Skip to content

ISO 27001 Checklist: Clauses 4 to 10, Annex A and Audit Readiness

An ISO 27001:2022 checklist: every requirement in Clauses 4 to 10, the mandatory documents, the 93 Annex A controls by theme, and an internal audit checklist.

Invadel TeamReviewed by Wahid Iqbal, Head of Compliance12 min read

This ISO 27001 checklist covers what a certification auditor will look for under ISO/IEC 27001:2022: every requirement in Clauses 4 to 10, the documented information the standard makes mandatory, the 93 Annex A controls and how to decide which apply, and a checklist for the internal audit you must run before certification. Use it to find gaps before a Stage 1 audit, or to check an existing ISMS before surveillance.

One thing up front, so the checklist reads correctly. Invadel does not certify organizations; certificates come only from an accredited certification body. We supply the technical evidence several Annex A controls depend on, chiefly the penetration testing and vulnerability scanning behind 8.8 and 8.29, which is covered on our ISO 27001 penetration testing page. The rest of this checklist is yours to work through with your team or your implementation partner.

Which version applies

ISO/IEC 27001:2022 is the current edition. ISO published it on 25 October 2022, and certificates issued against the 2013 edition had to transition by 31 October 2025, after which they expired or were withdrawn (IAF MD 26). An amendment published in February 2024 added climate change to Clause 4: you must decide whether climate change is a relevant issue for your ISMS, and note that interested parties may have climate-related requirements (ISO and IAF joint communique). Audits today are against the 2022 edition with that amendment.

How ISO 27001 is structured

  • Clauses 0 to 3 are introduction, scope, references and terms. Nothing to implement.
  • Clauses 4 to 10 are the mandatory requirements for the information security management system (ISMS). Every one applies; you cannot exclude any.
  • Annex A lists 93 information security controls. You compare your risk treatment against it and record in a Statement of Applicability which controls you use and why.

That split answers the common question “what are the 10 clauses of ISO 27001”: after the introduction there are ten numbered clauses, but only seven of them, 4 to 10, contain requirements.

ISO 27001 checklist: Clauses 4 to 10

The requirements below are paraphrased, not quoted from the standard. The evidence column is what an auditor typically asks to see.

Clause What you must have Evidence to show
4.1 Context The internal and external issues that affect your ISMS, including whether climate change is relevant A context analysis or issues register
4.2 Interested parties Who the interested parties are, their requirements, and which of them the ISMS addresses An interested-parties register, including legal, regulatory and contractual requirements
4.3 Scope ISMS boundaries and applicability, considering interfaces and dependencies A documented scope statement
4.4 ISMS The ISMS established, implemented, maintained and continually improved, including its processes Process descriptions and how they interact
5.1 Leadership Top management demonstrates commitment: resources, integration into business processes, direction Management review minutes, budget and resource decisions
5.2 Policy An information security policy with objectives or a framework for them, and commitments to meet requirements and improve The approved, communicated policy
5.3 Roles Responsibilities and authorities assigned and communicated, including who reports on ISMS performance Role descriptions, a RACI or appointment records
6.1.1 Risks and opportunities Planned actions to address risks and opportunities to the ISMS itself Action plan linked to the context analysis
6.1.2 Risk assessment A defined, repeatable process with risk acceptance criteria, risk owners, analysis and evaluation The documented risk assessment method
6.1.3 Risk treatment Treatment options chosen, controls determined and compared with Annex A, a Statement of Applicability, a treatment plan, and risk owners’ approval of residual risk The SoA, the risk treatment plan and the sign-offs
6.2 Objectives Measurable information security objectives, monitored and communicated, with plans for who, what, when and how they are evaluated The objectives and their tracking
6.3 Planning of changes Changes to the ISMS carried out in a planned way (new in 2022) Change records for the ISMS
7.1 Resources Resources needed for the ISMS provided Budget, headcount or tooling decisions
7.2 Competence Required competence defined, achieved and evidenced Training records, qualifications, role requirements
7.3 Awareness Staff know the policy, their contribution, and the consequences of not conforming Awareness program records
7.4 Communication What is communicated about the ISMS, when, to whom and how A communication plan
7.5 Documented information Documents the standard requires and those you decide are needed, created and controlled Document control procedure, version history
8.1 Operational planning Processes planned and controlled, including externally provided processes, products and services Operating procedures, supplier controls
8.2 Risk assessment performed Assessments run at planned intervals and after significant change Dated risk assessment results
8.3 Risk treatment performed The treatment plan implemented Treatment results and status
9.1 Monitoring and measurement What is measured, how, when, by whom, and how results are evaluated Metrics and their analysis
9.2 Internal audit A planned audit program run by objective auditors, results reported to management The audit program, reports and follow-up
9.3 Management review Reviews at planned intervals covering the inputs the standard lists, with decisions recorded Review minutes and actions
10.1 Continual improvement The ISMS continually improved Improvement records
10.2 Nonconformity and corrective action Nonconformities handled, causes addressed, effectiveness reviewed A corrective action log

Clauses 6.1.2 and 8.2 are where most first-time ISMSs are thinnest: a risk method that exists on paper but has never produced a dated, owned set of results. Our security risk assessment guide walks through a method that produces those results.

Mandatory documented information

The standard requires these documents or records. Auditors usually ask for them first, so assemble them before Stage 1:

  1. ISMS scope (4.3)
  2. Information security policy (5.2)
  3. Risk assessment process (6.1.2)
  4. Risk treatment process (6.1.3)
  5. Statement of Applicability (6.1.3)
  6. Information security objectives (6.2)
  7. Evidence of competence (7.2)
  8. Documented information you have determined is necessary for the ISMS (7.5.1)
  9. Operational planning and control information (8.1)
  10. Risk assessment results (8.2)
  11. Risk treatment results (8.3)
  12. Monitoring and measurement results (9.1)
  13. Internal audit program and results (9.2)
  14. Management review results (9.3)
  15. Nonconformities and corrective actions (10.2)

Annex A controls add documents of their own where you apply them, such as an asset inventory, an access control policy or incident procedures, but those follow from your Statement of Applicability rather than from the clauses.

Annex A: the 93 controls by theme

The 2022 edition reorganized Annex A around four themes. Compared with the 2013 edition, the number of controls fell from 114 in 14 clauses to 93 in four; 11 controls are new, 24 were merged from existing ones and 58 were updated (IAF MD 26).

Theme Controls Numbering Examples of what it covers
Organizational 37 5.1 to 5.37 Policies, roles, asset inventory, access control, supplier security, incident management, legal requirements, independent review
People 8 6.1 to 6.8 Screening, employment terms, awareness and training, disciplinary process, remote working, event reporting
Physical 14 7.1 to 7.14 Perimeters, entry controls, secure areas, equipment protection, storage media, secure disposal
Technological 34 8.1 to 8.34 Endpoints, privileged access, authentication, malware protection, vulnerability management, backups, logging, network security, secure development and testing

The 11 controls that were new in 2022, and that auditors still probe because many ISMSs were built before them: threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28).

Statement of Applicability checklist

The SoA is the document auditors spend the most time on. For each of the 93 controls, check that it records:

  • Whether the control is included or excluded.
  • Why it is included: the risk it treats, or a legal, contractual or business requirement.
  • Why it is excluded, where it is. An exclusion needs a reason tied to your risk assessment or scope, not “not relevant”.
  • Whether it is implemented, and where the evidence is.
  • Any controls you use beyond Annex A. The annex is a reference list, not a ceiling.

A common audit finding is an SoA that marks controls as implemented with nothing behind them. If a control says “implemented”, the auditor will sample the evidence.

Where testing evidence fits

Several Annex A controls are hard to evidence without testing, because the question is whether the control works, not whether a policy exists.

Control What the auditor wants to see Evidence that answers it
8.8 Management of technical vulnerabilities Vulnerabilities identified, exposure evaluated, and action taken in time Recurring vulnerability scanning from $1,500 per scan, plus an annual penetration test and remediation records
8.29 Security testing in development and acceptance Security testing defined in the development life cycle and actually performed A web application penetration test from $5,200 before release and after major change
8.28 Secure coding Secure coding principles applied to software development A secure code review from $4,800, which evidences the rules rather than just the outcome
5.35 Independent review of information security Your approach reviewed independently at planned intervals An external penetration test is an independent review of the technical controls
8.20 and 8.22 Network security and segregation Networks secured, and groups of services, users and systems segregated External and internal network testing, including segmentation

Findings from a test then feed Clause 8.2 and 8.3: each one is risk-rated, treated or formally accepted, and the retest records that treatment worked. Our guide to vulnerability remediation covers how to prioritize and prove fixes in a way an auditor can follow.

ISO 27001 internal audit checklist

Clause 9.2 requires internal audits at planned intervals, and certification bodies expect to see at least one completed internal audit before Stage 2. A practical checklist for running one:

  • Program. An audit program covering the whole ISMS scope and all applicable Annex A controls over the certification cycle, with frequency based on risk and past results.
  • Independence. Auditors who do not audit their own work, which is why small organizations sometimes bring in an outside internal auditor.
  • Criteria and scope defined for each audit.
  • Sampling. Evidence sampled for each clause and control, not just interviews.
  • Clause coverage. Every requirement in Clauses 4 to 10 checked at least once in the cycle, using the table above.
  • Control coverage. A sample of applied Annex A controls tested for operation: records, settings and, for technical controls, test results.
  • Findings graded as nonconformities or observations, each with evidence.
  • Reporting to relevant management, and the results feeding the management review (9.3).
  • Follow-up. Corrective actions logged under 10.2 and verified.

Questions worth asking in every internal audit: does the scope statement still match reality; when was the risk assessment last updated and what changed; is the SoA consistent with the risk treatment plan; do the objectives have measurements; were last year’s corrective actions effective; and is the technical evidence behind 8.8 and 8.29 less than a year old?

Certification audit readiness

Certification runs in two stages. Stage 1 reviews the ISMS design and documentation; Stage 2 checks that it operates, by sampling evidence across the clauses and controls. A certificate then runs a three-year cycle with surveillance audits in the intervening years and a recertification audit at the end. Before Stage 2, check:

  • At least one full internal audit and one management review completed and recorded.
  • The risk assessment and treatment plan are current, and residual risks are accepted by their owners.
  • Technical evidence is recent: vulnerability scans on a cadence, and a penetration test with its retest completed one to three months before the audit, so findings are closed rather than open.
  • Corrective actions from the internal audit are closed or in progress with dates.

If you already hold SOC 2, much of the control evidence carries over, but the management-system clauses do not. Our comparison of ISO 27001 vs SOC 2 shows where the two overlap and where ISO asks for more.

Frequently asked questions

What are the 10 clauses of ISO 27001? After the introduction (Clause 0), Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 hold the requirements: context of the organization, leadership, planning, support, operation, performance evaluation and improvement.

How many controls are in ISO 27001 Annex A? 93 in the 2022 edition, grouped into organizational (37), people (8), physical (14) and technological (34) controls.

Do we have to implement all 93 Annex A controls? No. You must compare your risk treatment against all 93 and justify each inclusion and exclusion in the Statement of Applicability. Clauses 4 to 10, by contrast, cannot be excluded.

Is there a free ISO 27001 checklist? This page is one: the Clauses 4 to 10 table, the mandatory documents list, the SoA checklist and the internal audit checklist cover what an auditor examines. The standard itself is sold by ISO and national standards bodies, and you need a copy to implement it properly.

Does ISO 27001 require penetration testing? Not by name, but controls 8.8 and 8.29 and the requirement to evaluate ISMS effectiveness are difficult to evidence without it, and certification auditors routinely expect a recent test. Our ISO 27001 penetration testing page explains what auditors check.

What changed between ISO 27001:2013 and 2022? Annex A was restructured from 114 controls in 14 clauses to 93 in four themes, with 11 new controls. The clauses gained a planning-of-changes requirement (6.3), a new item on which interested-party requirements the ISMS addresses (4.2), named and reordered subclauses in internal audit (9.2) and management review (9.3), and swapped the order of the two improvement subclauses in Clause 10. The 2024 amendment added climate change to Clause 4.

Need the technical evidence behind 8.8 and 8.29 before your Stage 2 or surveillance audit? Scope a test against your ISMS boundary, and we will time it so the retest is complete before the auditor arrives.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation