iso-27001-clause-by-clause

By July 25th, 2026ISO Audit And Certificate13 min read

ISO 27001:2022 Clause by Clause Explanation

ISO 27001:2022 clause by clause explanation is essential for anyone implementing or maintaining an Information Security Management System (ISMS). The standard follows the Annex SL high-level structure shared by all modern ISO management system standards, meaning clauses 4 to 10 follow the same order as ISO 9001, ISO 14001 and ISO 45001. Beyond the clause structure, ISO 27001 also includes Annex A, which lists 93 controls organised into four themes. This article explains every clause from 4 to 10, summarises the Annex A control framework, and provides implementation guidance for each requirement.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

Implementation Guidance

  • The context analysis in clause 4.1 is the foundation of your ISMS. A weak or generic context analysis leads to a weak risk assessment and inappropriate control selection. Invest time in making it specific to your organisation.
  • Interested parties in clause 4.2 should be analysed not just listed. For each party, document their specific information security requirements and how those requirements affect your ISMS. Customer contracts, regulatory requirements and insurance policies are typically the most impactful.
  • The ISMS scope (4.3) must be documented and accessible. Exclusions must be justified based on the organisation’s risk profile and operating context. An exclusion that saves a location or business unit from the scope is only acceptable if that area has no information assets that could affect the ISMS.

Implementation Guidance

  • Top management must demonstrate leadership beyond signing documents. Evidence includes attending management review meetings, allocating budget for security initiatives, approving the risk treatment plan, and communicating the importance of information security to the organisation.
  • The information security policy (5.2) should be concise and accessible. A multi-page document that no one reads is less effective than a one-page policy that employees understand and reference.
  • Define a RACI matrix for information security roles, including the Information Security Manager, IT operations, legal/compliance, HR and business process owners. Ensure each role has documented authority to make decisions within their domain.

Implementation Guidance

  • ISO 27001 does not prescribe a specific risk assessment methodology, but the chosen method must be defensible. Common approaches include asset-based (identify assets, assess threats and vulnerabilities for each), scenario-based (identify business process risks and map to assets), and control-based (evaluate existing controls and identify gaps).
  • The Statement of Applicability (6.1.3) is the most scrutinised document in the certification audit. Every control must be either implemented or excluded with justification. Exclusions must be reasonable: excluding A.8.23 (web filtering) because your organisation does not use the internet is not credible.
  • ISMS objectives (6.2) must be set at relevant functions and levels. An objective like “improve security awareness” is too vague. A measurable objective: “reduce phishing click rate from 12% to below 5% within 12 months.”

Implementation Guidance

  • Competence (7.2) extends beyond the security team. Personnel in HR, finance and operations who handle sensitive information must demonstrate competence in information security relevant to their role.
  • Awareness (7.3) must be ongoing, not a one-time event. Annual training with periodic reinforcement is more effective than annual training alone. Phishing simulations provide measurable awareness data.
  • Documented information (7.5) includes mandatory documents (scope, policy, risk assessment methodology, SoA, risk treatment plan, internal audit programme, management review results) and records generated during ISMS operation. Both must be controlled.

Implementation Guidance

  • Operational planning (8.1) must translate the ISMS policy and risk treatment plan into day-to-day operational controls. This is where documented policies become live security practices.
  • Supplier management (8.5) is increasingly important as organisations rely on cloud services and external data processors. Supplier security assessments must be proportionate to risk. A critical cloud service provider requires more rigorous assessment than a low-risk office supplies vendor.

Implementation Guidance

  • Security metrics in clause 9.1 should include both leading indicators (vulnerability age, training completion rate, patch latency) and lagging indicators (incident count, breach impact). Leading indicators predict problems; lagging indicators confirm them.
  • Internal audit (9.2) must be independent. For small organisations where complete independence is impossible, auditors should not audit their own work and findings must be reviewed by someone outside the audited area.
  • Management review (9.3) must produce actionable outputs. Minutes should document decisions and assigned actions with deadlines. Review these action items at the next management review to close the loop.

Implementation Guidance

  • Corrective action (10.1) must include root cause analysis. The 5 Whys method is effective for most information security nonconformities. Verify that corrective actions are effective and have not introduced new risks.
  • Continual improvement (10.2) does not require constant change. It requires evidence that the ISMS is reviewed and improved when opportunities arise. This could be updating policies, implementing new controls, improving training, or retiring controls that are no longer needed.

Annex A of ISO 27001:2022 lists 93 controls organised into four themes. Controls are not mandatory individually; the Statement of Applicability determines which controls are implemented based on the risk assessment. However, controls marked as implemented in the SoA must be fully operational and effective.

ThemeNumber of ControlsScopeExamples
5 – Organisational controls37Policies, roles, supplier security, incident management, business continuityA.5.1 Policies, A.5.15 Access control, A.5.24 Incident management
6 – People controls8Screening, training, awareness, disciplinary processesA.6.3 Awareness training, A.6.4 Disciplinary process
7 – Physical controls14Physical security perimeters, equipment security, media handlingA.7.1 Physical security perimeter, A.7.10 Media storage
8 – Technological controls34User access, encryption, logging, vulnerability management, network securityA.8.5 Privileged access, A.8.16 Logging, A.8.26 Application security

Compared to the 2013 version, ISO 27001:2022 reduced the number of controls from 114 to 93 by merging related controls and removing duplicates. The numbering scheme changed from 14 domains to 4 themes, which is a significant structural change. If you are transitioning from ISO 27001:2013, you must map your old SoA to the new structure, which is a key activity during the transition audit.

The following table provides a phased implementation roadmap that follows the clause structure.

PhaseClauses CoveredActivitiesTypical Duration
1 – Foundation4, 5Context analysis, interested parties, scope, policy, roles4 – 6 weeks
2 – Risk and planning6Risk assessment, risk treatment, SoA, objectives6 – 10 weeks
3 – Support and operation7, 8Resource allocation, competence, awareness, operational controls, supplier management10 – 16 weeks
4 – Evaluation and improvement9, 10Monitoring, internal audit, management review, corrective action, continual improvement4 – 8 weeks (ongoing)

No. The Statement of Applicability (SoA) determines which controls are implemented based on your risk assessment. Controls that are not applicable to your organisation can be excluded with justification. However, the auditor will scrutinise exclusions carefully, and poorly justified exclusions are a common nonconformity. You cannot exclude a control simply because it is difficult or expensive to implement.

Clause 6.1.2 requires you to define and establish the risk assessment process (the methodology). Clause 8.2 requires you to execute that process at planned intervals or when significant changes occur. In simpler terms: 6.1.2 is defining how you assess risk, 8.2 is actually doing the risk assessment. Both must be documented and the results must be linked.

Yes, but exclusions must be justified in the scope document (clause 4.3). The scope must be based on the context analysis and risk assessment. Excluded areas must genuinely have no impact on the organisation’s information security. An exclusion that simply avoids including a difficult department will be challenged by the certification auditor. The scope should reflect the organisation’s actual risk exposure, not its convenience.

ISO 27001 requires internal audits at planned intervals but does not specify frequency. Most organisations conduct a full ISMS audit annually, with partial audits (by process or area) spread throughout the year. High-risk areas or recently changed processes may require more frequent audits. The audit programme (clause 9.2) must define the frequency and scope for each audit cycle.

Clause 9.3 specifies inputs: status of previous actions, changes in external and internal issues, feedback on security performance (incidents, nonconformities, audit results), resource adequacy, effectiveness of risk treatment, and opportunities for improvement. Outputs must include decisions and actions related to improvement opportunities, changes to the ISMS, and resource needs. Minutes must document all inputs, discussions, decisions and assigned actions.

The 2022 version restructured controls from 14 domains (114 controls) to 4 themes (93 controls). Twenty-three controls were merged, eleven new controls were added (including threat intelligence, cloud services configuration, data masking and physical security monitoring), and the remaining controls were updated. Organisations transitioning from 2013 must map their existing SoA to the new structure and address any new controls relevant to their risk profile.

A clause-by-clause understanding of ISO 27001:2022 is essential for building a compliant and effective ISMS. Whether you are implementing for the first time, transitioning from the 2013 version, or strengthening an existing system, our consultants provide practical guidance tailored to your organisation’s context and risk profile.

Contact Bitrixme or send us a message on WhatsApp to discuss your ISO 27001 implementation and certification requirements.