Clause 4.4 of ISO/IEC 27001:2022, Information security management system¶
The shortest clause in the standard, and the one that ties the rest together.
One sentence, four verbs, and a phrase everyone skips.
- Establish. Decide what the ISMS is: which processes, who runs them, what they produce.
- Implement. Actually run them. A documented ISMS is not an ISMS.
- Maintain. Keep it working as the organisation changes.
- Continually improve. Feed back what you learn, over more than one cycle.
- "...and their interactions." The skipped phrase. This is where most ISMSs are weakest.
Clauses 5 to 10 are the detail of that one sentence.
The phrase people skip¶
It is not enough to have a risk process and an incident process. You have to know how they connect.
- An incident should feed the risk assessment.
- The risk assessment should feed the treatment plan.
- The treatment plan should feed the objectives.
If an incident never reaches your risk register, you have processes but no system. That is a clause 4.4 finding.
What counts as a process¶
Name all four or you have an intention, not a process.
| Element | Answers |
|---|---|
| Inputs | What has to exist before this can start? |
| Activities | What happens, in what order? |
| Outputs | What comes out, and where does it go? |
| Owner | Who is accountable when it does not happen? |
The processes clause 4.4 implies¶
The standard gives no list. The requirements clauses do.
| Process | From | Feeds |
|---|---|---|
| Context and parties review | 4.1, 4.2 | Scope, risk assessment, management review |
| Scope management | 4.3 | Everything. It bounds the system |
| Risk assessment | 6.1.2, 8.2 | Risk treatment, objectives |
| Risk treatment and SoA | 6.1.3, 8.3 | Controls, objectives, audit scope |
| Objectives | 6.2 | Management review |
| Change planning | 6.3 | Risk assessment, document control |
| Competence and awareness | 7.2, 7.3 | Nearly every control |
| Documented information control | 7.5 | Everything that produces a record |
| Internal audit | 9.2 | Nonconformity, management review |
| Management review | 9.3 | Objectives, improvement, resourcing |
| Nonconformity and corrective action | 10.1 | Risk assessment, the ISMS itself |
How to do it¶
- List the processes. Start from the table above, add anything specific to you. One page.
- Give each an owner by name. A role is fine. A department is not, because departments do not attend meetings.
- Write down the interactions. Two columns: this produces X, that consumes X. The gaps you find are the real output.
- Draw it once. One page, processes and arrows. Not for the auditor, for the people running it.
- Decide how you will know it ran. A date, a record, a count. This is the difference between maintaining and hoping.
- Do not write an ISMS manual. The 2022 standard does not require one. A hundred-page manual is a maintenance liability nobody reads.
What good looks like¶
- Process list on one page, every process with a named owner.
- Interactions written down, not implied by an org chart.
- You can point at any process and show the last time it ran.
- Evidence of improvement across more than one cycle.
- The documented system and the real system are recognisably the same.
Common pitfalls¶
- An ISMS manual nobody reads. Not required. Write the process map instead.
- Established but not implemented. Beautiful procedures, no records. The most common first-certification finding.
- Processes with no interactions. Each works, nothing connects, and an incident never reaches the risk register.
- Improvement only before an audit. "Continual" means over time, not in the fortnight before the auditor arrives.
- Owners who are departments. Accountability belonging to everyone belongs to no one.
Documents this clause should produce¶
| Document | For | Mandatory? | Format |
|---|---|---|---|
| ISMS process map | Processes, owners, interactions | Recommended. The most useful page in the ISMS | One page: a table plus a simple diagram |
| Process interaction table | Inputs and outputs, what feeds what | Recommended | Two columns, one row per handoff |
| Process owner register | Who is accountable, by name | Recommended | Can be a column in the process map |
The 2022 standard does not require an ISMS manual or a documented description of the ISMS as such. Documented information is specified clause by clause; 7.5.1 b leaves the rest to you.
Linked documents¶
| Document | How it depends on 4.4 |
|---|---|
| Context (4.1), parties register (4.2) | Inputs to establish, and reviewed to maintain |
| Scope statement (4.3) | Bounds which processes are in the ISMS at all |
| Risk assessment and treatment (6.1) | The two processes with the most interactions |
| Documented information (7.5) | How the ISMS is maintained rather than eroded |
| Internal audit (9.2), management review (9.3) | The two processes that check it is still a system |
| Improvement (10.1, 10.2) | The fourth verb, made operational |
Key definitions¶
| Term | Meaning here |
|---|---|
| Management system | Interrelated elements that set policy and objectives, and processes to achieve them |
| Process | Activities turning inputs into outputs. Has an owner |
| Interaction | The handoff. Where one process's output is another's input |
| Continual improvement | Recurring activity to improve performance. Recurring is the operative word |
Primary sources¶
- ISO/IEC 27001:2022 : Clause 4.4
- ISO/IEC 27000:2018 : Definitions of management system, process and continual improvement
Verify before you rely on it
A working interpretation of ISO/IEC 27001:2022 clause 4.4, written for practitioners. The standard is the only authoritative source. Check the current text before relying on any wording in an audit or filing.
Part of Clause 4, Context of the organisation, which shows how 4.4 depends on the other three. The working files are in the implementation kit.