Skip to content

ISO/IEC 27001

Miniature institution with a glass annex, cutaway to show the management system inside

ISO/IEC 27001:2022 is the management-system standard the rest of this library keeps pointing at. DORA, NIS2 and most customer security questionnaires either name it or assume it. Clauses 4 to 10 are the requirements you are audited against; Annex A is the 93 controls you have to consider and justify.

Two things live here: a complete implementation kit you can download and run with, and a clause-by-clause working interpretation.

Start here

What it is
Implementation Kit Seventeen documents and a 27-tab workbook that take an organisation from nothing to certified. Every Clause 4-10 requirement and all 93 Annex A controls as its own row, with an owner, a status and an evidence pointer. Free download
Clause 4, Context of the organisation The four subclauses that decide the ISMS before any control is chosen, and the terminology traps in Clauses 1 to 3

Clause 4, subclause by subclause

Subclause The one artefact it has to produce
4.1 Context A context picture. One or two pages, dated
4.2 Interested parties A register. Every requirement marked binding, adopted or noted
4.3 Scope A scope statement, signed off, with exclusions justified
4.4 The ISMS A process map. Owners named, interactions drawn

More clauses will follow. Clause 6.1.2 and 6.1.3, the risk work, are next.

The 2022 text is not the current text

ISO/IEC 27001:2022/Amd 1:2024, "Climate action changes", published February 2024, amends Clauses 4.1 and 4.2. It is one page and free from ISO: ISO/IEC 27001:2022/Amd 1:2024. Anyone working from a 2022 PDF alone is working from an incomplete Clause 4.

Primary sources

Verify before you rely on it

A working interpretation written for practitioners. The standard is the only authoritative source. Check the current text before relying on any wording in an audit or a filing.