1.2 ISO/IEC 27001:2022 Clauses 4 to 10 Requirements
Key Takeaways
- Clauses 4–10 of ISO/IEC 27001:2022 are normative requirements for the ISMS; Annex A is an informative reference of 93 controls in four themes used with risk treatment and the SoA.
- Clause 4 requires context, interested parties, and a defined ISMS scope; Clause 5 requires demonstrable top-management leadership, policy, and assigned authorities.
- Clause 6 planning covers actions on risks and opportunities plus information security objectives; Clause 8 operationalizes risk assessment and risk treatment.
- Clause 7 (Support) covers resources, competence, awareness, communication, and documented information that make the system workable.
- Clause 9 performance evaluation (monitoring, internal audit, management review) and Clause 10 improvement (nonconformity and corrective action, continual improvement) close the PDCA loop.
Why Clauses 4–10 matter for Lead Auditors
On the CQI/IRCA PR373 path, you audit conformity primarily against ISO/IEC 27001:2022 Clauses 4–10. Those clauses are normative: the organization shall meet them within the defined ISMS scope. Annex A is an informative reference listing 93 controls in four themes. A competent Lead Auditor can explain the difference in one sentence: Clauses 4–10 define the management system; Annex A offers a structured catalogue of controls to consider when treating risk and completing the Statement of Applicability.
ISO/IEC 27001 follows ISO's High-Level Structure (HLS), which aligns clause numbering with other management system standards (for example quality or environmental systems). That compatibility helps integrated audits, but your exam focus remains information security outcomes and ISMS evidence. Auditing practice is guided by ISO 19011, and certification bodies operate under ISO/IEC 17021 as applicable—use those as course-consistent references without inventing exam edition-switch stories.
Clause map at a glance
| Clause | Title | Auditor focus in plain language |
|---|---|---|
| 4 | Context of the organization | Issues, interested parties, scope, ISMS established |
| 5 | Leadership | Top management commitment, policy, roles/authorities |
| 6 | Planning | Risks/opportunities, risk assessment/treatment process, objectives |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | Operational control; perform risk assessment and treatment |
| 9 | Performance evaluation | Monitoring/measurement, internal audit, management review |
| 10 | Improvement | Continual improvement; nonconformity and corrective action |
Clause 4 — Context of the organization
4.1 Understanding the organization and its context
The organization shall determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS. External examples include regulatory pressure, threat landscape, supplier ecosystems, and market expectations. Internal examples include culture, governance model, technology estate, and contractual commitments.
4.2 Interested parties
Determine interested parties relevant to the ISMS and their requirements. Parties often include customers, regulators, employees, shareholders, cloud providers, and insurers. Not every wish becomes an ISMS requirement; the organization determines which requirements are relevant.
4.3 Determining the scope of the ISMS
Define boundaries and applicability considering context, interested parties, and interfaces/dependencies. Scope must be available as documented information. Weak scopes hide high-risk processes "outside ISO" without justification—an audit red flag.
4.4 Information security management system
Establish, implement, maintain, and continually improve an ISMS in accordance with the standard—including the processes needed and their interactions.
Audit scenario: A logistics firm scopes "HQ IT only" while warehouse scanning systems process personal data for the same service. The auditor should test whether context and interested-party requirements were honestly considered when setting boundaries.
Clause 5 — Leadership
5.1 Leadership and commitment
Top management shall demonstrate leadership and commitment by, among other duties, ensuring the ISMS is compatible with the strategic direction, integrating requirements into business processes, providing resources, communicating importance, and directing/supporting continual improvement. Delegation of tasks is allowed; abdication of accountability is not.
5.2 Policy
Top management shall establish an information security policy appropriate to the purpose of the organization, including information security objectives or a framework for setting them, commitment to satisfy applicable requirements, and commitment to continual improvement. The policy shall be available as documented information, communicated, and available to interested parties as appropriate.
5.3 Organizational roles, responsibilities and authorities
Assign and communicate responsibilities and authorities for roles relevant to information security, including reporting on ISMS performance to top management.
Audit scenario: The CISO presents the policy, but the CEO cannot explain residual risk acceptance or resource decisions. Interviews should probe whether Clause 5.1 commitment is real or ceremonial.
Clause 6 — Planning
Clause 6 is where many Domain 1 and planning questions connect to later deep dives on risk.
6.1 Actions to address risks and opportunities
When planning the ISMS, consider Clause 4 issues and requirements and determine risks and opportunities that need to be addressed so the ISMS can achieve intended outcomes, prevent/reduce undesired effects, and achieve continual improvement.
For information security risk assessment, the organization shall define and apply a process that:
- Establishes and maintains risk criteria (including risk acceptance criteria and criteria for performing assessments)
- Ensures consistent, valid, and comparable results
- Identifies risks associated with loss of confidentiality, integrity, and availability within scope, and identifies risk owners
- Analyses consequences and likelihood to determine levels of risk
- Evaluates risks against criteria to prioritize treatment
For risk treatment, the organization shall define and apply a process to select treatment options, determine all controls needed, compare controls with those in Annex A so no necessary controls are overlooked, produce a Statement of Applicability, formulate a risk treatment plan, and obtain risk owners' approval of residual risk.
6.2 Information security objectives and planning to achieve them
Objectives shall be consistent with the policy, measurable (if practicable), take into account requirements and risk assessment results, be monitored, communicated, and updated as appropriate. Plans shall determine what will be done, resources, responsibilities, timelines, and evaluation of results.
6.3 Planning of changes
When the organization determines the need for changes to the ISMS, changes shall be carried out in a planned manner.
Clause 7 — Support
| Subclause | Requirement theme | Typical evidence |
|---|---|---|
| 7.1 Resources | Provide resources needed for the ISMS | Budgets, staffing, tools |
| 7.2 Competence | Determine competence; ensure competence; take actions; retain evidence | Job profiles, training records, qualifications |
| 7.3 Awareness | Persons aware of policy, their contribution, implications of nonconformity | Awareness campaigns, onboarding modules |
| 7.4 Communication | What, when, with whom, how to communicate | Communication plans, tickets, notices |
| 7.5 Documented information | Required documented information created, updated, controlled | Document control, versioning, protection of records |
Competence and awareness are frequent minor/major nonconformity sources because "everyone completed a slide deck" may not prove role-specific competence for privileged administrators or developers shipping security-critical changes.
Clause 8 — Operation
8.1 Operational planning and control
Plan, implement, and control processes needed to meet requirements and to implement actions determined in Clause 6. Control planned changes, review consequences of unintended changes, and ensure outsourced processes are controlled. Retain documented information necessary for confidence that processes were carried out as planned.
8.2 Information security risk assessment
Perform risk assessments at planned intervals or when significant changes are proposed or occur, retaining documented information of the results.
8.3 Information security risk treatment
Implement the risk treatment plan and retain documented information of the results of risk treatment.
Audit scenario: Risk assessment is two years old despite a major cloud migration. Clause 8.2 "significant changes" is a strong conformity question even if the original Clause 6 methodology looked elegant on paper.
Clause 9 — Performance evaluation
9.1 Monitoring, measurement, analysis and evaluation
Determine what needs to be monitored and measured, methods, when monitoring is performed, and when results are analysed and evaluated. Evaluate information security performance and ISMS effectiveness. Retain appropriate documented information.
9.2 Internal audit
Conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the organization's requirements and to ISO/IEC 27001, and is effectively implemented and maintained. Plan a programme, define criteria and scope, select objective auditors, report results, and retain documented information.
9.3 Management review
Top management shall review the ISMS at planned intervals. Inputs include status of actions from previous reviews, changes in issues, feedback, performance information (including nonconformities, monitoring results, audit results), opportunities for continual improvement, and results of risk assessment / status of risk treatment plan. Outputs include decisions on continual improvement opportunities and any needs for changes to the ISMS. Retain documented information as evidence of reviews.
Clause 10 — Improvement
10.1 Continual improvement
Continually improve the suitability, adequacy, and effectiveness of the ISMS.
10.2 Nonconformity and corrective action
When a nonconformity occurs, react, evaluate the need for action to eliminate causes so it does not recur or occur elsewhere, implement any needed action, review effectiveness, and make changes to the ISMS if necessary. Corrective actions shall be appropriate to the effects of the nonconformities. Retain documented information on the nature of nonconformities, actions taken, and results of corrective action.
How clauses interact (auditor mental model)
Context (4) and leadership (5) shape planning (6). Support (7) enables operation (8). Performance evaluation (9) tests whether the system works. Improvement (10) feeds the next planning cycle. Annex A controls appear in treatment and the SoA because Clause 6 requires comparison with Annex A—not because Annex A alone is the management system.
Integrated example: Interested parties require breach notification (4.2) → policy and roles commit to incident handling (5) → risk assessment rates ransomware high (6/8) → competence for responders is demonstrated (7.2) → monitoring detects anomalies (9.1) → a missed alert becomes a nonconformity with corrective action (10.2) → management review adjusts objectives and resources (9.3 → 6.2).
Exam-oriented reminders
- Audit criteria for certification are Clauses 4–10, not "Annex A percentage complete."
- Internal audit lives in Clause 9.2; do not place it under Clause 6 or 10.
- Top management owns leadership commitments in Clause 5 even when a security team runs day-to-day tasks.
- Risk assessment appears in planning (6) and must be performed in operation (8.2).
- Keep Domain 1 timing context: online exam 40 questions / 1h 45m / five sections; do not invent a published pass percentage.
Which statement correctly describes Annex A in ISO/IEC 27001:2022 relative to Clauses 4 to 10?
Under Clause 5 of ISO/IEC 27001:2022, who must demonstrate leadership and commitment with respect to the ISMS, including ensuring integration of ISMS requirements into business processes?
Which clause specifically requires internal audits of the ISMS at planned intervals?