EXPLAINER
ISO 27001 Requirements and How to Meet Them
READ
ISO/IEC 27001 requires an organisation to establish, operate, review and continually improve an information security management system. The standard does not prescribe one fixed set of technologies. It requires a risk-based system that can show how information security decisions are made, implemented and checked.
That distinction matters because ISO 27001 is often reduced to a list of policies or Annex A controls. Neither view is complete. The certifiable requirements sit in clauses 4 to 10 of the standard. Annex A provides a reference set of information security controls that the organisation considers during risk treatment. Certification depends on the management system working as a whole: scope, leadership, risk assessment, control selection, operation, measurement, audit and improvement.
This guide sets out the current requirements, the evidence an auditor is likely to examine and the work needed to move from an informal collection of controls to a functioning information security management system, or ISMS.
What ISO 27001 covers
The full title is ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection – Information security management systems – Requirements. It applies to organisations of any size and sector. Some organisations implement the standard without seeking certification; others use an accredited certification body to obtain independent confirmation that their ISMS conforms to it.
The ISMS is the part of the organisation’s management system used to manage information security risk. It covers people, processes, technology and information in every relevant form, rather than only the corporate network. The intended security outcomes are commonly described through confidentiality, integrity and availability: information is accessible to authorised people, remains accurate and complete, and is available when required.
The current edition is ISO/IEC 27001:2022. The transition from the 2013 edition ended on 31 October 2025, so organisations checking a supplier certificate should expect to see the 2022 edition. Amendment 1:2024 also added climate-action wording to the management-system clauses on organisational context and interested parties. An organisation must determine whether climate change is relevant to its ISMS context, and recognise that relevant interested parties may have climate-related requirements. The amendment does not create a separate set of cyber controls, but it does need to be considered and evidenced.
The requirements in clauses 4 to 10
Clauses 1 to 3 describe the scope of the standard, normative references and terms. The requirements against which an organisation is audited begin at clause 4.
Clause 4 – Context of the organisation
The organisation must understand the internal and external issues that affect its ability to achieve the intended outcomes of the ISMS. It must identify relevant interested parties and their information security requirements, determine the boundaries and applicability of the ISMS, document that scope and establish the ISMS itself.
A defensible scope names the organisational units, locations, services, technologies and interfaces that are included. It also explains dependencies and exclusions. A scope chosen solely to keep difficult systems outside the audit can produce a certificate with little value and leave important business risks unmanaged.
Clause 5 – Leadership
Top management must demonstrate leadership and commitment, set an information security policy, integrate ISMS requirements into business processes, provide resources and assign responsibilities and authorities. The standard expects senior ownership rather than a system delegated completely to an IT manager or external consultant.
Leadership evidence can include approved policy, clear accountabilities, decisions recorded in management review, resourcing choices and examples of security being considered in wider business planning. A signed policy alone says little about whether leadership is active.
Clause 6 – Planning
The organisation must address risks and opportunities that could affect the ISMS, define and operate an information security risk assessment process, determine a risk treatment process and set measurable information security objectives. Planned changes to the ISMS also need to be carried out in a controlled way.
The risk method should produce consistent and comparable results. That means defining risk criteria, including the criteria for accepting risk, and assessing the potential consequences and realistic likelihood of information security scenarios. Treatment decisions then need owners, actions and approval from the people accountable for the risks.
Clause 7 – Support
The ISMS needs adequate resources, competent people, awareness, communication and controlled documented information. Organisations must decide what needs to be communicated, to whom, when and by what means. Documents and records must be identifiable, available where needed, protected from inappropriate access or change, and retained or disposed of appropriately.
Competence is broader than attendance at an annual awareness course. Auditors may look for role requirements, qualifications, experience, training outcomes and evidence that people performing security-relevant work can do it reliably.
Clause 8 – Operation
The organisation must plan, implement and control the processes needed to meet its information security requirements. It must perform risk assessments at planned intervals and when significant changes are proposed or occur, and implement the agreed risk treatment plan.
This is where the ISMS has to leave the policy library. The organisation should be able to demonstrate that controls operate across the defined scope, outsourced processes are controlled and changes are managed. Evidence might include access reviews, vulnerability-remediation records, supplier reviews, security monitoring, incident exercises, change approvals and recovery tests.
Clause 9 – Performance evaluation
The organisation must decide what to monitor and measure, how and when to do it, who is responsible and when results will be analysed and evaluated. It must conduct internal audits at planned intervals and top management must review the ISMS to confirm that it remains suitable, adequate and effective.
Useful measures relate to intended outcomes. A raw count of training completions or blocked emails may be easy to produce, but it needs context before it can show whether risk is reducing. Internal audit also requires objectivity and an audit programme that considers the importance of the processes and previous results. Having the person who designed a control simply confirm that it works is weak assurance.
Clause 10 – Improvement
The organisation must continually improve the suitability, adequacy and effectiveness of the ISMS. When a nonconformity occurs, it must react, correct or control the issue, deal with consequences, examine the cause, consider whether similar problems exist elsewhere and review the effectiveness of corrective action.
Closing the immediate finding is only part of the requirement. If leavers retained access because one ticket was missed, the wider question is why the process allowed that to happen and whether other accounts are affected. Corrective action should deal with the system cause, not just the sampled exception.
How Annex A and the 93 controls work
Annex A contains 93 reference controls organised into four themes. There are 37 organisational controls, eight people controls, 14 physical controls and 34 technological controls. ISO/IEC 27002:2022 supplies more detailed implementation guidance for these controls.
| Theme | Controls | Coverage |
| Organisational | 37 | Policies, roles, asset and supplier management, incidents, continuity, compliance and related governance. |
| People | 8 | Screening, terms of employment, awareness, responsibilities, remote working and event reporting. |
| Physical | 14 | Physical perimeters, entry, offices, equipment, media, utilities, cabling, maintenance and disposal. |
| Technological | 34 | Identity, access, endpoints, configuration, malware, vulnerabilities, backup, logging, networks, development and data protection. |
Annex A structure in ISO/IEC 27001:2022. The controls are a reference set, not a universal implementation checklist.
An organisation is not required to implement all 93 controls simply because they appear in Annex A. It must determine the controls needed to treat its own information security risks, compare those controls with Annex A to check that no necessary control has been overlooked, and record the result in a Statement of Applicability. The organisation may also need controls from other sources.
The Statement of Applicability records the necessary controls, why they are included, whether they are implemented and why any Annex A controls are excluded. An exclusion is acceptable when it is justified by the scope, technology and risk treatment. A copied explanation such as “not applicable to the business” will struggle under audit if the underlying reasoning cannot be shown.
The evidence your ISMS needs
ISO 27001 specifies documented information at several points, but the answer is not to create a separate document for every sentence in the standard. The format should fit the organisation. A smaller business may use a controlled set of concise procedures and registers; a complex group may need several linked systems and records.
The core evidence normally includes the ISMS scope, information security policy, risk assessment and treatment methods, risk assessment results, risk treatment plan, Statement of Applicability and information security objectives. It also includes records showing competence, monitoring and measurement, internal audits, management reviews, nonconformities and corrective action.
Operational evidence proves that stated controls are being used. For access control, that may include approvals, joiner and leaver records, privileged-account reviews and samples from identity systems. For vulnerability management, it may include asset coverage, scan results, remediation decisions, exceptions and evidence that high-risk issues were addressed. The evidence must be relevant to the defined scope and the period under review.
Documents should agree with each other and with the environment. If the policy says access is reviewed quarterly, the auditor will expect complete quarterly evidence. If the Statement of Applicability says a control is implemented, the responsible team should be able to explain it and produce a representative record. Overpromising in policy creates avoidable nonconformities.
A workable route to ISO 27001 readiness
1. Define the business outcome and scope
Decide why the organisation is implementing ISO 27001 and which services, information, locations, teams and dependencies the ISMS needs to cover. Confirm whether certification is required by a customer, contract or wider business objective. Write a scope that is clear enough for a buyer to understand what the eventual certificate represents.
2. Understand context and interested parties
Identify the issues that shape information security and the parties whose requirements matter. Customers, regulators, employees, owners, suppliers and public authorities may all have relevant expectations. Contractual handling requirements, data protection duties, sector rules and internal risk appetite should be connected to the ISMS rather than held in separate conversations.
3. Set the risk method before scoring risks
Define how risk will be identified, analysed, evaluated, accepted and reviewed. Agree scales, decision thresholds and ownership. A method that produces attractive heat maps but inconsistent decisions will not support the standard or the business.
4. Assess and treat information security risk
Identify scenarios that connect threats and vulnerabilities to information, systems and business consequences. Evaluate existing controls, determine the residual risk and choose treatments. Avoid a register filled with single words such as “phishing” or “ransomware”; the description should make the cause, event and consequence clear enough for a decision.
5. Build the Statement of Applicability
Use the treatment decisions to determine necessary controls, then compare them with Annex A. Record inclusions, exclusions, implementation status and reasons. The Statement of Applicability should be a live summary of control decisions, not a document written at the end to satisfy an auditor.
6. Implement controls and assign operational ownership
Close genuine gaps and make control ownership explicit. Each control needs somebody who can operate it, retain evidence and respond when it fails. Technical tools may support the control, but processes for approval, review, exception and escalation still matter.
7. Operate the ISMS long enough to generate evidence
Run the processes, collect records, monitor objectives and deal with exceptions. Certification is more credible when the organisation can show a period of consistent operation instead of policies approved immediately before the audit.
8. Audit, review and improve
Complete the internal audit programme, take the results into management review and address nonconformities before the certification audit. The internal audit should test conformity and effectiveness across the scope. A document-only check that avoids operational samples is unlikely to reveal the weaknesses an external auditor will find.
What ISO 27001 certification involves
Certification is optional, but where it is sought the organisation appoints a certification body. In the UK, using a UKAS-accredited certification body provides independent confirmation that the body is competent to perform management-system certification. The certificate scope and accreditation status should be checked rather than relying on the presence of an ISO logo.
The initial certification audit is normally split into two stages. Stage 1 reviews the design and readiness of the ISMS, including scope, documented information and preparation for Stage 2. Stage 2 examines implementation and effectiveness across the scope through interviews, records and sampling. Nonconformities must be handled in line with the certification body’s process before a certification decision is made.
Certification then moves into a continuing cycle of surveillance and recertification activity. Exact timing, audit duration and cost depend on the certification body and factors such as headcount, scope, sites, complexity, risk and existing management systems. Any quotation that ignores the scope and maturity of the organisation should be treated cautiously.
Problems that weaken an ISO 27001 programme
A scope designed around the certificate
A narrow scope can be legitimate, but it must reflect clear organisational and technical boundaries. Excluding shared identity, infrastructure or supplier dependencies while certifying a service that relies on them creates an awkward and potentially misleading result.
Policies that describe an imagined organisation
Generic policy packs move quickly, then fail when staff cannot recognise the process they describe. The safer approach is to document controls that the organisation can operate, identify gaps honestly and plan improvements with owners and dates.
Treating Annex A as the risk assessment
Starting with all 93 controls and marking them complete or incomplete can support a gap analysis, but it does not identify the organisation’s risks or explain why a control is necessary. Risk assessment, treatment and the Statement of Applicability need to remain connected.
Weak internal assurance
An internal audit that checks only whether documents exist provides little warning before Stage 2. The audit programme should sample operation, test evidence and maintain enough objectivity to challenge the people responsible for the controls.
Stopping at certification
A certificate is a point of assurance within an ongoing system. Business change, new suppliers, cloud services, incidents, vulnerabilities and contractual requirements all alter the risk picture. If the ISMS becomes an annual audit exercise, the evidence will drift away from the environment it is supposed to manage.
Frequently asked questions
Is ISO 27001 mandatory?
ISO/IEC 27001 is not generally mandated for every organisation. A customer, procurement exercise, contract, regulator or group policy may require certification or alignment. Organisations can also implement the standard voluntarily without seeking certification.
How many ISO 27001 controls are there?
ISO/IEC 27001:2022 contains 93 Annex A controls: 37 organisational, eight people, 14 physical and 34 technological controls. The certifiable management-system requirements are in clauses 4 to 10.
Does an organisation have to implement all 93 controls?
No. The organisation determines the controls necessary to treat its risks, compares them with Annex A and justifies inclusions and exclusions in its Statement of Applicability. Every applicable requirement in clauses 4 to 10 still has to be met.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 contains requirements for an ISMS and can be used for certification. ISO/IEC 27002 provides implementation guidance for information security controls. An organisation is certified to ISO/IEC 27001, not ISO/IEC 27002.
Does ISO 27001 certification prove that an organisation is secure?
Certification provides evidence that an independently audited management system conforms to the standard within its stated scope. It does not mean incidents are impossible or that every system operated by the organisation is covered. Buyers should check the certificate scope, issuing body, accreditation and current validity.
How long does ISO 27001 certification take?
There is no fixed duration. A focused organisation with established controls and evidence may reach readiness in months; a complex or immature environment can take longer. Scope, resources, risk work, remediation and the time needed to operate the ISMS all affect the schedule.
