skip to content

In ISO/IEC 27001:2022, what do clauses 4 to 10 require, and why is implementing Annex A controls alone not enough for certification?

level: middleimportance: must knowfreq 55%

answer

  1. the management system, not the checklist
  2. context to improvement
  3. leadership signs up
  4. plan, operate, evaluate, improve
  5. no exclusions from 4 to 10

basics

~20 s

Clauses 4 to 10 require the management system itself: context and scope, leadership, risk-based planning, support, operation, performance evaluation and improvement. They cannot be excluded, so controls without a working, audited and reviewed ISMS do not conform.

solid answer

~50 s

ISO/IEC 27001:2022 clauses 4 to 10 are all mandatory, and the standard states that excluding any of them is not acceptable when claiming conformity. **Clause 4** fixes context, interested parties and the ISMS scope. **Clause 5** requires top management commitment, an information security policy and assigned roles. **Clause 6** requires the risk assessment and treatment process, the Statement of Applicability, security objectives and planned changes. **Clause 7** covers resources, competence, awareness, communication and documented information. **Clause 8** runs those plans. **Clause 9** measures, audits internally and holds management reviews. **Clause 10** handles nonconformities, corrective action and continual improvement. Annex A controls are only the output of clause 6's risk treatment. An organization with strong controls but no scope, no risk process, no internal audit or no management review fails certification, because the auditor certifies the system that keeps the controls right, not a snapshot of them.

go deeper

for a junior

Recall the seven clause titles from context to improvement and that all of them are mandatory.

for a middle

Explain how clause 6's risk treatment produces the Annex A control selection and the Statement of Applicability, and what clause 9 asks for.

for a senior

Show how you would take an engineering-strong company with no ISMS to a stage 1 audit: scope, risk method, policy, first internal audit and management review.

for a principal

Discuss how to set an ISMS scope that satisfies customers without swallowing the whole company, and how the management system should integrate with existing governance.

## The shape of the standard ISO/IEC 27001:2022 follows the harmonized structure shared by ISO management-system standards. Clauses 0 to 3 are introductory (introduction, scope, normative references, terms). **Clauses 4 to 10 are the requirements**, and the standard says an organization cannot exclude any of them and still claim conformity. **Annex A** then lists the 93 reference controls. ## What each clause requires | Clause | Title | What must exist | |---|---|---| | 4 | Context of the organization | External and internal issues, interested parties and their requirements, a documented **ISMS scope** | | 5 | Leadership | Top management commitment, an **information security policy**, assigned roles and authorities | | 6 | Planning | Risk assessment and **risk treatment** processes, the **Statement of Applicability**, measurable objectives, planned changes | | 7 | Support | Resources, **competence**, awareness, communication, controlled **documented information** | | 8 | Operation | Carrying out the planned processes, performing risk assessments at planned intervals, implementing the treatment plan | | 9 | Performance evaluation | Monitoring and measurement, **internal audit**, **management review** | | 10 | Improvement | Continual improvement, **nonconformity and corrective action** | Read together, clauses 4 to 10 form a plan-do-check-act loop: define context and plan (4–6), resource and run (7–8), check (9), improve (10). ## Where Annex A fits Annex A is not a checklist to implement top to bottom. Within clause 6 the organization: 1. Assesses information security risks against its own criteria. 2. Chooses treatment options and determines the controls needed. 3. Compares those controls with **Annex A** to check nothing necessary was missed. 4. Produces the **Statement of Applicability**, listing necessary controls, why they are included, whether they are implemented, and why any Annex A control is excluded. 5. Writes a risk treatment plan and obtains the **risk owners'** approval of it and their acceptance of residual risk. So Annex A controls are an output of the management system, and they stay right only because the system keeps re-running. ## Why controls alone fail certification Consider a 250-person SaaS company with excellent engineering hygiene: SSO everywhere, encrypted storage, tested backups, a solid secure development process. It asks for certification with no scope statement, no risk assessment, no internal audit and no management review. - The **stage 1** audit finds no documented scope or risk methodology, and the organization is not ready for stage 2. - Even with documents written overnight, **stage 2** needs evidence the system has *operated*: at least one internal audit, a management review, objectives being measured. - Missing a whole clause, such as no internal audit ever held, is typically raised as a **major nonconformity**, which blocks certification until corrected. The certificate asserts that a management system exists and works for a defined scope, which is why customers can rely on it between audits. ## What the 2022 edition changed in the clauses - A requirement to plan **changes** to the ISMS in a controlled way. - More explicit requirements to determine the **processes** the ISMS needs and their interactions. - Clarified monitoring and measurement and objectives. - Amendment 1:2024 added a requirement to consider whether **climate change** is a relevant issue when determining context. ## Common mistakes - Writing a scope that excludes the systems customers actually care about. - A policy signed by the security lead rather than top management. - Treating documentation as the ISMS rather than as evidence of it.

  • Can a company exclude a clause, say internal audit, because it is small?
    No. ISO/IEC 27001 says excluding any requirement in clauses 4 to 10 is not acceptable when claiming conformity. A small company can run a lighter internal audit, for example using a competent external auditor, but it must plan and perform one. Only Annex A controls may be excluded, and only with justification in the Statement of Applicability.
  • What does 'ISMS scope' decide, and why do auditors challenge it?
    The scope sets which organizational units, locations, systems and processes the ISMS, and therefore the certificate, covers, taking account of interfaces and dependencies with what is outside. Auditors challenge scopes that carve out the product customers use or the teams that run it, because a certificate for a narrow scope says little about the service a customer buys.

saying these in an interview costs you the question

  • Certification means implementing all 93 Annex A controls.
  • Small organizations may skip internal audit or management review.
  • The ISMS is the collection of policy documents.
  • The information security policy only needs the CISO's signature.
  • Clauses 4 to 10 are guidance and Annex A is the requirement.