home / frameworks / iso-27001 / isms-requirements

// ISO 27001 hub

ISO 27001 ISMS requirements, clauses 4 to 10

What each management system clause of ISO/IEC 27001:2022 asks for, and the records auditors expect to see.

How the clauses are built

ISO/IEC 27001:2022 follows the harmonized structure that ISO uses for all management system standards. Clauses 1 to 3 are introductory. Clauses 4 to 10 hold the requirements that an organization must meet to claim conformity, and none of them can be excluded. Because ISO 9001, ISO 22301, ISO/IEC 27701, and ISO/IEC 42001 share the same structure, many organizations run a single integrated system with one audit program and one management review.

Context, leadership, and planning

Clause 4 asks the organization to understand the issues that affect its security outcomes, the interested parties that care about them, and which of their requirements the ISMS will address. Since Amendment 1:2024, it must also decide whether climate change is a relevant issue, and a note reminds it that interested parties can have climate-related requirements. The scope must be documented. It sets the boundary for everything that follows.

Clause 5 puts responsibility on top management. Leaders must approve a security policy, make sure resources exist, assign roles, and support people who contribute to the ISMS. Clause 6 is the heart of the standard, covering a defined risk assessment process, a risk treatment process, the Statement of Applicability, measurable objectives, and, new in 2022, planning for changes to the ISMS so they happen in a controlled way.

Support and operation

Clause 7 covers resources, competence, awareness, communication, and documented information. Auditors look for evidence that people in security roles have the right skills, that staff know the policy and how to report events, and that documents are controlled, current, and protected. Records count.

Clause 8 turns plans into work. The organization must control the processes that deliver security, including processes, products, and services supplied by outside parties. It must repeat risk assessments at planned intervals or when significant changes occur and carry out its risk treatment plan, keeping the results as documented information.

Performance evaluation and improvement

Clause 9 asks the organization to decide what it will monitor and measure, how, when, and who will analyze the results. It must run internal audits under a planned program, with auditors who are objective about the areas they check. Top management must review the ISMS at planned intervals using set inputs, such as audit results, changes in issues, feedback from interested parties, and the status of risk treatment. Results are recorded.

Clause 10 requires continual improvement and a defined way to handle nonconformities. When something goes wrong, the organization must react, fix the problem, find the cause, act to prevent it happening again, and check that the action worked. The 2022 edition placed continual improvement before nonconformity in this clause. That's a reordering only.

Documented information auditors usually ask for

The standard requires certain information to be documented or kept as evidence. Certification bodies expect to see at least the following, along with anything else the organization decides it needs.

  • ISMS scope
  • Information security policy and objectives
  • Risk assessment and risk treatment processes and their results
  • Statement of Applicability
  • Evidence of competence
  • Monitoring and measurement results
  • Internal audit program and audit results
  • Management review results
  • Nonconformities, corrective actions, and their outcomes

Resources

All ISO 27001 resources

References

  1. ISO/IEC 27001:2022 Information security management systems, ISO
  2. ISO/IEC 27001:2022/Amd 1:2024 Climate action changes, ISO
  3. IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum