ISO 27001

The ISO/IEC 27001:2022 cheat sheet covers the ISMS structure (clauses 4-10), Annex A controls, PDCA cycle, certification process, and relationships with ISO 27002 and ISO 27005.

#Overview

#ISO 27001 at a Glance

Aspect Detail
Standard ISO/IEC 27001:2022
Full title Information security, cybersecurity and privacy protection - ISMS requirements
Purpose Requirements for establishing, implementing, maintaining, and continually improving an ISMS
Previous version ISO/IEC 27001:2013 (+ Cor 1:2014, Cor 2:2015)
Transition deadline 2025-10-31 (all 2013 certificates expire)
Annex A controls 93 controls in 4 themes (2022) vs 114 in 14 domains (2013)
New controls (2022) 11 new, 24 merged, 58 revised
Related standards ISO 27002, 27005, 27017, 27018, 27701
Certification body Accredited 3rd-party CB (audit stages 1+2)
Certificate validity 3 years + annual surveillance audits

#PDCA Cycle (ISMS)

PDCA Cycle - ISO 27001 ISMS

Click a phase for details. Click the center for an overview of all phases.

PLAN Cl. 4-7 DO Cl. 8 CHECK Cl. 9 ACT Cl. 10 ISMS ISO 27001
OVERVIEW

#Clauses 4-10

#Normative Clauses Overview

Clause Title Key Requirement
4 Context of the Organization Scope, internal/external issues, interested parties, legal requirements
5 Leadership Management commitment, ISMS policy, roles and responsibilities
6 Planning Risk assessment (6.1.2), risk treatment (6.1.3), SoA, objectives (6.2), planning of changes (6.3)
7 Support Resources, competence, awareness, communication, documented information
8 Operation Implement risk treatment, control operational processes, manage changes
9 Performance Evaluation Internal audit program, management review, KPI monitoring
10 Improvement Nonconformities, corrective actions, continual improvement

#Clause 6 - Planning (Key Deliverables)

6.1.1 General:
  - Determine risks and opportunities considering context (clause 4) issues
  - Plan actions to address those risks and opportunities
  - Plan how to integrate actions into ISMS processes and evaluate effectiveness

6.1.2 Risk Assessment:
  - Documented risk assessment methodology (criteria, scope, process)
  - Risk identification: assets x threats x vulnerabilities x existing controls
  - Risk criteria: likelihood x impact scale (defined by organization)
  - Risk acceptance threshold (approved by management)
  - Risk owner assigned per risk
  - Consistent, valid, and comparable results required

6.1.3 Risk Treatment:
  - Select appropriate treatment options: Modify, Avoid, Share, Retain
  - Determine ALL controls necessary (not limited to Annex A)
  - Compare controls with Annex A to verify nothing overlooked
  - Statement of Applicability (SoA): all 93 controls with justification
  - Risk treatment plan: owner + deadline + budget per control
  - Risk owners must approve the RTP and accept residual risks

6.2 Information Security Objectives:
  - Measurable, time-bound security objectives
  - Consistent with IS policy
  - Linked to risk treatment results
  - Communicated across the organization
  - Monitored, updated, and documented

6.3 Planning of Changes (new in 2022 text):
  - Changes to ISMS must be carried out in a planned manner

#Clause 8 - Operation

8.1 Operational Planning and Control:
  - Plan, implement, and control processes to meet IS requirements
  - Implement actions from clause 6 (risk treatment, objectives)
  - Control planned changes and review unintended changes
  - Control outsourced processes

8.2 Information Security Risk Assessment:
  - Perform risk assessment at planned intervals
  - Perform risk assessment when significant changes occur
  - Retain documented evidence of results

8.3 Information Security Risk Treatment:
  - Implement the risk treatment plan
  - Retain documented evidence of treatment results

#Clause 9 - Audits & Review

9.1 Monitoring, Measurement, Analysis, and Evaluation:
  - Define what needs to be monitored and measured (including IS processes and controls)
  - Define methods, frequency, and responsibilities
  - KPIs: patch rate, # incidents, phishing simulation pass rate, audit findings
  - Analyze and evaluate results at planned intervals

9.2 Internal Audit:
  - Planned audit program considering importance of processes and previous audits
  - Cover ALL clauses + ALL Annex A controls over the audit cycle
  - Auditors must be objective and impartial (no self-audit)
  - Audit criteria, scope, frequency, and methods defined
  - Audit report with nonconformities + corrective action tracking

9.3 Management Review (inputs required by the standard):
  a) Status of previous management review actions
  b) Changes in external/internal issues relevant to ISMS
  c) Changes in needs and expectations of interested parties
  d) Feedback on IS performance: nonconformities, monitoring results, audit results, objective fulfillment
  e) Feedback from interested parties
  f) Results of risk assessment and risk treatment plan status
  g) Opportunities for continual improvement

9.3 Management Review (outputs):
  - Decisions on continual improvement opportunities
  - Decisions on changes needed to the ISMS
  - Resource needs

#Annex A Controls (ISO 27001:2022)

#Control Themes Overview

Theme Count Scope
A.5 Organizational 37 Policies, roles, asset mgmt, supplier relations, cloud, incident mgmt, BCP
A.6 People 8 Screening, T&Cs, training, disciplinary, termination, NDA, remote work
A.7 Physical 14 Perimeters, entry control, monitoring, clean desk, disposal, cabling
A.8 Technological 34 Access control, crypto, malware, logging, vuln mgmt, secure coding, network

#A.5 Organizational Controls (37)

Control Title Brief Description
A.5.1 Policies for Information Security Define, approve and publish IS policies
A.5.2 IS Roles and Responsibilities Assign and communicate security responsibilities
A.5.3 Segregation of Duties Separate conflicting duties to prevent fraud
A.5.4 Management Responsibilities Management enforces IS policies
A.5.5 Contact with Authorities Maintain contacts with regulators and law enforcement
A.5.6 Contact with Special Interest Groups Stay current via ISACs, CERTs, industry groups
A.5.7 Threat Intelligence Collect and analyze threat intel (NEW in 2022)
A.5.8 IS in Project Management Embed security into project lifecycle
A.5.9 Inventory of Information and Assets Maintain asset inventory with owners
A.5.10 Acceptable Use of Information and Assets Define acceptable use rules
A.5.11 Return of Assets Enforce asset return on termination
A.5.12 Classification of Information Define classification scheme (e.g., Public/Internal/Confidential/Secret)
A.5.13 Labelling of Information Apply labels per classification scheme
A.5.14 Information Transfer Policies for transfer via email, USB, cloud
A.5.15 Access Control Establish access control policy (RBAC, least privilege)
A.5.16 Identity Management Manage full identity lifecycle
A.5.17 Authentication Information Manage passwords, tokens, keys securely
A.5.18 Access Rights Grant, review, revoke access rights
A.5.19 IS in Supplier Relationships Define IS requirements for suppliers
A.5.20 IS within Supplier Agreements Contractual IS clauses
A.5.21 IS in ICT Supply Chain Manage risks in software/hardware supply chain
A.5.22 Monitoring and Review of Supplier Services Audit supplier security performance
A.5.23 IS for Use of Cloud Services Cloud-specific IS controls (NEW in 2022)
A.5.24 IS Incident Mgmt Planning Prepare incident response plans
A.5.25 Assessment of IS Events Classify and triage security events
A.5.26 Response to IS Incidents Contain, eradicate, recover from incidents
A.5.27 Learning from IS Incidents Post-incident review, lessons learned
A.5.28 Collection of Evidence Forensic-ready evidence handling
A.5.29 IS During Disruption Maintain security during BCP activation
A.5.30 ICT Readiness for Business Continuity ICT continuity planning (NEW in 2022)
A.5.31 Legal, Statutory, Regulatory Requirements Identify and comply with legal obligations
A.5.32 Intellectual Property Rights Protect IPR (software licenses, patents)
A.5.33 Protection of Records Manage records per retention requirements
A.5.34 Privacy and Protection of PII GDPR / privacy controls for PII
A.5.35 Independent Review of IS Periodic independent IS reviews
A.5.36 Compliance with IS Policies Monitor and enforce policy compliance
A.5.37 Documented Operating Procedures Maintain operating procedures for IS activities

#A.6 People Controls (8)

Control Title Brief Description
A.6.1 Screening Background checks before employment
A.6.2 Terms and Conditions of Employment IS responsibilities in employment contracts
A.6.3 IS Awareness, Education and Training Regular IS training and awareness programs
A.6.4 Disciplinary Process Formal process for IS policy violations
A.6.5 Responsibilities After Termination IS obligations after leaving the organization
A.6.6 Confidentiality / NDA Agreements NDAs for personnel and contractors
A.6.7 Remote Working Security controls for remote/home working
A.6.8 IS Event Reporting Enable staff to report IS events and weaknesses

#A.7 Physical Controls (14)

Control Title Brief Description
A.7.1 Physical Security Perimeters Define secure zones (fences, doors, card access)
A.7.2 Physical Entry Control and log physical access
A.7.3 Securing Offices, Rooms, Facilities Lock and protect work areas
A.7.4 Physical Security Monitoring CCTV, intrusion detection in secure areas (NEW in 2022)
A.7.5 Protecting Against Physical/Environmental Threats Fire, flood, power failure controls
A.7.6 Working in Secure Areas Restrict and control secure area access
A.7.7 Clear Desk and Clear Screen No sensitive info left unattended
A.7.8 Equipment Siting and Protection Protect hardware from environmental damage
A.7.9 Security of Assets Off-Premises Controls for laptops, phones outside office
A.7.10 Storage Media Secure handling, transport, disposal of media
A.7.11 Supporting Utilities UPS, generators, cooling for datacenters
A.7.12 Cabling Security Protect network and power cabling
A.7.13 Equipment Maintenance Schedule and log hardware maintenance
A.7.14 Secure Disposal or Re-Use of Equipment Wipe / destroy before disposal

#A.8 Technological Controls (34)

Control Title Brief Description
A.8.1 User Endpoint Devices Policies for laptops, phones, BYOD
A.8.2 Privileged Access Rights Restrict, review, and log privileged accounts (PAM)
A.8.3 Information Access Restriction Enforce need-to-know data access
A.8.4 Access to Source Code Protect source code repositories
A.8.5 Secure Authentication MFA, password policies, SSO
A.8.6 Capacity Management Monitor and plan resource capacity
A.8.7 Protection Against Malware EDR, AV, email filtering, sandboxing
A.8.8 Management of Technical Vulnerabilities Patching, vuln scanning, prioritization
A.8.9 Configuration Management Hardening baselines, CIS benchmarks (NEW in 2022)
A.8.10 Information Deletion Secure deletion of data per retention policy (NEW in 2022)
A.8.11 Data Masking Pseudonymization, anonymization, tokenization (NEW in 2022)
A.8.12 Data Leakage Prevention DLP tools and controls (NEW in 2022)
A.8.13 Information Backup Backup policies, testing, offsite/immutable
A.8.14 Redundancy of Information Processing HA, failover, geographic redundancy
A.8.15 Logging Audit logs, retention periods, SIEM
A.8.16 Monitoring Activities Anomaly detection, SOC, behavioral analytics (NEW in 2022)
A.8.17 Clock Synchronization NTP time sync for log correlation
A.8.18 Use of Privileged Utility Programs Control admin tools (sysinternals, etc.)
A.8.19 Installation of Software on Operational Systems Software allowlisting, deployment control
A.8.20 Networks Security Segmentation, firewall rules, DMZ
A.8.21 Security of Network Services Secure network service agreements
A.8.22 Segregation of Networks VLAN, micro-segmentation, Zero Trust
A.8.23 Web Filtering Content filtering, DNS filtering, proxy (NEW in 2022)
A.8.24 Use of Cryptography Crypto policies, key management
A.8.25 Secure Development Life Cycle Security requirements in SDLC
A.8.26 Application Security Requirements Secure design, threat modeling
A.8.27 Secure System Architecture and Engineering Security-by-design principles
A.8.28 Secure Coding SAST, DAST, code review standards (NEW in 2022)
A.8.29 Security Testing in Dev and Acceptance Pentest, vuln assessment in pipeline
A.8.30 Outsourced Development Security requirements for third-party dev
A.8.31 Separation of Dev/Test/Production Isolate environments
A.8.32 Change Management Formal change control process
A.8.33 Test Information Protect production data used in tests
A.8.34 Protection of IS During Audit Testing Isolate and scope audit access

#2013 vs 2022 Comparison

#Structural Changes

Dimension ISO 27001:2013 ISO 27001:2022
Total controls 114 93
Themes / Annexes 14 clauses (A.5-A.18) 4 themes (A.5-A.8)
New controls - 11 new controls
Merged controls - 24 controls merged
Revised controls - 58 controls updated
Attributes None 5 attribute types per control
Clause 6.1.3 SoA required SoA required (no change)
Clause 6.3 N/A Planning of changes (new subclause)

#11 New Controls Added in 2022

Control Title Theme
A.5.7 Threat Intelligence Organizational
A.5.23 Information Security for Use of Cloud Services Organizational
A.5.30 ICT Readiness for Business Continuity Organizational
A.7.4 Physical Security Monitoring Physical
A.8.9 Configuration Management Technological
A.8.10 Information Deletion Technological
A.8.11 Data Masking Technological
A.8.12 Data Leakage Prevention Technological
A.8.16 Monitoring Activities Technological
A.8.23 Web Filtering Technological
A.8.28 Secure Coding Technological

#Control Attributes (New in 2022)

Each of the 93 controls now carries 5 attribute types to aid categorization:

Attribute Values (examples)
Control type Preventive / Detective / Corrective
IS properties Confidentiality / Integrity / Availability
Cybersecurity concepts Identify / Protect / Detect / Respond / Recover
Operational capabilities Governance, Asset mgmt, IAM, Threat intel, etc.
Security domains Governance, Protection, Defence, Resilience

#Statement of Applicability (SoA)

#SoA Structure and Purpose

The SoA is a mandatory document (clause 6.1.3) that maps each of the 93 Annex A controls to the organization's risk treatment decisions.

For each of the 93 controls, document:
  - Applicable: Yes / No
  - Justification for inclusion: which risk(s) justify this control
  - Justification for exclusion: why this control is not needed (if excluded)
  - Implementation status: Not started / Planned / Partial / Implemented / Verified
  - Reference to implementing document (policy, procedure, technical config)

Example SoA rows:
  A.8.5  | Secure Authentication    | YES | Risk R-042: credential theft     | Implemented | POL-IAM-007
  A.8.11 | Data Masking             | YES | Risk R-018: PII exposure in test  | Partial     | PROC-DEV-012
  A.7.4  | Physical Security Mon.   | NO  | Out of scope: no on-prem DC       | N/A         | -

#Risk Assessment Process

#Likelihood x Impact Matrix

           Impact
           1-Low  2-Med  3-High  4-Crit
          +------+------+-------+------+
  4-VHigh |  Med | High |  High | Crit |
  3-High  |  Low |  Med |  High | High |
  2-Med   |  Low |  Low |   Med |  Med |
  1-Low   |  Low |  Low |   Low |  Low |
          +------+------+-------+------+
Likelihood

Risk level -> treatment decision (per 6.1.3):
  Critical/High  : Modify (implement controls) or Avoid (stop activity)
  Medium         : Modify (implement controls) or Share (transfer to 3rd party)
  Low            : Retain (accept) or Monitor

#Risk Assessment Steps

Step Activity Output
1 Define methodology and criteria Risk assessment methodology doc
2 Identify assets in scope Asset inventory with owners
3 Identify threats and vulnerabilities Threat/vuln register
4 Assess existing controls Control effectiveness rating
5 Determine likelihood (1-4) Per risk entry
6 Determine impact (1-4) Per risk entry per CIA property
7 Calculate risk level Risk register with ratings
8 Compare to risk acceptance threshold Risks to treat vs. accept
9 Select Annex A controls SoA draft
10 Define risk treatment plan RTP with owners and deadlines

#Certification Process

#Certification Roadmap

Step Phase Description
1 Gap analysis Compare current state vs ISO 27001 requirements, identify gaps
2 Define ISMS scope Which assets, processes, locations, and services are in scope (4.3)
3 Risk assessment Identify and evaluate risks to in-scope assets (ISO 27005 / EBIOS RM)
4 Risk treatment Select Annex A controls, justify exclusions, build SoA
5 Implement controls Deploy policies, procedures, technical measures
6 Awareness and training All staff trained on ISMS policies and their responsibilities
7 Internal audit Independent audit verifying all clauses and Annex A controls
8 Management review Formal ISMS review by top management with defined inputs
9 Stage 1 audit CB reviews documentation, scope, and ISMS readiness
10 Stage 2 audit CB verifies implementation on-site; issues nonconformities
11 Close nonconformities Remediate major/minor NCs before certificate issued
12 Certification Certificate issued (valid 3 years)
13 Surveillance audits Annual audit to verify ISMS is maintained and improved
14 Recertification Full audit every 3 years

#Key Mandatory Documents

Document Clause Purpose
ISMS Scope document 4.3 Defines what is covered
Information security policy 5.2 Top-level policy signed by management
Risk assessment methodology 6.1.2 Documented process for risk identification
Risk register 6.1.2 All identified risks with ratings and owners
Statement of Applicability (SoA) 6.1.3 Links risks to all 93 Annex A controls
Risk treatment plan 6.1.3 Remediation plan with owners and deadlines
Security objectives 6.2 Measurable IS goals
Competence records 7.2 Training and qualification evidence
Operational control procedures 8.1 Procedures for key IS processes
Internal audit program + reports 9.2 Audit schedule and findings
Management review minutes 9.3 Formal review records
Nonconformity + corrective action records 10.1 NC tracking and closure

#Standards Family and Integration

Standard Title Relationship to ISO 27001
ISO 27001:2022 ISMS Requirements Certifiable - the main standard
ISO 27002:2022 Controls Guidance Guidance on implementing each Annex A control (not certifiable)
ISO 27005:2022 Risk Management Risk assessment methodology aligned with 27001 clause 6
ISO 27017:2015 Cloud Security Extra controls for cloud service providers and customers
ISO 27018:2019 Cloud PII Privacy controls in public cloud (GDPR alignment)
ISO 27701:2019 Privacy (PIMS) Extension of 27001 scope to cover privacy management
ISO 27035:2023 Incident Management Incident response process (feeds A.5.24-5.28)
NIST CSF 2.0 Cyber Framework Identify/Protect/Detect/Respond/Recover aligns with Annex A themes
EBIOS RM Risk Method (ANSSI) French risk methodology, ISO 27005 aligned, feeds clause 6 directly

#Also See

#Cyber Aurelien Guidi

  • EBIOS RM (ANSSI risk management methodology, ISO 27005 aligned)
  • PCI-DSS (Payment card industry compliance)
  • Wazuh (Open source SIEM/XDR - supports A.8.15/A.8.16)
  • MITRE ATT&CK (Adversary TTPs - supports A.5.7 threat intelligence)
  • Sigma (Detection rules - supports A.8.16 monitoring activities)