1.2 ISO/IEC 27001:2022 Clauses 4 to 10 Requirements

Key Takeaways

  • Clauses 4–10 of ISO/IEC 27001:2022 are normative requirements for the ISMS; Annex A is an informative reference of 93 controls in four themes used with risk treatment and the SoA.
  • Clause 4 requires context, interested parties, and a defined ISMS scope; Clause 5 requires demonstrable top-management leadership, policy, and assigned authorities.
  • Clause 6 planning covers actions on risks and opportunities plus information security objectives; Clause 8 operationalizes risk assessment and risk treatment.
  • Clause 7 (Support) covers resources, competence, awareness, communication, and documented information that make the system workable.
  • Clause 9 performance evaluation (monitoring, internal audit, management review) and Clause 10 improvement (nonconformity and corrective action, continual improvement) close the PDCA loop.
Last updated: July 2026

Why Clauses 4–10 matter for Lead Auditors

On the CQI/IRCA PR373 path, you audit conformity primarily against ISO/IEC 27001:2022 Clauses 4–10. Those clauses are normative: the organization shall meet them within the defined ISMS scope. Annex A is an informative reference listing 93 controls in four themes. A competent Lead Auditor can explain the difference in one sentence: Clauses 4–10 define the management system; Annex A offers a structured catalogue of controls to consider when treating risk and completing the Statement of Applicability.

ISO/IEC 27001 follows ISO's High-Level Structure (HLS), which aligns clause numbering with other management system standards (for example quality or environmental systems). That compatibility helps integrated audits, but your exam focus remains information security outcomes and ISMS evidence. Auditing practice is guided by ISO 19011, and certification bodies operate under ISO/IEC 17021 as applicable—use those as course-consistent references without inventing exam edition-switch stories.

Clause map at a glance

ClauseTitleAuditor focus in plain language
4Context of the organizationIssues, interested parties, scope, ISMS established
5LeadershipTop management commitment, policy, roles/authorities
6PlanningRisks/opportunities, risk assessment/treatment process, objectives
7SupportResources, competence, awareness, communication, documented information
8OperationOperational control; perform risk assessment and treatment
9Performance evaluationMonitoring/measurement, internal audit, management review
10ImprovementContinual improvement; nonconformity and corrective action

Clause 4 — Context of the organization

4.1 Understanding the organization and its context

The organization shall determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS. External examples include regulatory pressure, threat landscape, supplier ecosystems, and market expectations. Internal examples include culture, governance model, technology estate, and contractual commitments.

4.2 Interested parties

Determine interested parties relevant to the ISMS and their requirements. Parties often include customers, regulators, employees, shareholders, cloud providers, and insurers. Not every wish becomes an ISMS requirement; the organization determines which requirements are relevant.

4.3 Determining the scope of the ISMS

Define boundaries and applicability considering context, interested parties, and interfaces/dependencies. Scope must be available as documented information. Weak scopes hide high-risk processes "outside ISO" without justification—an audit red flag.

4.4 Information security management system

Establish, implement, maintain, and continually improve an ISMS in accordance with the standard—including the processes needed and their interactions.

Audit scenario: A logistics firm scopes "HQ IT only" while warehouse scanning systems process personal data for the same service. The auditor should test whether context and interested-party requirements were honestly considered when setting boundaries.

Clause 5 — Leadership

5.1 Leadership and commitment

Top management shall demonstrate leadership and commitment by, among other duties, ensuring the ISMS is compatible with the strategic direction, integrating requirements into business processes, providing resources, communicating importance, and directing/supporting continual improvement. Delegation of tasks is allowed; abdication of accountability is not.

5.2 Policy

Top management shall establish an information security policy appropriate to the purpose of the organization, including information security objectives or a framework for setting them, commitment to satisfy applicable requirements, and commitment to continual improvement. The policy shall be available as documented information, communicated, and available to interested parties as appropriate.

5.3 Organizational roles, responsibilities and authorities

Assign and communicate responsibilities and authorities for roles relevant to information security, including reporting on ISMS performance to top management.

Audit scenario: The CISO presents the policy, but the CEO cannot explain residual risk acceptance or resource decisions. Interviews should probe whether Clause 5.1 commitment is real or ceremonial.

Clause 6 — Planning

Clause 6 is where many Domain 1 and planning questions connect to later deep dives on risk.

6.1 Actions to address risks and opportunities

When planning the ISMS, consider Clause 4 issues and requirements and determine risks and opportunities that need to be addressed so the ISMS can achieve intended outcomes, prevent/reduce undesired effects, and achieve continual improvement.

For information security risk assessment, the organization shall define and apply a process that:

  • Establishes and maintains risk criteria (including risk acceptance criteria and criteria for performing assessments)
  • Ensures consistent, valid, and comparable results
  • Identifies risks associated with loss of confidentiality, integrity, and availability within scope, and identifies risk owners
  • Analyses consequences and likelihood to determine levels of risk
  • Evaluates risks against criteria to prioritize treatment

For risk treatment, the organization shall define and apply a process to select treatment options, determine all controls needed, compare controls with those in Annex A so no necessary controls are overlooked, produce a Statement of Applicability, formulate a risk treatment plan, and obtain risk owners' approval of residual risk.

6.2 Information security objectives and planning to achieve them

Objectives shall be consistent with the policy, measurable (if practicable), take into account requirements and risk assessment results, be monitored, communicated, and updated as appropriate. Plans shall determine what will be done, resources, responsibilities, timelines, and evaluation of results.

6.3 Planning of changes

When the organization determines the need for changes to the ISMS, changes shall be carried out in a planned manner.

Clause 7 — Support

SubclauseRequirement themeTypical evidence
7.1 ResourcesProvide resources needed for the ISMSBudgets, staffing, tools
7.2 CompetenceDetermine competence; ensure competence; take actions; retain evidenceJob profiles, training records, qualifications
7.3 AwarenessPersons aware of policy, their contribution, implications of nonconformityAwareness campaigns, onboarding modules
7.4 CommunicationWhat, when, with whom, how to communicateCommunication plans, tickets, notices
7.5 Documented informationRequired documented information created, updated, controlledDocument control, versioning, protection of records

Competence and awareness are frequent minor/major nonconformity sources because "everyone completed a slide deck" may not prove role-specific competence for privileged administrators or developers shipping security-critical changes.

Clause 8 — Operation

8.1 Operational planning and control

Plan, implement, and control processes needed to meet requirements and to implement actions determined in Clause 6. Control planned changes, review consequences of unintended changes, and ensure outsourced processes are controlled. Retain documented information necessary for confidence that processes were carried out as planned.

8.2 Information security risk assessment

Perform risk assessments at planned intervals or when significant changes are proposed or occur, retaining documented information of the results.

8.3 Information security risk treatment

Implement the risk treatment plan and retain documented information of the results of risk treatment.

Audit scenario: Risk assessment is two years old despite a major cloud migration. Clause 8.2 "significant changes" is a strong conformity question even if the original Clause 6 methodology looked elegant on paper.

Clause 9 — Performance evaluation

9.1 Monitoring, measurement, analysis and evaluation

Determine what needs to be monitored and measured, methods, when monitoring is performed, and when results are analysed and evaluated. Evaluate information security performance and ISMS effectiveness. Retain appropriate documented information.

9.2 Internal audit

Conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the organization's requirements and to ISO/IEC 27001, and is effectively implemented and maintained. Plan a programme, define criteria and scope, select objective auditors, report results, and retain documented information.

9.3 Management review

Top management shall review the ISMS at planned intervals. Inputs include status of actions from previous reviews, changes in issues, feedback, performance information (including nonconformities, monitoring results, audit results), opportunities for continual improvement, and results of risk assessment / status of risk treatment plan. Outputs include decisions on continual improvement opportunities and any needs for changes to the ISMS. Retain documented information as evidence of reviews.

Clause 10 — Improvement

10.1 Continual improvement

Continually improve the suitability, adequacy, and effectiveness of the ISMS.

10.2 Nonconformity and corrective action

When a nonconformity occurs, react, evaluate the need for action to eliminate causes so it does not recur or occur elsewhere, implement any needed action, review effectiveness, and make changes to the ISMS if necessary. Corrective actions shall be appropriate to the effects of the nonconformities. Retain documented information on the nature of nonconformities, actions taken, and results of corrective action.

How clauses interact (auditor mental model)

Context (4) and leadership (5) shape planning (6). Support (7) enables operation (8). Performance evaluation (9) tests whether the system works. Improvement (10) feeds the next planning cycle. Annex A controls appear in treatment and the SoA because Clause 6 requires comparison with Annex A—not because Annex A alone is the management system.

Integrated example: Interested parties require breach notification (4.2) → policy and roles commit to incident handling (5) → risk assessment rates ransomware high (6/8) → competence for responders is demonstrated (7.2) → monitoring detects anomalies (9.1) → a missed alert becomes a nonconformity with corrective action (10.2) → management review adjusts objectives and resources (9.3 → 6.2).

Exam-oriented reminders

  • Audit criteria for certification are Clauses 4–10, not "Annex A percentage complete."
  • Internal audit lives in Clause 9.2; do not place it under Clause 6 or 10.
  • Top management owns leadership commitments in Clause 5 even when a security team runs day-to-day tasks.
  • Risk assessment appears in planning (6) and must be performed in operation (8.2).
  • Keep Domain 1 timing context: online exam 40 questions / 1h 45m / five sections; do not invent a published pass percentage.
Test Your Knowledge

Which statement correctly describes Annex A in ISO/IEC 27001:2022 relative to Clauses 4 to 10?

A
B
C
D
Test Your Knowledge

Under Clause 5 of ISO/IEC 27001:2022, who must demonstrate leadership and commitment with respect to the ISMS, including ensuring integration of ISMS requirements into business processes?

A
B
C
D
Test Your Knowledge

Which clause specifically requires internal audits of the ISMS at planned intervals?

A
B
C
D