ISO 27001 Requirements (Clauses 4 to 10)
These clauses are the actual requirements you are certified against. They are mandatory: you cannot exclude any of clauses 4 to 10. The Annex A controls are selected separately based on your risk assessment (clause 6.1.3).

Context of the organization
Set the foundations: understand your context and interested parties, define the ISMS scope, and establish the ISMS itself.
Clause 5 · 3 sub-clausesLeadership
Top management must own the ISMS: demonstrate commitment, set the policy, and assign roles and authorities.
Clause 6 · 5 sub-clausesPlanning
The risk-based core: address risks and opportunities, run risk assessment and treatment, set objectives, and plan changes.
Clause 7 · 5 sub-clausesSupport
Provide the resources, competence, awareness, communication, and documented information the ISMS needs to run.
Clause 8 · 3 sub-clausesOperation
Run the plan: control your processes, and actually perform risk assessment and treatment.
Clause 9 · 3 sub-clausesPerformance evaluation
Check it works: monitor and measure, run internal audits, and hold management reviews.
Clause 10 · 2 sub-clausesImprovement
Keep getting better: continually improve, and handle nonconformities with corrective action.
The mandatory documents
The documented information ISO 27001 explicitly requires across clauses 4 to 10:
- ✓Scope of the ISMS (4.3)
- ✓Information security policy (5.2)
- ✓Risk assessment process (6.1.2)
- ✓Statement of Applicability (6.1.3)
- ✓Risk treatment plan (6.1.3)
- ✓Information security objectives (6.2)
- ✓Evidence of competence (7.2)
- ✓Documented information required by the standard and by the organisation (7.5)
- ✓Operational planning evidence (8.1)
- ✓Risk assessment results (8.2)
- ✓Risk treatment results (8.3)
- ✓Monitoring and measurement results (9.1)
- ✓Internal audit programme and results (9.2)
- ✓Management review results (9.3)
- ✓Nature of nonconformities and actions taken (10.2)
- ✓Results of corrective actions (10.2)
Get a head start with our ISO 27001 templates.
ISO 27001 documents, evidence, and software path
SoA, risk register, access, supplier, incident, backup, crypto, endpoint, and secure development records.