ISO 27001
What we cover, clause by clause.
ISO/IEC 27001:2022 is 93 Annex A controls and clauses 4 to 10, the management system around them. Most tools talk about the controls. This page is the other half: which clauses StandardOS holds your records for, where each one lives, and what remains yours to do whatever tool you buy.
26
covered
1
limit no tool removes
All 26 clauses have a place in the product, and each row below says where. That is not the same as being ready: an auditor tests what you have written, not what the software can hold, and an empty register in a covered clause passes nothing. Clause 5.1 is the honest edge: we can assemble the evidence that leadership committed, and we cannot be the commitment. The same page lives inside the product, counting what you have actually written against each clause, which is the number that decides your audit.
4: Context of the organization
5: Leadership
- 5.1Covered
Leadership actually owning the system
Every demonstration the clause asks for is assembled from records held elsewhere in the management system, so the evidence is produced rather than asserted. No software can show that top management personally did any of it. Your auditor establishes that by interviewing them, and no tool in this market changes that.
- 5.2Covered
An information security policy
- 5.3Covered
Who is responsible for what, and with what authority
6: Planning
7: Support
8: Operation
9: Performance evaluation
10: Improvement
Clause numbers are exact. The descriptions are our own wording, because ISO's text is copyrighted and is not reproduced here. Buy the standard from ISO or your national body to read it in full.