Learn about the SoA, four control themes in ISO 27001:2022, main clauses, Annex A, performance evaluation requirements, risk register and more, through the Frequently Asked Questions (FAQs) below. Please schedule a meeting if you are looking for an authorized certifying body for your ISO 27001 Certification.
Table of Contents
What are the main clauses of ISO 27001?
ISO/IEC 27001:2022 is organized into eleven clauses (0, 10), of which Clauses 4 through 10 contain the formal, auditable certification requirements.
Clause 4 (Context of the Organization) requires the organization to understand its internal and external environment, identify interested parties, and define the ISMS scope. Clause 5 (Leadership) requires top management commitment, an information security policy, and assignment of roles and responsibilities. Clause 6 (Planning) addresses risk assessment, risk treatment, information security objectives, and the new Clause 6.3 requirement for managing planned ISMS changes. Clause 7 (Support) covers resources, competence, awareness, communication, and documentation. Clause 8 (Operation) governs the execution of risk assessments and treatment plans. Clause 9 (Performance Evaluation) requires monitoring, measurement, internal audits, and management reviews. Clause 10 (Improvement) addresses nonconformities, corrective actions, and continual improvement. Clauses 0, 3 provide introduction, scope, normative references, and terms; they are informational, not auditable.
What is Annex A in ISO 27001?
Annex A in ISO 27001:2022 is a normative reference catalog of 93 information security controls organized into four themes, against which organizations document their control selection decisions.
Annex A is not a mandatory implementation checklist; it is a reference library that organizations must consider when treating identified risks. For each control, an organization must either implement it or formally document its justification for exclusion in the Statement of Applicability (SoA). Annex A corresponds directly to ISO/IEC 27002:2022, which provides detailed implementation guidance for each control. The four themes are Organizational controls (37 controls), People controls (8 controls), Physical controls (14 controls), and Technological controls (34 controls). The auditor will review both the SoA and evidence of control implementation during the Stage 2 certification audit.
What are the four control themes in ISO 27001:2022?
ISO 27001:2022 organizes all 93 Annex A controls into four themes that replaced the 14, domain structure of the 2013 version.
Organizational controls (37 controls) address governance, level topics including information security policies, roles and responsibilities, supplier relationships, incident management, business continuity, and legal compliance. People control (8 controls) cover employee screening, terms of employment, security awareness training, responsibilities during and after employment, and remote working policies. Physical controls (14 controls) address physical security perimeters, access to secure areas, clear desk and screen policies, physical media handling, and equipment security. Technological controls (34 controls) cover access control, authentication, encryption, vulnerability management, logging, network security, and secure software development. The four, theme structure makes it easier to map ISO 27001 controls against other frameworks such as NIST CSF, SOC 2, and CIS Controls.
What is the Statement of Applicability (SoA) in ISO 27001?
The Statement of Applicability (SoA) is one of the most critical mandatory documents in ISO 27001, recording which of the 93 Annex A controls an organization has selected, which it has excluded, and the evidence, based justification for both decisions.
The SoA must document each of the 93 Annex A controls, whether each is applicable or not applicable, the justification for inclusion or exclusion, and confirmation of whether each applicable control has been implemented. Exclusions are permitted only when the associated risks are absent or managed through equally effective alternative means, auditors scrutinize exclusions closely. The SoA must be updated whenever the risk profile, business scope, or control environment changes. It is one of the first documents an ISO 27001 auditor requests and serves as the backbone that links the risk assessment to implemented controls. Organizations that produce a template, copied SoA without genuine risk analysis face a high probability of audit findings.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable management system standard that defines the requirements an organization’s ISMS must meet, including risk assessment, governance, documentation, and continual improvement. ISO 27002 is a supplementary guidance standard providing detailed implementation advice for each of the 93 controls listed in ISO 27001’s Annex A. Organizations are certified against ISO 27001, not ISO 27002. ISO 27002 exists purely as an implementation reference. For example, ISO 27001 Annex A lists “Threat Intelligence” as Control 5.7, while ISO 27002 explains what a threat intelligence process should cover and how to implement it effectively. Both documents must be purchased separately from ISO. Organizations implementing ISO 27001 should use ISO 27002:2022 as their implementation companion.
What are the main clauses governing planning in ISO 27001?
Clause 6 of ISO 27001:2022 (Planning) contains three sub-clauses establishing how organizations plan their ISMS, covering risk management, measurable security objectives, and controlled management of ISMS changes.
Clause 6.1 covers actions to address risks and opportunities, requiring a formal, documented risk assessment methodology, a risk treatment plan, and management approval of both. Clause 6.2 covers information security objectives, which must be measurable, monitored, communicated, and documented. The 2022 version added an explicit requirement to track objectives against defined timeframes and responsibilities. Clause 6.3, newly introduced in ISO 27001:2022, addresses the planning of changes to the ISMS, requiring organizations to manage any significant modifications in a structured manner so that changes do not inadvertently introduce new security risks or undermine existing controls.
What are the performance evaluation requirements in ISO 27001?
Clause 9 of ISO 27001:2022 (Performance Evaluation) requires organizations to monitor, measure, analyze, and evaluate ISMS performance through three mandatory processes: ongoing measurement, internal audits, and management reviews.
Clause 9.1 requires organizations to define what to measure, which methods to use, when to analyze results, and who is responsible. Clause 9.2, split into 9.2.1 (General) and 9.2.2 (Internal Audit Program) in the 2022 version, requires planned internal audits at defined intervals to confirm the ISMS conforms to ISO 27001 requirements and the organization’s own policies, and that it is effectively implemented. Clause 9.3 requires top management to review the ISMS at planned intervals, considering audit results, nonconformities, risk changes, and security performance. Evidence of all three processes is reviewed by external auditors during certification, surveillance, and recertification audits.
What is the continual improvement requirement in ISO 27001?
Clause 10 of ISO 27001:2022 (Improvement) places a binding obligation on organizations to continually improve the suitability, adequacy, and effectiveness of their ISMS. Clause 10.1 requires demonstrable ongoing improvement, not merely maintaining the status quo. Clause 10.2 requires that whenever a nonconformity is identified, the organization must react promptly, investigate its root cause, implement corrective actions to prevent recurrence, and review the effectiveness of those actions. Evidence of corrective action must be retained as documented information. Certification bodies expect to see a documented improvement history during surveillance and recertification audits. An ISMS showing no improvement activity across a three, year certification cycle will raise serious concerns during recertification.
What is an ISO 27001 risk register?
An ISO 27001 risk register is a structured document that records every identified information security risk, its assessed likelihood and impact, the treatment decision applied to it, the controls used to address it, the assigned risk owner, and the residual risk level after controls are in place. Required under Clause 6.1.2 of ISO 27001:2022, the risk register must be maintained as a living document, updated whenever new risks are identified, existing risks change, or the business environment shifts. It is the connective tissue of the ISMS: every control in the SoA and every entry in the risk treatment plan should trace directly back to a risk in the register. Auditors review the risk register to confirm that control selections are genuinely driven by identified risks rather than copied from a template.
What is an ISO 27001 ISMS policy document?
An ISO 27001 ISMS policy document, typically the Information Security Policy, is the top, level, management, approved statement that establishes the organization’s commitment to information security and sets the governance framework within which all supporting security policies operate.
Required by Clause 5.2 of ISO 27001:2022, the policy must be appropriate to the organization’s purpose, include measurable security objectives or a framework for setting them, commit to satisfying applicable security requirements, and commit to continual improvement. It must be documented, communicated internally, and made available to interested parties. In addition to this overarching policy, ISO 27001 requires topic, specific supporting policies, including access control, acceptable use, cryptography, clear desk and screen, and supplier security policies, each tied to specific Annex A controls and risk treatment decisions.
What is data classification in ISO 27001?
Data classification in ISO 27001 is the process of categorizing information assets according to their sensitivity, ensuring that controls proportional to each category’s risk are consistently applied. ISO 27001:2022 Annex A Control 5.12 (Classification of Information) requires organizations to classify information based on legal requirements, business value, and sensitivity using a defined classification scheme. Common classification levels include Public, Internal, Confidential, and Restricted, though organizations define their own tiers. Classification directly informs access control decisions, encryption requirements, and data handling procedures for employees and third parties. Control 5.13 (Labeling) and Control 5.14 (Information Transfer) build on the classification scheme to govern how information is marked and moved. Auditors verify that the classification scheme is documented, implemented, and reflected in risk treatment decisions.
How are ISO 27001 controls selected based on risk?
ISO 27001 controls are selected through a risk, based process, not imposed as a universal mandatory list, making the risk assessment the most foundational activity in the entire ISMS.
The process begins with a risk assessment (Clause 6.1.2) identifying information assets, threats, vulnerabilities, and potential impact. Each risk is evaluated against the organization’s defined acceptance criteria. For risks exceeding acceptable levels, the organization chooses a treatment option: mitigate (implement controls), accept (acknowledge and monitor), transfer (such as through cyber insurance), or avoid (discontinue the risky activity). When mitigating, controls are selected primarily from Annex A and documented in the Statement of Applicability with justification. Any Annex A control not selected must be explicitly excluded in the SoA with a documented rationale. This risk, driven approach distinguishes ISO 27001 from prescriptive compliance frameworks, controls must be justified by actual risks, not copied from templates.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties