0%
0 of 58 answered
Clauses 4–5 — Context & Leadership
Context & Leadership
0/8
Clause 6 — Risk Planning
Risk Planning
0/8
Clauses 7–8 — Support & Operations
Support & Operations
0/8
Clauses 9–10 — Performance & Improvement
Performance & Improvement
0/6
Annex A.5–A.8 — Organisational Controls
Organisational Controls
0/8
Annex A — People Controls
People Controls
0/6
Annex A — Physical Controls
Physical Controls
0/6
Annex A — Technological Controls
Technological Controls
0/8
Used to tailor guidance in your report
CL1

Context & Leadership

Clauses 4–5 — Organisational context, interested parties, scope, leadership & commitment

Clause 4.1–4.2 — Context of the Organisation
Has the organisation determined external and internal issues relevant to its purpose that affect the ISMS outcomes?
Clause 4.1 requires understanding the organisation's context including regulatory, contractual, and business environment factors that influence information security objectives.
Have interested parties and their requirements relevant to the ISMS been identified?
Clause 4.2 requires identifying stakeholders (regulators, customers, partners) and their information security requirements, including legal, regulatory, and contractual obligations.
Clause 4.3–4.4 — Scope & ISMS
Is the scope of the ISMS clearly defined and documented, including boundaries and applicability?
Clause 4.3 requires determining the boundaries and applicability of the ISMS, considering internal/external issues, interested party requirements, and interfaces with activities performed by other organisations.
Has the organisation established, implemented, maintained, and continually improved an ISMS in accordance with ISO 27001?
Clause 4.4 requires a formal ISMS that includes the processes needed and their interactions, following the requirements of the standard.
Clause 5.1–5.3 — Leadership
Does top management demonstrate leadership and commitment to the ISMS?
Clause 5.1 requires top management to ensure the information security policy and objectives are established and compatible with strategic direction, ensure integration of ISMS requirements into business processes, and ensure adequate resources.
Is there a documented information security policy that is appropriate, includes objectives, and is communicated within the organisation?
Clause 5.2 requires an information security policy that is appropriate to the purpose of the organisation, includes information security objectives or provides a framework for setting them, includes a commitment to satisfy applicable requirements, and is available to interested parties as appropriate.
Are organisational roles, responsibilities, and authorities for information security assigned and communicated?
Clause 5.3 requires top management to ensure the responsibilities and authorities for roles relevant to information security are assigned and communicated, including responsibility for ensuring ISMS conformity and reporting on ISMS performance.
Is there a designated information security management representative or team with adequate authority and resources?
While ISO 27001:2022 does not mandate a specific role title, the organisation needs someone accountable for the ISMS with sufficient authority and resource allocation to maintain and improve it.
CL2

Risk Planning

Clause 6 — Actions to address risks & opportunities, information security objectives, planning of changes

Clause 6.1 — Actions to Address Risks & Opportunities
Does the organisation consider internal/external issues and interested party requirements when determining risks and opportunities for the ISMS?
Clause 6.1.1 requires planning actions to address risks and opportunities, ensuring the ISMS can achieve its intended outcomes, prevent or reduce undesired effects, and achieve continual improvement.
Is there a defined and documented information security risk assessment process with established risk criteria?
Clause 6.1.2 requires defining a risk assessment process that establishes risk acceptance criteria, ensures repeated assessments produce consistent and comparable results, identifies risks to confidentiality, integrity, and availability.
Are information security risks analysed (likelihood and impact) and evaluated against the risk criteria to prioritise treatment?
Risk analysis assesses the realistic likelihood and potential consequences of each identified risk. Risk evaluation compares results against acceptance criteria to determine which risks need treatment.
Clause 6.1.3 — Risk Treatment
Is there a documented risk treatment plan with selected controls and justification for their selection?
Clause 6.1.3 requires selecting appropriate risk treatment options, determining controls necessary to implement those options, and comparing controls with Annex A to verify none have been omitted.
Has a Statement of Applicability (SoA) been produced listing all necessary controls and justification for inclusion/exclusion?
The SoA is a key ISO 27001 document that lists all Annex A controls, states whether each is applicable, provides justification for inclusion or exclusion, and confirms implementation status.
Clause 6.2–6.3 — Objectives & Planning of Changes
Are information security objectives established at relevant functions and levels, and are they measurable and monitored?
Clause 6.2 requires objectives that are consistent with the security policy, measurable (if practicable), take into account requirements, and are communicated and updated as appropriate. Plans must address what, resources, responsibility, deadlines, and evaluation.
Are information security objectives documented and retained as documented information?
Objectives should be formally documented and retained. They should be reviewed periodically and updated to reflect changing circumstances, new threats, and business developments.
When changes to the ISMS are needed, are they planned and carried out in a controlled manner?
Clause 6.3 (new in ISO 27001:2022) requires that when the organisation determines the need for changes to the ISMS, the changes are carried out in a planned manner, considering the purpose, consequences, ISMS integrity, and resource availability.
CL3

Support & Operations

Clauses 7–8 — Resources, competence, awareness, communication, documented information, operational planning

Clause 7.1–7.3 — Resources, Competence & Awareness
Has the organisation determined and provided the resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS?
Clause 7.1 requires adequate resources including people, infrastructure, and budget to establish and maintain the ISMS effectively.
Are persons doing work under the organisation's control competent on the basis of appropriate education, training, or experience?
Clause 7.2 requires determining competence needs for persons affecting information security performance, ensuring competence through training or other actions, and retaining evidence of competence.
Are persons doing work under the organisation's control aware of the security policy, their contribution to ISMS effectiveness, and implications of non-conformity?
Clause 7.3 requires awareness of the information security policy, the person's contribution to ISMS effectiveness including benefits of improved performance, and implications of not conforming with ISMS requirements.
Clause 7.4–7.5 — Communication & Documented Information
Has the organisation determined the need for internal and external communications relevant to the ISMS (what, when, with whom, and how)?
Clause 7.4 requires determining what to communicate, when, with whom, and how for both internal and external communications related to the ISMS.
Is documented information required by the ISMS created, updated, and controlled appropriately (identification, format, review, approval, access, storage, retention)?
Clause 7.5 covers creating and updating documented information with appropriate identification, format, and review/approval, plus controlling distribution, access, retrieval, storage, preservation, and disposition.
Clause 8 — Operational Planning & Control
Does the organisation plan, implement, and control the processes needed to meet ISMS requirements and implement risk treatment actions?
Clause 8.1 requires operational planning and control of the processes needed to meet information security requirements. This includes establishing criteria for processes and implementing control in accordance with those criteria.
Are information security risk assessments performed at planned intervals or when significant changes are proposed or occur?
Clause 8.2 requires performing risk assessments at planned intervals or when significant changes occur, retaining documented information of the results.
Is the information security risk treatment plan implemented and are results of the risk treatment retained as documented information?
Clause 8.3 requires implementing the risk treatment plan and retaining documented information of results. This ensures that treatment decisions are carried through to action.
CL4

Performance & Improvement

Clauses 9–10 — Monitoring, measurement, internal audit, management review, nonconformity, continual improvement

Clause 9.1–9.2 — Monitoring & Internal Audit
Does the organisation monitor, measure, analyse, and evaluate information security performance and ISMS effectiveness?
Clause 9.1 requires determining what needs to be monitored and measured, the methods used, when monitoring and measuring are performed, who performs them, and when results are analysed and evaluated.
Are internal audits conducted at planned intervals to determine whether the ISMS conforms to requirements and is effectively implemented and maintained?
Clause 9.2 requires an audit programme considering the importance of processes and previous audit results. Auditors must be objective and impartial, and results reported to relevant management.
Clause 9.3 — Management Review
Does top management review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness?
Clause 9.3 requires management reviews considering the status of actions from previous reviews, changes in external/internal issues, nonconformities, monitoring and measurement results, audit results, and opportunities for improvement.
Are management review outputs documented, including decisions on continual improvement opportunities and any needs for ISMS changes?
Management review outputs must include decisions related to continual improvement opportunities and any need for changes to the ISMS. Documented information must be retained as evidence.
Clause 10 — Improvement
When a nonconformity occurs, does the organisation react, evaluate, take corrective action, and review the effectiveness of actions taken?
Clause 10.1 requires reacting to nonconformities by taking action to control and correct them, evaluating the need for action to eliminate root causes, implementing needed actions, reviewing effectiveness, and making changes to the ISMS if necessary.
Does the organisation continually improve the suitability, adequacy, and effectiveness of the ISMS?
Clause 10.2 requires continual improvement through the use of the information security policy, objectives, audit results, analysis of monitored events, corrective actions, and management review.
AA1

Organisational Controls

Annex A.5 — Information security policies, roles, threat intelligence, asset management, access control, supplier relations

A.5.1–A.5.10 — Policies, Roles & Threat Intelligence
Are information security policies defined, approved by management, published, communicated, and reviewed at planned intervals?
A.5.1 requires a set of policies for information security, approved by management, published and communicated to relevant personnel and interested parties, and reviewed at planned intervals or if significant changes occur.
Are information security roles and responsibilities defined and allocated, with segregation of duties where appropriate?
A.5.2 assigns roles, A.5.3 requires segregation of conflicting duties to reduce opportunities for unauthorised modification or misuse, and A.5.4 requires management to enforce information security policies.
Is threat intelligence collected and analysed to produce actionable information about information security threats?
A.5.7 (new in 2022) requires collecting and analysing information about threats to produce threat intelligence that is relevant, insightful, contextual, and actionable. This should inform risk assessment and controls.
A.5.9–A.5.15 — Asset Management & Access Control
Is there an inventory of information and associated assets, with defined acceptable use rules?
A.5.9 requires an inventory of information and other associated assets (including owners), and A.5.10 requires rules for acceptable use and procedures for handling of information and assets.
Is access to information and information processing facilities restricted based on business and security requirements with a formal access control policy?
A.5.15 defines access control rules, A.5.16 covers identity management, A.5.17 covers authentication information, and A.5.18 covers access rights including provisioning, review, and removal.
A.5.19–A.5.23 — Supplier Relations & Cloud
Are information security requirements established for supplier relationships, with monitoring and change management of supplier services?
A.5.19 requires addressing security in supplier agreements, A.5.20 covers addressing security within supplier agreements, A.5.21 covers managing security in the ICT supply chain, and A.5.22 covers monitoring, review, and change management of supplier services.
Are information security requirements defined for the acquisition, use, management, and exit of cloud services?
A.5.23 (new in 2022) requires processes for cloud service acquisition, use, management, and exit to be established in accordance with the organisation's information security requirements.
Are incident management processes in place including planning, assessment, response, learning from incidents, and evidence collection?
A.5.24 requires incident management planning, A.5.25 covers assessment and decision on events, A.5.26 covers response to incidents, A.5.27 covers learning from incidents, A.5.28 covers evidence collection, and A.5.29-30 cover business continuity and ICT readiness.
AA2

People Controls

Annex A.6 — Screening, terms & conditions, awareness, training, disciplinary process, responsibilities after termination, remote working, event reporting

A.6.1–A.6.4 — Employment Lifecycle
Are background verification checks on all candidates carried out prior to joining the organisation, proportional to business requirements and risk?
A.6.1 requires background verification checks taking into account applicable laws, regulations, ethics, and proportional to business requirements, the classification of information to be accessed, and the perceived risks.
Do employment contractual agreements state the employee's and the organisation's responsibilities for information security?
A.6.2 requires that employment contracts include information security responsibilities, including responsibilities that extend beyond the employment period (e.g. confidentiality agreements).
Do all personnel receive appropriate information security awareness education, training, and regular updates, with a disciplinary process for violations?
A.6.3 requires awareness, education, and training programmes, and A.6.4 requires a disciplinary process for information security policy violations. Training should be relevant to job function.
A.6.5–A.6.8 — Post-Employment & Working Practices
Are information security responsibilities that remain valid after termination or change of employment defined, enforced, and communicated?
A.6.5 requires that information security responsibilities and duties that remain valid after termination or change of employment are defined, enforced, and communicated to the employee or contractor.
Are confidentiality or non-disclosure agreements in place and reviewed, and is information security applied when personnel are working remotely?
A.6.6 covers confidentiality and non-disclosure agreements reflecting the organisation's needs for information protection. A.6.7 requires security measures for remote working to protect information accessed, processed, or stored outside the premises.
Is there a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner?
A.6.8 requires providing a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner. This supports early detection and response.
AA3

Physical Controls

Annex A.7 — Physical security perimeters, entry controls, securing offices, physical security monitoring, protection against environmental threats, equipment

A.7.1–A.7.4 — Physical Perimeters & Monitoring
Are physical security perimeters defined and used to protect areas containing information and information processing facilities, with appropriate entry controls?
A.7.1 requires defining security perimeters for areas containing sensitive or critical information and information processing facilities. A.7.2 requires secure areas to be protected by appropriate entry controls to ensure only authorised personnel are allowed access.
Are offices, rooms, and facilities secured, and are premises continuously monitored for unauthorised physical access?
A.7.3 requires designing and applying physical security for offices, rooms, and facilities. A.7.4 (new in 2022) requires continuous monitoring of premises for unauthorised physical access.
A.7.5–A.7.8 — Environmental & Equipment Protection
Are protection measures against physical and environmental threats (fire, flood, earthquake, explosion, civil unrest) designed and implemented?
A.7.5 requires designing and implementing protection against physical and environmental threats such as natural disasters and other intentional or unintentional physical threats to infrastructure.
Are clear desk and clear screen policies implemented, and is equipment sited and protected to reduce risks from environmental threats and unauthorised access?
A.7.7 requires clear desk for papers/removable storage and clear screen for information processing facilities. A.7.8 requires equipment to be sited and protected to reduce risks from environmental threats, hazards, and opportunities for unauthorised access.
A.7.9–A.7.14 — Assets, Storage & Utilities
Are assets off-premises protected, and are storage media managed through their lifecycle including acquisition, use, transport, and disposal?
A.7.9 requires protection of off-premises assets considering different risks of working outside the organisation's premises. A.7.10 covers lifecycle management of storage media including disposal requirements to prevent unauthorised data disclosure.
Are supporting utilities (power, telecommunications) protected, is cabling secured, and is equipment properly maintained?
A.7.11 covers protecting information processing facilities from power failures and other disruptions. A.7.12 covers protecting cabling carrying data or supporting information services. A.7.13 covers equipment maintenance, and A.7.14 covers secure disposal or re-use of equipment.
AA4

Technological Controls

Annex A.8 — User endpoints, privileged access, access restriction, secure authentication, capacity, malware, vulnerabilities, configuration, data deletion, masking, DLP, monitoring, web filtering, secure coding

A.8.1–A.8.5 — Endpoints & Access
Are user endpoint devices (laptops, mobiles, tablets) protected with appropriate security configurations and controls?
A.8.1 requires that information stored on, processed by, or accessible via user endpoint devices is protected. This includes configuration management, encryption, remote wipe capability, and endpoint protection software.
Are privileged access rights restricted and managed, with information access restrictions and secure authentication mechanisms enforced?
A.8.2 restricts privileged access, A.8.3 restricts read/write access to information based on policy, A.8.4 restricts source code access, and A.8.5 requires secure authentication including multi-factor where appropriate.
A.8.6–A.8.10 — Capacity, Malware, Vulnerabilities & Configuration
Are capacity requirements monitored and adjusted, and is protection against malware implemented with appropriate user awareness?
A.8.6 requires capacity management to ensure adequate resources. A.8.7 requires malware protection that includes detection, prevention, and recovery combined with appropriate user awareness.
Are technical vulnerabilities identified in a timely manner, evaluated, and treated, with secure configurations defined and maintained for hardware, software, services, and networks?
A.8.8 requires obtaining information about technical vulnerabilities, evaluating exposure, and taking appropriate measures. A.8.9 (new in 2022) requires configurations of hardware, software, services, and networks to be established, documented, implemented, monitored, and reviewed.
Is information deleted when no longer required, using appropriate deletion methods and tools?
A.8.10 (new in 2022) requires information stored in information systems, devices, or any other storage media to be deleted when no longer required, using secure deletion methods.
A.8.11–A.8.16 — Data Protection, Monitoring & Network Security
Is data masking applied where appropriate, and are data leakage prevention measures implemented for systems, networks, and devices?
A.8.11 (new in 2022) covers data masking in accordance with the organisation's access control policy and business requirements. A.8.12 (new in 2022) covers data leakage prevention measures applied to systems, networks, and any other devices that process, store, or transmit sensitive information.
Are activities on networks, systems, and applications monitored for anomalous behaviour, and is logging enabled and protected?
A.8.15 requires logging to record activities, exceptions, faults, and other relevant events. A.8.16 (new in 2022) requires monitoring networks, systems, and applications for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
Is web filtering applied to reduce exposure to malicious content, and are secure coding practices applied in software development?
A.8.23 (new in 2022) requires web filtering to manage access to external websites to reduce exposure to malicious content. A.8.25-8.28 cover the secure development lifecycle including secure coding principles, application security requirements, secure architecture, and secure coding practices.