[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:iso-27001-compliance-checklist":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","iso-27001-compliance-checklist","ISO 27001 compliance checklist, by clause","A checklist that follows the standard's own structure: clauses 4 to 10 and what each one asks you to be able to show, plus what Annex A adds.","2026-08-20","\nAn ISO 27001 compliance checklist should follow the standard's own clauses 4 to 10, because that is how an auditor works: context and scope recorded, leadership commitment shown, risks assessed and a Statement of Applicability across all 93 Annex A controls, resources and competence in place, the system operated with dated records, an internal audit and a management review held, and nonconformities corrected. Each line below is something you must be able to show, not merely have decided.\n\n## Clause 4, context\n\n- The internal and external issues affecting your information security management system, recorded\n- Interested parties and what they require of you\n- The scope, documented, with any exclusions justified\n- The processes of the system and how they interact\n\n## Clause 5, leadership\n\n- An information security policy, approved, communicated and available\n- Roles, responsibilities and authorities assigned and understood\n- Evidence top management is involved, not merely named\n\n## Clause 6, planning\n\n- A risk assessment with a stated methodology and acceptance criteria\n- A risk treatment plan\n- The Statement of Applicability: all 93 Annex A controls, applicable or excluded, each justified\n- Measurable security objectives, with plans to achieve them\n- Changes to the system planned rather than improvised\n\n## Clause 7, support\n\n- Resources determined and provided\n- Competence evidenced for the people doing the work\n- Awareness activities, with records of who attended\n- Internal and external communication about the system\n- Documented information controlled and versioned\n\n## Clause 8, operation\n\n- The processes above actually operating, with records\n- Risk assessments performed at planned intervals and after significant change\n- The risk treatment plan implemented\n\n## Clause 9, performance evaluation\n\n- What is monitored and measured, by what method, and when\n- An internal audit programme, and audits performed against it\n- Management review, with the inputs and outputs the clause lists\n\n## Clause 10, improvement\n\n- Nonconformities recorded, with correction and cause\n- Corrective actions, with a check that the action worked\n- Evidence of continual improvement\n\n## The two that fail audits\n\n**Records covering a period.** Every line above says \"show\". A policy dated last week does not evidence a year of operation.\n\n**Internal audit and management review.** Both are mandatory before certification and both are commonly missing or too thin at Stage 2.\n\nIf you want this mapped to a specific product rather than in the abstract, [our clause-by-clause coverage](\u002Fiso-27001\u002Fcoverage) states which of these StandardOS holds records for and which it does not.\n",1789383986409]