ISO 27001 clauses 4 to 10, requirement by
Annex A gets the attention and clauses 4 to 10 get the nonconformities. These 25 requirements are the mandatory part of ISO 27001, none of them can be excluded, and this page lists every one with the record that satisfies it.
Clauses 4 to 10 of ISO/IEC 27001:2022 carry 25 mandatory requirements. Every one of them applies to every certified organization, no matter the size or the scope, and unlike the 93 Annex A controls not one of them can be excluded with a justification. Clauses 1 to 3 are scope, normative references and terms, and they are not auditable. If you have been told the standard has 114 requirements or 118 controls, someone has added two different things together.
This is the half of the standard that fails first. Annex A tends to be engineering work that is either done or visibly not done, and clauses 4 to 10 are management work that is usually happening informally and has no record attached to it. The controls that go with the annex are covered separately on the Annex A page.
How the 25 requirements are distributed
| Clause | Requirements | Where the work sits |
|---|---|---|
| 4 Context of the organization | 4 | One afternoon of thinking and one page of scope that decides the audit fee |
| 5 Leadership | 3 | Executive time, not security team time |
| 6 Planning | 5 | The heaviest clause. Risk assessment, risk treatment, Statement of Applicability, objectives |
| 7 Support | 5 | Competence records, awareness training, and document control that runs forever |
| 8 Operation | 3 | Mostly a restatement of clause 6 as a running activity |
| 9 Performance evaluation | 3 | Measurement, internal audit, management review. All three are records with dates |
| 10 Improvement | 2 | The corrective action log, which auditors read closely |
| Total mandatory requirements | 25 | None excludable. Separate from the 93 Annex A controls |
What each of the 25 requirements asks for
This is the table to work from. The right-hand column is the record a certification body asks to see, which is a more useful thing to know than the wording of the requirement, because the wording rarely tells you what will satisfy it.
| Clause | What it requires | Evidence an auditor accepts |
|---|---|---|
| 4.1 Context | Determine external and internal issues relevant to your information security outcomes | A short issues register. Two pages, reviewed at management review, is enough |
| 4.2 Interested parties | Identify interested parties and which of their requirements are relevant | A table naming customers, regulators, staff and the specific obligation each brings, such as PIPEDA or a contract security schedule |
| 4.3 Scope | Determine the boundaries and applicability of the ISMS, considering 4.1, 4.2 and the interfaces and dependencies with other organizations | A scope statement held as documented information. See the scope statement page |
| 4.4 The ISMS itself | Establish, implement, maintain and continually improve the management system, including the processes it needs | The system existing and running. Usually evidenced by everything else on this list |
| 5.1 Leadership and commitment | Eight specific things top management shall do, from resourcing to promoting improvement | Board or executive minutes, budget approvals, the review record. Covered on the clause 5 page |
| 5.2 Policy | An information security policy that is appropriate to the purpose, frames objectives, commits to applicable requirements and to continual improvement | One approved top-level policy, dated, communicated, available to interested parties as appropriate |
| 5.3 Roles and authorities | Assign responsibility for conformity of the ISMS and for reporting its performance to top management | A responsibility matrix or the job description, plus proof the person named knows they hold it |
| 6.1.1 Risks and opportunities | Plan actions addressing the risks and opportunities arising from 4.1 and 4.2 | Usually folded into the risk method document |
| 6.1.2 Risk assessment | Define and apply a risk assessment process with criteria, consistency, identification, analysis and evaluation | A documented method and a populated register. See the risk assessment method |
| 6.1.3 Risk treatment | Select treatments, compare against Annex A, produce a Statement of Applicability, formulate a risk treatment plan, obtain owner approval of residual risk | The Statement of Applicability and the risk treatment plan, both approved |
| 6.2 Objectives | Measurable information security objectives, planned, monitored, communicated and held as documented information | Four to eight objectives with a number, an owner and a date. Not aspirations |
| 6.3 Planning of changes | Changes to the ISMS shall be carried out in a planned manner | Added in the 2022 edition and often missed. Evidence is a change record for ISMS changes, not just for systems |
| 7.1 Resources | Determine and provide the resources the ISMS needs | Budget line, headcount or a signed contract with a consultant or fractional security lead |
| 7.2 Competence | Determine necessary competence, ensure it, act where it is missing, retain evidence | Per-person records of training, education or experience for the roles named in 5.3 |
| 7.3 Awareness | People under your control shall be aware of the policy, their contribution, and the implications of not conforming | Training completion by person and date, sampled at stage 2. See clause 7 |
| 7.4 Communication | Determine what to communicate, when, with whom and how | A half-page communication plan covering internal and external, including breach notification routes |
| 7.5 Documented information | Create, update and control documents: identification, format, review and approval, availability, protection, version control, retention | Version history, approval records, an access model, and control of documents that come from outside |
| 8.1 Operational planning and control | Plan and control the processes, set criteria, control planned changes, review unintended ones, control outsourced processes | Operating procedures plus supplier control evidence. Externally provided processes are the part most often forgotten |
| 8.2 Risk assessment in operation | Perform risk assessments at planned intervals and when significant changes occur | Dated reassessments. Two in a year beats one, because the clause says intervals |
| 8.3 Risk treatment in operation | Implement the risk treatment plan and retain the results | Closure evidence against each treatment, not the plan itself |
| 9.1 Monitoring and measurement | Determine what to monitor, the methods, when, by whom, and when results are analysed | A measurement table with actual figures in it. Patch latency, phishing failure rate, access review completion |
| 9.2 Internal audit | An audit program at planned intervals, with objective auditors, reported to management | program, plan, findings and proof they reached management. See internal audit |
| 9.3 Management review | Top management reviews the ISMS at planned intervals against a defined input list, and records decisions | Minutes covering every required input. See management review |
| 10.1 Continual improvement | Continually improve the suitability, adequacy and effectiveness of the ISMS | An improvement log with things actually closed in it |
| 10.2 Nonconformity and corrective action | React, evaluate the cause, check whether it exists elsewhere, act, review effectiveness, record all of it | A corrective action register with root cause and effectiveness columns. See clause 10 |
Why clause 8 has no page of its own
Because it mostly says do what clause 6 planned. Clause 8.2 is the risk assessment from 6.1.2 performed on a schedule, and 8.3 is the risk treatment plan from 6.1.3 actually executed. The only genuinely new obligation is in 8.1, where the standard requires that externally provided processes, products and services relevant to the ISMS are controlled. For a Canadian software company running on a public cloud with a dozen software subscriptions, that single sentence is a supplier register, signed agreements with security terms, and a review cadence. It is more work than the rest of clause 8 combined and it is the part that gets read as boilerplate.
The 2022 requirement people still miss
Clause 6.3, planning of changes, was added in the 2022 edition. It asks that changes to the management system itself be carried out in a planned manner: a new product line brought into scope, an office closed, a subsidiary acquired. Companies that transitioned from the 2013 edition frequently have nothing against it, because their change management evidence is all about code and infrastructure. A change record for the scope change is what closes it.
Which clauses actually produce findings
Findings cluster in clause 9 and clause 7 for a structural reason. Both require records made at particular times, and a record that was never made cannot be produced on the day of the audit the way a firewall rule can. A missing management review is not fixable during stage 2. A missing training record for one of five sampled employees is not fixable either, because the date has passed.
- Fixable while the auditor is in the room
- A policy missing an approval signature, a register missing a column, an objective without a target. Documentation defects, which auditors will often let you correct on the spot.
- Not fixable on the day
- Anything with a date attached: the internal audit, the management review, a quarter of access reviews, the training completion for a leaver who has already left. These become nonconformities, and what happens next is on the nonconformity page.
- Not fixable this cycle
- An operating period that does not exist. If the system started running in July, no amount of money produces April evidence.
When this is more management system than you need
The honest counter-case. Clauses 4 to 10 describe a governance loop designed for an organization that will hold a certificate for years and be audited every one of them. If what you actually have is one enterprise customer asking a security question, the whole loop is disproportionate and there are two cheaper answers. A completed security questionnaire with real evidence attached will satisfy many buyers. A SOC 2 report satisfies most North American ones and does not require you to run a management review or an internal audit program at all, because the auditor tests your controls rather than your governance of them.
Clauses 4 to 10 earn their cost when the certificate is a repeated commercial requirement, when more than one buyer will ask, and when the same question will come back at every renewal. If you are not sure which of the two standards your buyer meant, the wording in their email usually settles it, and the comparison page takes it apart. Where neither is clearly required yet, working out which framework applies is a cheaper first step than starting either.
The order to build them in
- Clause 4.3 scope first, because it prices the audit and constrains everything after it.
- Clause 5.2 policy and 5.3 roles, because the risk work needs an owner with authority before it needs a method.
- Clause 6.1.2 and 6.1.3, the risk assessment, treatment plan and Statement of Applicability. This is the longest stretch.
- Clause 7 in parallel with the Annex A implementation, since competence and awareness records take calendar time to accumulate.
- Clause 8, which is clause 6 running with dates on it, for at least three months.
- Clause 9.1 measurement, then 9.2 internal audit, then 9.3 management review, in that order, because each is an input to the next.
- Clause 10 from the moment the internal audit produces its first finding. A corrective action register that opens the week before stage 2 is transparent.
The calendar version of this, with the months attached, is on the implementation page.
Get the clause work quoted properly
Tell us your scope and headcount and we will match you with Canadian firms that build management systems rather than sell templates.
Get matchedCommon questions
How many clauses does ISO 27001 have?
Ten, but only clauses 4 to 10 contain auditable requirements, and those seven clauses carry 25 numbered requirements between them. Clauses 1, 2 and 3 are the scope of the document, the normative references and the definitions. Annex A is separate again and holds 93 reference controls.
Can we exclude a clause the way we exclude an Annex A control?
No. Exclusion applies only to Annex A controls, and only with a justification recorded in the Statement of Applicability. All 25 clause requirements apply to every certified organization regardless of size, sector or scope. A management system that has decided not to do management review is not a management system a body can certify.
What is the difference between a clause and a control?
A clause is a mandatory requirement in the body of the standard about how the management system works: scope, leadership, risk, competence, audit, review, improvement. An Annex A control is one of 93 reference safeguards you select from to treat the risks you identified. Clauses are compulsory and controls are selected. Adding the two counts together and quoting a single figure is the clearest sign a page was written without the standard open.
Which clause causes the most trouble at certification?
Clause 9, for a structural reason: internal audit and management review both have to have happened before stage 2, and both are easy to defer while the technical work absorbs attention. Clause 7 is second, because competence and awareness evidence is per person and cannot be reconstructed after the fact.
Do we need a separate document for every clause?
No, and building one is a common way to produce a management system nobody uses. The standard requires specific documented information in particular places, notably the scope, the policy, the risk method, the Statement of Applicability, the objectives and a set of records. Everything else can live in whatever tools you already run, provided it can be found, it is version controlled and it is current.
Did the 2022 edition change the clauses?
Lightly. The structure stayed the same, the wording was aligned with the harmonised structure used across ISO management system standards, and clause 6.3 on planning of changes was added. The large change in 2022 was to Annex A, which went from 114 controls in 14 domains to 93 controls in four themes.