourced or cloud-based activities relevant to the ISMS are controlled. This links to Annex A supplier controls 5.19 to 5.23.
Clause 8.1 works together with Clause 8.2, which requires information security risk assessments at planned intervals or when significant changes occur. It also works with Clause 8.3, which requires implementing the risk treatment plan and retaining the results.
From a Lead Auditor perspective, the auditor checks that planning has actually been put into practice. Typical evidence includes:
- operating procedures and work instructions;
- change management records and approvals;
- supplier contracts, service level agreements and supplier performance reviews;
- implemented Annex A controls that match the Statement of Applicability;
- records proving that controls operate effectively.
Auditors sample real transactions, interview process owners and trace each risk to its treatment and then to its operational evidence. Common nonconformities include uncontrolled changes, unmanaged outsourced services, controls described in the Statement of Applicability but not implemented, and missing evidence that processes ran as intended. Effective operational control shows that the ISMS is a living management system rather than just paperwork.
Monitoring, Measurement, Internal Audit and Management Review
Clause 9 (Performance Evaluation) of ISO/IEC 27001:2022 requires the organization to verify that its Information Security Management System (ISMS) works as intended and achieves its intended outcomes. It contains three linked requirements. Monitoring, measurement, analysis and evaluation (9.1): The organization must determine what needs to be monitored and measured, including information security processes and controls. It must also define the methods used, which should produce comparable and reproducible results, when monitoring and measuring occur and who performs them, and when and by whom results are analysed and evaluated. Documented information must be available as evidence of the results. Auditors look for meaningful metrics tied to information security objectives, such as incident trends, patch compliance or awareness training completion, rather than data collected for its own sake. Internal audit (9.2): Audits must be conducted at planned intervals to determine whether the ISMS conforms to the organization's own requirements and to ISO/IEC 27001, and whether it is effectively implemented and maintained. The organization must plan, establish, implement and maintain an audit programme that considers the importance of the processes concerned and the results of previous audits. For each audit, criteria and scope must be defined and auditors selected to ensure objectivity and impartiality. Results must be reported to relevant management, and documented information must be retained as evidence of the programme and its results. ISO 19011 provides guidance on auditing. Management review (9.3): Top management must review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Inputs include the status of previous actions, changes in internal and external issues, and changes in interested parties' needs and expectations. They also include feedback on security performance, covering nonconformities, corrective actions, measurement results, audit findings and achievement of objectives. Further inputs are risk assessment results, the status of risk treatment, and opportunities for improvement. Outputs include decisions on improvements and any needed changes to the ISMS, retained as documented information. Together, these activities feed Clause 10 (Improvement) and complete the Plan-Do-Check-Act cycle.
Nonconformity, Corrective Action and Continual Improvement
In ISO/IEC 27001:2022, Clause 10 (Improvement) contains two requirements: 10.1 Continual Improvement and 10.2 Nonconformity and Corrective Action. A nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard itself, the organization's own ISMS policies and procedures, legal or contractual obligations, or interested party expectations. Nonconformities can be identified through internal audits, management reviews, security incidents, monitoring and measurement, or external certification audits. Lead auditors typically grade them as major or minor. A major nonconformity is the absence or total breakdown of a required process, or raises significant doubt about the ISMS achieving its intended outcomes. A minor nonconformity is an isolated lapse that does not compromise the system. When a nonconformity occurs, the organization must first react by controlling and correcting it and dealing with its consequences. This is called correction. It must then evaluate the need to eliminate the cause so the problem does not recur or occur elsewhere. This involves reviewing the nonconformity, determining root causes using tools such as 5 Whys or fishbone analysis, and checking whether similar nonconformities exist or could occur. Corrective actions must be appropriate to the effects of the nonconformity. The organization must implement them, review their effectiveness, and change the ISMS where necessary. It must retain documented information on the nature of nonconformities, actions taken, and results. Auditors distinguish correction (the immediate fix) from corrective action (eliminating the root cause). They verify effectiveness, not merely closure. Continual improvement requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. Inputs include audit results, risk assessment outcomes, performance metrics, incident trends and management review decisions (Clause 9.3). Clause 10 corresponds to the Act phase of Plan-Do-Check-Act thinking. During audits, the lead auditor looks for evidence that improvement is systematic, measured and driven by top management rather than purely reactive. Such evidence shows a mature, learning ISMS that adapts to changing threats, risks and business context.