Onwyn › Standards › ISO/IEC 27001:2022
Certifiable standard · 2022ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for running an information security management system (ISMS): a repeatable way of deciding what to protect, treating the risks, and proving it works. Companies pursue certification when customers, tenders, or regulators demand independent proof of security discipline. The standard has two parts: the management-system clauses 4-10 that everyone must implement, and Annex A, a catalogue of 93 controls you select from based on your risk assessment.
What this standard asks for
Every requirement in ISO/IEC 27001:2022, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
Context of the organization
4 requirements
- 4.1Understanding the organization and its context
- 4.2Understanding the needs and expectations of interested parties
- 4.3Determining the scope of the ISMS
- 4.4Information security management system
Leadership
3 requirements
- 5.1Leadership and commitment
- 5.2Policy
- 5.3Organizational roles, responsibilities and authorities
Planning
5 requirements
- 6.1.1Actions to address risks and opportunities — general
- 6.1.2Information security risk assessment
- 6.1.3Information security risk treatment
- 6.2Information security objectives and planning to achieve them
- 6.3Planning of changes
Support
5 requirements
- 7.1Resources
- 7.2Competence
- 7.3Awareness
- 7.4Communication
- 7.5Documented information
Operation
3 requirements
- 8.1Operational planning and control
- 8.2Information security risk assessment (performance)
- 8.3Information security risk treatment (performance)
Performance evaluation
3 requirements
- 9.1Monitoring, measurement, analysis and evaluation
- 9.2Internal audit
- 9.3Management review
Improvement
2 requirements
- 10.1Continual improvement
- 10.2Nonconformity and corrective action
Organizational controls (A.5)
37 requirements
- A.5.1Policies for information security
- A.5.2Information security roles and responsibilities
- A.5.3Segregation of duties
- A.5.4Management responsibilities
- A.5.5Contact with authorities
- A.5.6Contact with special interest groups
- A.5.7Threat intelligence
- A.5.8Information security in project management
- A.5.9Inventory of information and other associated assets
- A.5.10Acceptable use of information and other associated assets
- A.5.11Return of assets
- A.5.12Classification of information
- A.5.13Labelling of information
- A.5.14Information transfer
- A.5.15Access control
- A.5.16Identity management
- A.5.17Authentication information
- A.5.18Access rights
- A.5.19Information security in supplier relationships
- A.5.20Addressing information security within supplier agreements
- A.5.21Managing information security in the ICT supply chain
- A.5.22Monitoring, review and change management of supplier services
- A.5.23Information security for use of cloud services
- A.5.24Information security incident management planning and preparation
- A.5.25Assessment and decision on information security events
- A.5.26Response to information security incidents
- A.5.27Learning from information security incidents
- A.5.28Collection of evidence
- A.5.29Information security during disruption
- A.5.30ICT readiness for business continuity
- A.5.31Legal, statutory, regulatory and contractual requirements
- A.5.32Intellectual property rights
- A.5.33Protection of records
- A.5.34Privacy and protection of PII
- A.5.35Independent review of information security
- A.5.36Compliance with policies, rules and standards for information security
- A.5.37Documented operating procedures
People controls (A.6)
8 requirements
- A.6.1Screening
- A.6.2Terms and conditions of employment
- A.6.3Information security awareness, education and training
- A.6.4Disciplinary process
- A.6.5Responsibilities after termination or change of employment
- A.6.6Confidentiality or non-disclosure agreements
- A.6.7Remote working
- A.6.8Information security event reporting
Physical controls (A.7)
14 requirements
- A.7.1Physical security perimeters
- A.7.2Physical entry
- A.7.3Securing offices, rooms and facilities
- A.7.4Physical security monitoring
- A.7.5Protecting against physical and environmental threats
- A.7.6Working in secure areas
- A.7.7Clear desk and clear screen
- A.7.8Equipment siting and protection
- A.7.9Security of assets off-premises
- A.7.10Storage media
- A.7.11Supporting utilities
- A.7.12Cabling security
- A.7.13Equipment maintenance
- A.7.14Secure disposal or re-use of equipment
Technological controls (A.8)
34 requirements
- A.8.1User endpoint devices
- A.8.2Privileged access rights
- A.8.3Information access restriction
- A.8.4Access to source code
- A.8.5Secure authentication
- A.8.6Capacity management
- A.8.7Protection against malware
- A.8.8Management of technical vulnerabilities
- A.8.9Configuration management
- A.8.10Information deletion
- A.8.11Data masking
- A.8.12Data leakage prevention
- A.8.13Information backup
- A.8.14Redundancy of information processing facilities
- A.8.15Logging
- A.8.16Monitoring activities
- A.8.17Clock synchronization
- A.8.18Use of privileged utility programs
- A.8.19Installation of software on operational systems
- A.8.20Networks security
- A.8.21Security of network services
- A.8.22Segregation of networks
- A.8.23Web filtering
- A.8.24Use of cryptography
- A.8.25Secure development life cycle
- A.8.26Application security requirements
- A.8.27Secure system architecture and engineering principles
- A.8.28Secure coding
- A.8.29Security testing in development and acceptance
- A.8.30Outsourced development
- A.8.31Separation of development, test and production environments
- A.8.32Change management
- A.8.33Test information
- A.8.34Protection of information systems during audit testing
The documents you will end up with
The recommended document set for ISO/IEC 27001:2022 — 32 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
Says in plain words which parts of the business, which locations and which systems your security programme covers — and what is deliberately outside it.
The top-level statement of what the company commits to on security, signed by whoever is actually accountable.
Names who owns security decisions, who runs day-to-day security work, and which duties must not sit with the same person.
Explains how you find security risks, how you score them, and how you decide what to do about each one — so two people assessing the same risk land in the same place.
Lists every Annex A control, whether you apply it, and why — the single page auditors open first.
The working list of what you are actually going to do about each accepted risk, who owns it and by when.
The handful of security outcomes you are aiming at this year and how you will tell whether you hit them.
How security documents get written, approved, versioned and retired, and where the current copy lives.
What security training each group of staff gets, how often, and how you know they did it.
Who you tell what, and when — internally, and to regulators, customers and industry contacts.
How you check your own security controls before the certification body does, and the schedule for doing it.
What leadership looks at when they review security, how often, and what has to come out of the meeting.
What happens when something is found to be wrong: how it gets recorded, fixed at the root, and closed out.
How you keep track of the information and equipment you hold, who owns each item, how sensitive it is and how it is labelled.
The rules staff actually read: what you may do with company laptops, accounts and data, and what you may not.
Who gets access to what, how accounts are created and removed, and how admin rights are kept rare and reviewed.
How you check a supplier before you sign, what security terms go into the contract, and how you keep an eye on them afterwards.
What anyone should do when something looks wrong, who decides it is an incident, and how it gets handled and closed.
How the business keeps running, and how systems come back, when something significant breaks.
What gets backed up, how often, where copies live, and how you know a restore actually works.
The security parts of hiring, employment and leaving: checks before someone starts, what their contract says, and what happens on the last day.
The rules for working away from the office — home, travel, customer sites — and how company kit and data are protected there.
How your premises are protected: who gets in, how visitors are handled, and how equipment and utilities are looked after.
Where encryption is required, which algorithms are acceptable, and how keys are generated, stored and rotated.
How your networks are segmented and defended, and the rules for sending information in and out of the company.
How security gets built into software you write: design rules, coding standards, testing, and keeping environments apart.
How changes to systems get proposed, reviewed, tested and released, and who can approve an emergency one.
The baseline settings your systems are built to, and the written procedures for the operational tasks people repeat.
How you learn about new threats and weaknesses, how fast you patch them, and what protects your machines in the meantime.
What gets logged, how long logs are kept, who watches them, and what triggers a look.
How long you keep each kind of information, who decides, and how personal and sensitive data is protected and deleted.
The list of laws, regulations and contract clauses that bind your security, and who checks you still meet them.
Work that counts twice
ISO/IEC 27001:2022 overlaps with 8 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start ISO/IEC 27001:2022 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.