ISO/IEC 27001¶

ISO/IEC 27001:2022 is the management-system standard the rest of this library keeps pointing at. DORA, NIS2 and most customer security questionnaires either name it or assume it. Clauses 4 to 10 are the requirements you are audited against; Annex A is the 93 controls you have to consider and justify.
Two things live here: a complete implementation kit you can download and run with, and a clause-by-clause working interpretation.
Start here¶
| What it is | |
|---|---|
| Implementation Kit | Seventeen documents and a 27-tab workbook that take an organisation from nothing to certified. Every Clause 4-10 requirement and all 93 Annex A controls as its own row, with an owner, a status and an evidence pointer. Free download |
| Clause 4, Context of the organisation | The four subclauses that decide the ISMS before any control is chosen, and the terminology traps in Clauses 1 to 3 |
Clause 4, subclause by subclause¶
| Subclause | The one artefact it has to produce |
|---|---|
| 4.1 Context | A context picture. One or two pages, dated |
| 4.2 Interested parties | A register. Every requirement marked binding, adopted or noted |
| 4.3 Scope | A scope statement, signed off, with exclusions justified |
| 4.4 The ISMS | A process map. Owners named, interactions drawn |
More clauses will follow. Clause 6.1.2 and 6.1.3, the risk work, are next.
The 2022 text is not the current text
ISO/IEC 27001:2022/Amd 1:2024, "Climate action changes", published February 2024, amends Clauses 4.1 and 4.2. It is one page and free from ISO: ISO/IEC 27001:2022/Amd 1:2024. Anyone working from a 2022 PDF alone is working from an incomplete Clause 4.
Primary sources¶
- ISO/IEC 27001:2022 — Information security management systems, requirements
- ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes. Free, one page
- ISO/IEC 27000:2018 — the single normative reference, and the source of every defined term
- ISO Online Browsing Platform — the maintained terminology database
Verify before you rely on it
A working interpretation written for practitioners. The standard is the only authoritative source. Check the current text before relying on any wording in an audit or a filing.