ISO 27001
What we cover, clause by clause.
ISO/IEC 27001:2022 is 93 Annex A controls and clauses 4 to 10 — the management system around them. Most tools talk about the controls. This page is the other half: which clauses StandardOS holds your records for, where each one lives, and what remains yours to do whatever tool you buy.
26
covered
1
limit no tool removes
All 26 clauses have a place in the product, and each row below says where. That is not the same as being ready: an auditor tests what you have written, not what the software can hold, and an empty register in a covered clause passes nothing. Clause 5.1 is the honest edge — we can assemble the evidence that leadership committed, and we cannot be the commitment. The same page lives inside the product, counting what you have actually written against each clause, which is the number that decides your audit.
4 — Context of the organization
- 4.1Covered
Understanding the organization and what surrounds it
- 4.2Covered
Who has an interest, and what they require
- 4.3Covered
Deciding what the ISMS covers
- 4.4Covered
The ISMS and the processes that make it up
5 — Leadership
- 5.1Covered
Leadership actually owning the system
Every demonstration the clause asks for is assembled from records held elsewhere in the management system, so the evidence is produced rather than asserted. No software can show that top management personally did any of it — your auditor establishes that by interviewing them, and no tool in this market changes that.
- 5.2Covered
An information security policy
- 5.3Covered
Who is responsible for what, and with what authority
6 — Planning
- 6.1.1Covered
Acting on risks and on opportunities
- 6.1.2Covered
How risk is assessed, on your own scale
- 6.1.3Covered
Choosing controls and stating which apply
- 6.2Covered
Security objectives and how they will be met
- 6.3Covered
Planning changes to the ISMS
7 — Support
- 7.1Covered
The resources the ISMS needs
- 7.2Covered
Competence, and evidence of it
- 7.3Covered
Making people aware
- 7.4Covered
Communicating about security
- 7.5Covered
Controlling documented information
8 — Operation
- 8.1Covered
Planning and controlling how the ISMS runs
- 8.2Covered
Assessing risk at planned intervals, and when things change
- 8.3Covered
Carrying out the risk treatment plan
9 — Performance evaluation
- 9.1Covered
Monitoring, measuring, analysing and evaluating
- 9.2.1Covered
Running internal audits
- 9.2.2Covered
The audit programme behind those audits
- 9.3Covered
Management review
10 — Improvement
- 10.1Covered
Continual improvement
- 10.2Covered
Nonconformity and corrective action
Clause numbers are exact. The descriptions are our own wording — ISO's text is copyrighted and is not reproduced here. Buy the standard from ISO or your national body to read it in full.