ISO · International16 requirements

ISO/IEC 27001:2022

The information security management standard. The management system clauses set the discipline, and Annex A supplies the control set you select from and justify.

Clause structure in CompStack
  • 4Context of the organization1
  • 5Leadership1
  • 6.1.2Information security risk assessment1
  • 6.1.3Information security risk treatment2
  • 9Performance evaluation1
  • 10Improvement2
  • A.5Organizational controls3
  • A.6People controls1
  • A.7Physical controls1
  • A.8Technological controls3
15 clauses total16 requirements
Who carries this

ISO 27001, in practice.

Information security, cybersecurity and privacy protection. Information security management systems. Requirements.

Organisations holding data somebody else cares about, usually driven by a customer requirement, a regulator, or the wish to answer security questionnaires once instead of forty times.

A note on the text

The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.

What the service does with it

Every month, on a schedule you can check.

This is the running work for this standard specifically. The general shape is the same across all of them.

We carry
  • Maintain the statement of applicability with a justification against every Annex A control
  • Keep the information security risk assessment and treatment plan on their review dates
  • Operate the selected controls on cadence and file the evidence against each
  • Run the internal audit programme and the management review
  • Carry nonconformities to verified closure
Evidence the assessor asks for
  • Statement of applicability with inclusion and exclusion reasoning
  • Risk assessment and risk treatment plan with owners
  • Access control, joiner and leaver records
  • Internal audit reports covering the management system clauses
  • Security incident records and their corrective actions

Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.

Walk it yourself

Name a clause in ISO 27001 and we will open it.

The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.