The ISO/IEC 27001:2022 cheat sheet covers the ISMS structure (clauses 4-10), Annex A controls, PDCA cycle, certification process, and relationships with ISO 27002 and ISO 27005.
| Aspect | Detail |
|---|---|
| Standard | ISO/IEC 27001:2022 |
| Full title | Information security, cybersecurity and privacy protection - ISMS requirements |
| Purpose | |
| Previous version | ISO/IEC 27001:2013 (+ Cor 1:2014, Cor 2:2015) |
| Transition deadline | |
| Annex A controls | |
| New controls (2022) | 11 new, 24 merged, 58 revised |
| Related standards | ISO 27002, 27005, 27017, 27018, 27701 |
| Certification body | Accredited 3rd-party CB (audit stages 1+2) |
| Certificate validity | 3 years + annual surveillance audits |
| Clause | Title | Key Requirement |
|---|---|---|
| 4 | Context of the Organization | |
| 5 | Leadership | Management commitment, ISMS policy, roles and responsibilities |
| 6 | Planning | |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | |
| 9 | Performance Evaluation | Internal audit program, management review, KPI monitoring |
| 10 | Improvement |
6.1.1 General:
- Determine risks and opportunities considering context (clause 4) issues
- Plan actions to address those risks and opportunities
- Plan how to integrate actions into ISMS processes and evaluate effectiveness
6.1.2 Risk Assessment:
- Documented risk assessment methodology (criteria, scope, process)
- Risk identification: assets x threats x vulnerabilities x existing controls
- Risk criteria: likelihood x impact scale (defined by organization)
- Risk acceptance threshold (approved by management)
- Risk owner assigned per risk
- Consistent, valid, and comparable results required
6.1.3 Risk Treatment:
- Select appropriate treatment options: Modify, Avoid, Share, Retain
- Determine ALL controls necessary (not limited to Annex A)
- Compare controls with Annex A to verify nothing overlooked
- Statement of Applicability (SoA): all 93 controls with justification
- Risk treatment plan: owner + deadline + budget per control
- Risk owners must approve the RTP and accept residual risks
6.2 Information Security Objectives:
- Measurable, time-bound security objectives
- Consistent with IS policy
- Linked to risk treatment results
- Communicated across the organization
- Monitored, updated, and documented
6.3 Planning of Changes (new in 2022 text):
- Changes to ISMS must be carried out in a planned manner
8.1 Operational Planning and Control:
- Plan, implement, and control processes to meet IS requirements
- Implement actions from clause 6 (risk treatment, objectives)
- Control planned changes and review unintended changes
- Control outsourced processes
8.2 Information Security Risk Assessment:
- Perform risk assessment at planned intervals
- Perform risk assessment when significant changes occur
- Retain documented evidence of results
8.3 Information Security Risk Treatment:
- Implement the risk treatment plan
- Retain documented evidence of treatment results
9.1 Monitoring, Measurement, Analysis, and Evaluation:
- Define what needs to be monitored and measured (including IS processes and controls)
- Define methods, frequency, and responsibilities
- KPIs: patch rate, # incidents, phishing simulation pass rate, audit findings
- Analyze and evaluate results at planned intervals
9.2 Internal Audit:
- Planned audit program considering importance of processes and previous audits
- Cover ALL clauses + ALL Annex A controls over the audit cycle
- Auditors must be objective and impartial (no self-audit)
- Audit criteria, scope, frequency, and methods defined
- Audit report with nonconformities + corrective action tracking
9.3 Management Review (inputs required by the standard):
a) Status of previous management review actions
b) Changes in external/internal issues relevant to ISMS
c) Changes in needs and expectations of interested parties
d) Feedback on IS performance: nonconformities, monitoring results, audit results, objective fulfillment
e) Feedback from interested parties
f) Results of risk assessment and risk treatment plan status
g) Opportunities for continual improvement
9.3 Management Review (outputs):
- Decisions on continual improvement opportunities
- Decisions on changes needed to the ISMS
- Resource needs
| Theme | Count | Scope |
|---|---|---|
| A.5 Organizational | Policies, roles, asset mgmt, supplier relations, cloud, incident mgmt, BCP | |
| A.6 People | Screening, T&Cs, training, disciplinary, termination, NDA, remote work | |
| A.7 Physical | Perimeters, entry control, monitoring, clean desk, disposal, cabling | |
| A.8 Technological | Access control, crypto, malware, logging, vuln mgmt, secure coding, network |
| Control | Title | Brief Description |
|---|---|---|
| A.5.1 | Policies for Information Security | Define, approve and publish IS policies |
| A.5.2 | IS Roles and Responsibilities | Assign and communicate security responsibilities |
| A.5.3 | Segregation of Duties | Separate conflicting duties to prevent fraud |
| A.5.4 | Management Responsibilities | Management enforces IS policies |
| A.5.5 | Contact with Authorities | Maintain contacts with regulators and law enforcement |
| A.5.6 | Contact with Special Interest Groups | Stay current via ISACs, CERTs, industry groups |
| Threat Intelligence | ||
| A.5.8 | IS in Project Management | Embed security into project lifecycle |
| A.5.9 | Inventory of Information and Assets | Maintain asset inventory with owners |
| A.5.10 | Acceptable Use of Information and Assets | Define acceptable use rules |
| A.5.11 | Return of Assets | Enforce asset return on termination |
| A.5.12 | Classification of Information | Define classification scheme (e.g., Public/Internal/Confidential/Secret) |
| A.5.13 | Labelling of Information | Apply labels per classification scheme |
| A.5.14 | Information Transfer | Policies for transfer via email, USB, cloud |
| A.5.15 | Access Control | Establish access control policy (RBAC, least privilege) |
| A.5.16 | Identity Management | Manage full identity lifecycle |
| A.5.17 | Authentication Information | Manage passwords, tokens, keys securely |
| A.5.18 | Access Rights | Grant, review, revoke access rights |
| A.5.19 | IS in Supplier Relationships | Define IS requirements for suppliers |
| A.5.20 | IS within Supplier Agreements | Contractual IS clauses |
| A.5.21 | IS in ICT Supply Chain | Manage risks in software/hardware supply chain |
| A.5.22 | Monitoring and Review of Supplier Services | Audit supplier security performance |
| IS for Use of Cloud Services | ||
| A.5.24 | IS Incident Mgmt Planning | Prepare incident response plans |
| A.5.25 | Assessment of IS Events | Classify and triage security events |
| A.5.26 | Response to IS Incidents | Contain, eradicate, recover from incidents |
| A.5.27 | Learning from IS Incidents | Post-incident review, lessons learned |
| A.5.28 | Collection of Evidence | Forensic-ready evidence handling |
| A.5.29 | IS During Disruption | Maintain security during BCP activation |
| ICT Readiness for Business Continuity | ||
| A.5.31 | Legal, Statutory, Regulatory Requirements | Identify and comply with legal obligations |
| A.5.32 | Intellectual Property Rights | Protect IPR (software licenses, patents) |
| A.5.33 | Protection of Records | Manage records per retention requirements |
| A.5.34 | Privacy and Protection of PII | GDPR / privacy controls for PII |
| A.5.35 | Independent Review of IS | Periodic independent IS reviews |
| A.5.36 | Compliance with IS Policies | Monitor and enforce policy compliance |
| A.5.37 | Documented Operating Procedures | Maintain operating procedures for IS activities |
| Control | Title | Brief Description |
|---|---|---|
| A.6.1 | Screening | Background checks before employment |
| A.6.2 | Terms and Conditions of Employment | IS responsibilities in employment contracts |
| A.6.3 | IS Awareness, Education and Training | Regular IS training and awareness programs |
| A.6.4 | Disciplinary Process | Formal process for IS policy violations |
| A.6.5 | Responsibilities After Termination | IS obligations after leaving the organization |
| A.6.6 | Confidentiality / NDA Agreements | NDAs for personnel and contractors |
| A.6.7 | Remote Working | Security controls for remote/home working |
| A.6.8 | IS Event Reporting | Enable staff to report IS events and weaknesses |
| Control | Title | Brief Description |
|---|---|---|
| A.7.1 | Physical Security Perimeters | Define secure zones (fences, doors, card access) |
| A.7.2 | Physical Entry | Control and log physical access |
| A.7.3 | Securing Offices, Rooms, Facilities | Lock and protect work areas |
| Physical Security Monitoring | ||
| A.7.5 | Protecting Against Physical/Environmental Threats | Fire, flood, power failure controls |
| A.7.6 | Working in Secure Areas | Restrict and control secure area access |
| A.7.7 | Clear Desk and Clear Screen | No sensitive info left unattended |
| A.7.8 | Equipment Siting and Protection | Protect hardware from environmental damage |
| A.7.9 | Security of Assets Off-Premises | Controls for laptops, phones outside office |
| A.7.10 | Storage Media | Secure handling, transport, disposal of media |
| A.7.11 | Supporting Utilities | UPS, generators, cooling for datacenters |
| A.7.12 | Cabling Security | Protect network and power cabling |
| A.7.13 | Equipment Maintenance | Schedule and log hardware maintenance |
| A.7.14 | Secure Disposal or Re-Use of Equipment | Wipe / destroy before disposal |
| Control | Title | Brief Description |
|---|---|---|
| A.8.1 | User Endpoint Devices | Policies for laptops, phones, BYOD |
| A.8.2 | Privileged Access Rights | |
| A.8.3 | Information Access Restriction | Enforce need-to-know data access |
| A.8.4 | Access to Source Code | Protect source code repositories |
| A.8.5 | Secure Authentication | |
| A.8.6 | Capacity Management | Monitor and plan resource capacity |
| A.8.7 | Protection Against Malware | EDR, AV, email filtering, sandboxing |
| A.8.8 | Management of Technical Vulnerabilities | |
| Configuration Management | ||
| Information Deletion | ||
| Data Masking | ||
| Data Leakage Prevention | ||
| A.8.13 | Information Backup | Backup policies, testing, offsite/immutable |
| A.8.14 | Redundancy of Information Processing | HA, failover, geographic redundancy |
| A.8.15 | Logging | |
| Monitoring Activities | ||
| A.8.17 | Clock Synchronization | NTP time sync for log correlation |
| A.8.18 | Use of Privileged Utility Programs | Control admin tools (sysinternals, etc.) |
| A.8.19 | Installation of Software on Operational Systems | Software allowlisting, deployment control |
| A.8.20 | Networks Security | Segmentation, firewall rules, DMZ |
| A.8.21 | Security of Network Services | Secure network service agreements |
| A.8.22 | Segregation of Networks | VLAN, micro-segmentation, Zero Trust |
| Web Filtering | ||
| A.8.24 | Use of Cryptography | Crypto policies, key management |
| A.8.25 | Secure Development Life Cycle | Security requirements in SDLC |
| A.8.26 | Application Security Requirements | Secure design, threat modeling |
| A.8.27 | Secure System Architecture and Engineering | Security-by-design principles |
| Secure Coding | ||
| A.8.29 | Security Testing in Dev and Acceptance | Pentest, vuln assessment in pipeline |
| A.8.30 | Outsourced Development | Security requirements for third-party dev |
| A.8.31 | Separation of Dev/Test/Production | Isolate environments |
| A.8.32 | Change Management | Formal change control process |
| A.8.33 | Test Information | Protect production data used in tests |
| A.8.34 | Protection of IS During Audit Testing | Isolate and scope audit access |
| Dimension | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Total controls | ||
| Themes / Annexes | 14 clauses (A.5-A.18) | |
| New controls | - | |
| Merged controls | - | 24 controls merged |
| Revised controls | - | 58 controls updated |
| Attributes | None | |
| Clause 6.1.3 | SoA required | SoA required (no change) |
| Clause 6.3 | N/A |
| Control | Title | Theme |
|---|---|---|
| A.5.7 | Threat Intelligence | Organizational |
| A.5.23 | Information Security for Use of Cloud Services | Organizational |
| A.5.30 | ICT Readiness for Business Continuity | Organizational |
| A.7.4 | Physical Security Monitoring | Physical |
| A.8.9 | Configuration Management | Technological |
| A.8.10 | Information Deletion | Technological |
| A.8.11 | Data Masking | Technological |
| A.8.12 | Data Leakage Prevention | Technological |
| A.8.16 | Monitoring Activities | Technological |
| A.8.23 | Web Filtering | Technological |
| A.8.28 | Secure Coding | Technological |
Each of the 93 controls now carries 5 attribute types to aid categorization:
| Attribute | Values (examples) |
|---|---|
| Control type | Preventive / Detective / Corrective |
| IS properties | Confidentiality / Integrity / Availability |
| Cybersecurity concepts | Identify / Protect / Detect / Respond / Recover |
| Operational capabilities | Governance, Asset mgmt, IAM, Threat intel, etc. |
| Security domains | Governance, Protection, Defence, Resilience |
The SoA is a mandatory document (clause 6.1.3) that maps each of the 93 Annex A controls to the organization's risk treatment decisions.
For each of the 93 controls, document:
- Applicable: Yes / No
- Justification for inclusion: which risk(s) justify this control
- Justification for exclusion: why this control is not needed (if excluded)
- Implementation status: Not started / Planned / Partial / Implemented / Verified
- Reference to implementing document (policy, procedure, technical config)
Example SoA rows:
A.8.5 | Secure Authentication | YES | Risk R-042: credential theft | Implemented | POL-IAM-007
A.8.11 | Data Masking | YES | Risk R-018: PII exposure in test | Partial | PROC-DEV-012
A.7.4 | Physical Security Mon. | NO | Out of scope: no on-prem DC | N/A | -
Impact
1-Low 2-Med 3-High 4-Crit
+------+------+-------+------+
4-VHigh | Med | High | High | Crit |
3-High | Low | Med | High | High |
2-Med | Low | Low | Med | Med |
1-Low | Low | Low | Low | Low |
+------+------+-------+------+
Likelihood
Risk level -> treatment decision (per 6.1.3):
Critical/High : Modify (implement controls) or Avoid (stop activity)
Medium : Modify (implement controls) or Share (transfer to 3rd party)
Low : Retain (accept) or Monitor
| Step | Activity | Output |
|---|---|---|
| 1 | Define methodology and criteria | Risk assessment methodology doc |
| 2 | Identify assets in scope | Asset inventory with owners |
| 3 | Identify threats and vulnerabilities | Threat/vuln register |
| 4 | Assess existing controls | Control effectiveness rating |
| 5 | Determine likelihood (1-4) | Per risk entry |
| 6 | Determine impact (1-4) | Per risk entry per CIA property |
| 7 | Calculate risk level | Risk register with ratings |
| 8 | Compare to risk acceptance threshold | Risks to treat vs. accept |
| 9 | Select Annex A controls | SoA draft |
| 10 | Define risk treatment plan | RTP with owners and deadlines |
| Step | Phase | Description |
|---|---|---|
| 1 | Compare current state vs ISO 27001 requirements, identify gaps | |
| 2 | Which assets, processes, locations, and services are in scope (4.3) | |
| 3 | Identify and evaluate risks to in-scope assets (ISO 27005 / EBIOS RM) | |
| 4 | Select Annex A controls, justify exclusions, build SoA | |
| 5 | Deploy policies, procedures, technical measures | |
| 6 | All staff trained on ISMS policies and their responsibilities | |
| 7 | Independent audit verifying all clauses and Annex A controls | |
| 8 | Formal ISMS review by top management with defined inputs | |
| 9 | CB reviews documentation, scope, and ISMS readiness | |
| 10 | CB verifies implementation on-site; issues nonconformities | |
| 11 | Remediate major/minor NCs before certificate issued | |
| 12 | Certificate issued (valid 3 years) | |
| 13 | Surveillance audits | Annual audit to verify ISMS is maintained and improved |
| 14 | Recertification | Full audit every 3 years |
| Document | Clause | Purpose |
|---|---|---|
| ISMS Scope document | 4.3 | Defines what is covered |
| Information security policy | 5.2 | Top-level policy signed by management |
| Risk assessment methodology | 6.1.2 | Documented process for risk identification |
| Risk register | 6.1.2 | All identified risks with ratings and owners |
| Statement of Applicability (SoA) | 6.1.3 | Links risks to all 93 Annex A controls |
| Risk treatment plan | 6.1.3 | Remediation plan with owners and deadlines |
| Security objectives | 6.2 | Measurable IS goals |
| Competence records | 7.2 | Training and qualification evidence |
| Operational control procedures | 8.1 | Procedures for key IS processes |
| Internal audit program + reports | 9.2 | Audit schedule and findings |
| Management review minutes | 9.3 | Formal review records |
| Nonconformity + corrective action records | 10.1 | NC tracking and closure |
| Standard | Title | Relationship to ISO 27001 |
|---|---|---|
| ISO 27001:2022 | ISMS Requirements | |
| ISO 27002:2022 | Controls Guidance | |
| ISO 27005:2022 | Risk Management | |
| ISO 27017:2015 | Cloud Security | Extra controls for cloud service providers and customers |
| ISO 27018:2019 | Cloud PII | Privacy controls in public cloud (GDPR alignment) |
| ISO 27701:2019 | Privacy (PIMS) | Extension of 27001 scope to cover privacy management |
| ISO 27035:2023 | Incident Management | Incident response process (feeds A.5.24-5.28) |
| NIST CSF 2.0 | Cyber Framework | Identify/Protect/Detect/Respond/Recover aligns with Annex A themes |
| EBIOS RM | Risk Method (ANSSI) |