OnwynStandards › ISO/IEC 27001:2022

Certifiable standard · 2022

ISO/IEC 27001:2022

ISO/IEC 27001 is the international standard for running an information security management system (ISMS): a repeatable way of deciding what to protect, treating the risks, and proving it works. Companies pursue certification when customers, tenders, or regulators demand independent proof of security discipline. The standard has two parts: the management-system clauses 4-10 that everyone must implement, and Annex A, a catalogue of 93 controls you select from based on your risk assessment.

118
Requirements
11
Areas
32
Recommended documents
8
Mapped frameworks
Start ISO/IEC 27001:2022 free Have us do it instead

What this standard asks for

Every requirement in ISO/IEC 27001:2022, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Context of the organization

4 requirements

  • 4.1Understanding the organization and its context
  • 4.2Understanding the needs and expectations of interested parties
  • 4.3Determining the scope of the ISMS
  • 4.4Information security management system

Leadership

3 requirements

  • 5.1Leadership and commitment
  • 5.2Policy
  • 5.3Organizational roles, responsibilities and authorities

Planning

5 requirements

  • 6.1.1Actions to address risks and opportunities — general
  • 6.1.2Information security risk assessment
  • 6.1.3Information security risk treatment
  • 6.2Information security objectives and planning to achieve them
  • 6.3Planning of changes

Support

5 requirements

  • 7.1Resources
  • 7.2Competence
  • 7.3Awareness
  • 7.4Communication
  • 7.5Documented information

Operation

3 requirements

  • 8.1Operational planning and control
  • 8.2Information security risk assessment (performance)
  • 8.3Information security risk treatment (performance)

Performance evaluation

3 requirements

  • 9.1Monitoring, measurement, analysis and evaluation
  • 9.2Internal audit
  • 9.3Management review

Improvement

2 requirements

  • 10.1Continual improvement
  • 10.2Nonconformity and corrective action

Organizational controls (A.5)

37 requirements

  • A.5.1Policies for information security
  • A.5.2Information security roles and responsibilities
  • A.5.3Segregation of duties
  • A.5.4Management responsibilities
  • A.5.5Contact with authorities
  • A.5.6Contact with special interest groups
  • A.5.7Threat intelligence
  • A.5.8Information security in project management
  • A.5.9Inventory of information and other associated assets
  • A.5.10Acceptable use of information and other associated assets
  • A.5.11Return of assets
  • A.5.12Classification of information
  • A.5.13Labelling of information
  • A.5.14Information transfer
  • A.5.15Access control
  • A.5.16Identity management
  • A.5.17Authentication information
  • A.5.18Access rights
  • A.5.19Information security in supplier relationships
  • A.5.20Addressing information security within supplier agreements
  • A.5.21Managing information security in the ICT supply chain
  • A.5.22Monitoring, review and change management of supplier services
  • A.5.23Information security for use of cloud services
  • A.5.24Information security incident management planning and preparation
  • A.5.25Assessment and decision on information security events
  • A.5.26Response to information security incidents
  • A.5.27Learning from information security incidents
  • A.5.28Collection of evidence
  • A.5.29Information security during disruption
  • A.5.30ICT readiness for business continuity
  • A.5.31Legal, statutory, regulatory and contractual requirements
  • A.5.32Intellectual property rights
  • A.5.33Protection of records
  • A.5.34Privacy and protection of PII
  • A.5.35Independent review of information security
  • A.5.36Compliance with policies, rules and standards for information security
  • A.5.37Documented operating procedures

People controls (A.6)

8 requirements

  • A.6.1Screening
  • A.6.2Terms and conditions of employment
  • A.6.3Information security awareness, education and training
  • A.6.4Disciplinary process
  • A.6.5Responsibilities after termination or change of employment
  • A.6.6Confidentiality or non-disclosure agreements
  • A.6.7Remote working
  • A.6.8Information security event reporting

Physical controls (A.7)

14 requirements

  • A.7.1Physical security perimeters
  • A.7.2Physical entry
  • A.7.3Securing offices, rooms and facilities
  • A.7.4Physical security monitoring
  • A.7.5Protecting against physical and environmental threats
  • A.7.6Working in secure areas
  • A.7.7Clear desk and clear screen
  • A.7.8Equipment siting and protection
  • A.7.9Security of assets off-premises
  • A.7.10Storage media
  • A.7.11Supporting utilities
  • A.7.12Cabling security
  • A.7.13Equipment maintenance
  • A.7.14Secure disposal or re-use of equipment

Technological controls (A.8)

34 requirements

  • A.8.1User endpoint devices
  • A.8.2Privileged access rights
  • A.8.3Information access restriction
  • A.8.4Access to source code
  • A.8.5Secure authentication
  • A.8.6Capacity management
  • A.8.7Protection against malware
  • A.8.8Management of technical vulnerabilities
  • A.8.9Configuration management
  • A.8.10Information deletion
  • A.8.11Data masking
  • A.8.12Data leakage prevention
  • A.8.13Information backup
  • A.8.14Redundancy of information processing facilities
  • A.8.15Logging
  • A.8.16Monitoring activities
  • A.8.17Clock synchronization
  • A.8.18Use of privileged utility programs
  • A.8.19Installation of software on operational systems
  • A.8.20Networks security
  • A.8.21Security of network services
  • A.8.22Segregation of networks
  • A.8.23Web filtering
  • A.8.24Use of cryptography
  • A.8.25Secure development life cycle
  • A.8.26Application security requirements
  • A.8.27Secure system architecture and engineering principles
  • A.8.28Secure coding
  • A.8.29Security testing in development and acceptance
  • A.8.30Outsourced development
  • A.8.31Separation of development, test and production environments
  • A.8.32Change management
  • A.8.33Test information
  • A.8.34Protection of information systems during audit testing

The documents you will end up with

The recommended document set for ISO/IEC 27001:2022 — 32 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

ISMS Scope Statement

Says in plain words which parts of the business, which locations and which systems your security programme covers — and what is deliberately outside it.

Information Security Policy

The top-level statement of what the company commits to on security, signed by whoever is actually accountable.

Information Security Roles and Responsibilities

Names who owns security decisions, who runs day-to-day security work, and which duties must not sit with the same person.

Risk Assessment and Treatment Methodology

Explains how you find security risks, how you score them, and how you decide what to do about each one — so two people assessing the same risk land in the same place.

Statement of Applicability

Lists every Annex A control, whether you apply it, and why — the single page auditors open first.

Risk Treatment Plan

The working list of what you are actually going to do about each accepted risk, who owns it and by when.

Security Objectives and Measurement Plan

The handful of security outcomes you are aiming at this year and how you will tell whether you hit them.

Document and Record Control Procedure

How security documents get written, approved, versioned and retired, and where the current copy lives.

Security Awareness and Training Plan

What security training each group of staff gets, how often, and how you know they did it.

Security Communication Plan

Who you tell what, and when — internally, and to regulators, customers and industry contacts.

Internal Audit Procedure and Programme

How you check your own security controls before the certification body does, and the schedule for doing it.

Management Review Procedure

What leadership looks at when they review security, how often, and what has to come out of the meeting.

Nonconformity and Corrective Action Procedure

What happens when something is found to be wrong: how it gets recorded, fixed at the root, and closed out.

Asset Management and Classification Policy

How you keep track of the information and equipment you hold, who owns each item, how sensitive it is and how it is labelled.

Acceptable Use Policy

The rules staff actually read: what you may do with company laptops, accounts and data, and what you may not.

Access Control Policy

Who gets access to what, how accounts are created and removed, and how admin rights are kept rare and reviewed.

Supplier and Cloud Security Policy

How you check a supplier before you sign, what security terms go into the contract, and how you keep an eye on them afterwards.

Security Incident Management Procedure

What anyone should do when something looks wrong, who decides it is an incident, and how it gets handled and closed.

Business Continuity and ICT Recovery Plan

How the business keeps running, and how systems come back, when something significant breaks.

Backup Policy

What gets backed up, how often, where copies live, and how you know a restore actually works.

HR Security Policy

The security parts of hiring, employment and leaving: checks before someone starts, what their contract says, and what happens on the last day.

Remote and Mobile Working Policy

The rules for working away from the office — home, travel, customer sites — and how company kit and data are protected there.

Physical Security Policy

How your premises are protected: who gets in, how visitors are handled, and how equipment and utilities are looked after.

Cryptography Policy

Where encryption is required, which algorithms are acceptable, and how keys are generated, stored and rotated.

Network and Communications Security Policy

How your networks are segmented and defended, and the rules for sending information in and out of the company.

Secure Development Policy

How security gets built into software you write: design rules, coding standards, testing, and keeping environments apart.

Change Management Procedure

How changes to systems get proposed, reviewed, tested and released, and who can approve an emergency one.

Secure Configuration and Operating Procedures

The baseline settings your systems are built to, and the written procedures for the operational tasks people repeat.

Vulnerability and Malware Management Policy

How you learn about new threats and weaknesses, how fast you patch them, and what protects your machines in the meantime.

Logging and Monitoring Policy

What gets logged, how long logs are kept, who watches them, and what triggers a look.

Data Protection and Retention Policy

How long you keep each kind of information, who decides, and how personal and sensitive data is protected and deleted.

Legal and Compliance Register

The list of laws, regulations and contract clauses that bind your security, and who checks you still meet them.

Work that counts twice

ISO/IEC 27001:2022 overlaps with 8 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start ISO/IEC 27001:2022 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.