Skip to content

Clause 4.4 of ISO/IEC 27001:2022, Information security management system

The shortest clause in the standard, and the one that ties the rest together.

One sentence, four verbs, and a phrase everyone skips.

  • Establish. Decide what the ISMS is: which processes, who runs them, what they produce.
  • Implement. Actually run them. A documented ISMS is not an ISMS.
  • Maintain. Keep it working as the organisation changes.
  • Continually improve. Feed back what you learn, over more than one cycle.
  • "...and their interactions." The skipped phrase. This is where most ISMSs are weakest.
Establish, implement, maintain, continually improve A four-stage cycle showing what clause 4.4 requires. Establish means decide the processes the ISMS needs and how they connect. Implement means actually run them, so that the documented system and the real one are the same thing. Maintain means keep them working as the organisation changes, through document control, audits and management review. Continually improve means feed what you learn back in, through nonconformities, corrective action and objectives. The fourth stage returns to the first, because the cycle repeats for the life of the ISMS. 1 Establish Decide the processes the ISMS needs, and how they interact. Clauses 4 to 10 are the list. 2 Implement Actually run them. The written system and the real one have to be the same system. 3 Maintain Keep them working as the organisation changes. Document control, audit, review. 4 Continually improve Feed back what you learn. Nonconformities, corrective action, objectives. Then repeat. Establish, implement, maintain, continually improve A four-stage cycle showing what clause 4.4 requires. Establish means decide the processes the ISMS needs and how they connect. Implement means actually run them, so that the documented system and the real one are the same thing. Maintain means keep them working as the organisation changes, through document control, audits and management review. Continually improve means feed what you learn back in, through nonconformities, corrective action and objectives. The fourth stage returns to the first, because the cycle repeats for the life of the ISMS. 1 Establish Decide the processes the ISMS needs, and how they interact. Clauses 4 to 10 are the list. 2 Implement Actually run them. The written system and the real one have to be the same system. 3 Maintain Keep them working as the organisation changes. Document control, audit, review. 4 Continually improve Feed back what you learn. Nonconformities, corrective action, objectives. Then repeat.

Clauses 5 to 10 are the detail of that one sentence.

The phrase people skip

It is not enough to have a risk process and an incident process. You have to know how they connect.

  • An incident should feed the risk assessment.
  • The risk assessment should feed the treatment plan.
  • The treatment plan should feed the objectives.

If an incident never reaches your risk register, you have processes but no system. That is a clause 4.4 finding.

What counts as a process

Name all four or you have an intention, not a process.

Element Answers
Inputs What has to exist before this can start?
Activities What happens, in what order?
Outputs What comes out, and where does it go?
Owner Who is accountable when it does not happen?

The processes clause 4.4 implies

The standard gives no list. The requirements clauses do.

Process From Feeds
Context and parties review 4.1, 4.2 Scope, risk assessment, management review
Scope management 4.3 Everything. It bounds the system
Risk assessment 6.1.2, 8.2 Risk treatment, objectives
Risk treatment and SoA 6.1.3, 8.3 Controls, objectives, audit scope
Objectives 6.2 Management review
Change planning 6.3 Risk assessment, document control
Competence and awareness 7.2, 7.3 Nearly every control
Documented information control 7.5 Everything that produces a record
Internal audit 9.2 Nonconformity, management review
Management review 9.3 Objectives, improvement, resourcing
Nonconformity and corrective action 10.1 Risk assessment, the ISMS itself

How to do it

  1. List the processes. Start from the table above, add anything specific to you. One page.
  2. Give each an owner by name. A role is fine. A department is not, because departments do not attend meetings.
  3. Write down the interactions. Two columns: this produces X, that consumes X. The gaps you find are the real output.
  4. Draw it once. One page, processes and arrows. Not for the auditor, for the people running it.
  5. Decide how you will know it ran. A date, a record, a count. This is the difference between maintaining and hoping.
  6. Do not write an ISMS manual. The 2022 standard does not require one. A hundred-page manual is a maintenance liability nobody reads.

What good looks like

  • Process list on one page, every process with a named owner.
  • Interactions written down, not implied by an org chart.
  • You can point at any process and show the last time it ran.
  • Evidence of improvement across more than one cycle.
  • The documented system and the real system are recognisably the same.

Common pitfalls

  • An ISMS manual nobody reads. Not required. Write the process map instead.
  • Established but not implemented. Beautiful procedures, no records. The most common first-certification finding.
  • Processes with no interactions. Each works, nothing connects, and an incident never reaches the risk register.
  • Improvement only before an audit. "Continual" means over time, not in the fortnight before the auditor arrives.
  • Owners who are departments. Accountability belonging to everyone belongs to no one.

Documents this clause should produce

Document For Mandatory? Format
ISMS process map Processes, owners, interactions Recommended. The most useful page in the ISMS One page: a table plus a simple diagram
Process interaction table Inputs and outputs, what feeds what Recommended Two columns, one row per handoff
Process owner register Who is accountable, by name Recommended Can be a column in the process map

The 2022 standard does not require an ISMS manual or a documented description of the ISMS as such. Documented information is specified clause by clause; 7.5.1 b leaves the rest to you.

Linked documents

Document How it depends on 4.4
Context (4.1), parties register (4.2) Inputs to establish, and reviewed to maintain
Scope statement (4.3) Bounds which processes are in the ISMS at all
Risk assessment and treatment (6.1) The two processes with the most interactions
Documented information (7.5) How the ISMS is maintained rather than eroded
Internal audit (9.2), management review (9.3) The two processes that check it is still a system
Improvement (10.1, 10.2) The fourth verb, made operational

Key definitions

Term Meaning here
Management system Interrelated elements that set policy and objectives, and processes to achieve them
Process Activities turning inputs into outputs. Has an owner
Interaction The handoff. Where one process's output is another's input
Continual improvement Recurring activity to improve performance. Recurring is the operative word

Primary sources

Verify before you rely on it

A working interpretation of ISO/IEC 27001:2022 clause 4.4, written for practitioners. The standard is the only authoritative source. Check the current text before relying on any wording in an audit or filing.


Part of Clause 4, Context of the organisation, which shows how 4.4 depends on the other three. The working files are in the implementation kit.