ISO 27001

What we cover, clause by clause.

ISO/IEC 27001:2022 is 93 Annex A controls and clauses 4 to 10 — the management system around them. Most tools talk about the controls. This page is the other half: which clauses StandardOS holds your records for, where each one lives, and what remains yours to do whatever tool you buy.

26

covered

1

limit no tool removes

All 26 clauses have a place in the product, and each row below says where. That is not the same as being ready: an auditor tests what you have written, not what the software can hold, and an empty register in a covered clause passes nothing. Clause 5.1 is the honest edge — we can assemble the evidence that leadership committed, and we cannot be the commitment. The same page lives inside the product, counting what you have actually written against each clause, which is the number that decides your audit.

4 — Context of the organization

  • 4.1

    Understanding the organization and what surrounds it

    Covered
  • 4.2

    Who has an interest, and what they require

    Covered
  • 4.3

    Deciding what the ISMS covers

    Covered
  • 4.4

    The ISMS and the processes that make it up

    Covered

5 — Leadership

  • 5.1

    Leadership actually owning the system

    Every demonstration the clause asks for is assembled from records held elsewhere in the management system, so the evidence is produced rather than asserted. No software can show that top management personally did any of it — your auditor establishes that by interviewing them, and no tool in this market changes that.

    Covered
  • 5.2

    An information security policy

    Covered
  • 5.3

    Who is responsible for what, and with what authority

    Covered

6 — Planning

  • 6.1.1

    Acting on risks and on opportunities

    Covered
  • 6.1.2

    How risk is assessed, on your own scale

    Covered
  • 6.1.3

    Choosing controls and stating which apply

    Covered
  • 6.2

    Security objectives and how they will be met

    Covered
  • 6.3

    Planning changes to the ISMS

    Covered

7 — Support

  • 7.1

    The resources the ISMS needs

    Covered
  • 7.2

    Competence, and evidence of it

    Covered
  • 7.3

    Making people aware

    Covered
  • 7.4

    Communicating about security

    Covered
  • 7.5

    Controlling documented information

    Covered

8 — Operation

  • 8.1

    Planning and controlling how the ISMS runs

    Covered
  • 8.2

    Assessing risk at planned intervals, and when things change

    Covered
  • 8.3

    Carrying out the risk treatment plan

    Covered

9 — Performance evaluation

  • 9.1

    Monitoring, measuring, analysing and evaluating

    Covered
  • 9.2.1

    Running internal audits

    Covered
  • 9.2.2

    The audit programme behind those audits

    Covered
  • 9.3

    Management review

    Covered

10 — Improvement

  • 10.1

    Continual improvement

    Covered
  • 10.2

    Nonconformity and corrective action

    Covered

Clause numbers are exact. The descriptions are our own wording — ISO's text is copyrighted and is not reproduced here. Buy the standard from ISO or your national body to read it in full.