An ISO 27001 compliance checklist should follow the standard's own clauses 4 to 10, because that is how an auditor works: context and scope recorded, leadership commitment shown, risks assessed and a Statement of Applicability across all 93 Annex A controls, resources and competence in place, the system operated with dated records, an internal audit and a management review held, and nonconformities corrected. Each line below is something you must be able to show, not merely have decided.
Clause 4, context
- The internal and external issues affecting your information security management system, recorded
- Interested parties and what they require of you
- The scope, documented, with any exclusions justified
- The processes of the system and how they interact
Clause 5, leadership
- An information security policy, approved, communicated and available
- Roles, responsibilities and authorities assigned and understood
- Evidence top management is involved, not merely named
Clause 6, planning
- A risk assessment with a stated methodology and acceptance criteria
- A risk treatment plan
- The Statement of Applicability: all 93 Annex A controls, applicable or excluded, each justified
- Measurable security objectives, with plans to achieve them
- Changes to the system planned rather than improvised
Clause 7, support
- Resources determined and provided
- Competence evidenced for the people doing the work
- Awareness activities, with records of who attended
- Internal and external communication about the system
- Documented information controlled and versioned
Clause 8, operation
- The processes above actually operating, with records
- Risk assessments performed at planned intervals and after significant change
- The risk treatment plan implemented
Clause 9, performance evaluation
- What is monitored and measured, by what method, and when
- An internal audit programme, and audits performed against it
- Management review, with the inputs and outputs the clause lists
Clause 10, improvement
- Nonconformities recorded, with correction and cause
- Corrective actions, with a check that the action worked
- Evidence of continual improvement
The two that fail audits
Records covering a period. Every line above says "show". A policy dated last week does not evidence a year of operation.
Internal audit and management review. Both are mandatory before certification and both are commonly missing or too thin at Stage 2.
If you want this mapped to a specific product rather than in the abstract, our clause-by-clause coverage states which of these StandardOS holds records for and which it does not.