ISO 27001 Requirements (Clauses 4 to 10)

These clauses are the actual requirements you are certified against. They are mandatory: you cannot exclude any of clauses 4 to 10. The Annex A controls are selected separately based on your risk assessment (clause 6.1.3).

Compliance evidence room showing ISO 27001 clauses mapped to policy, owner, evidence and review.
Clause evidence room / 13 KB WebP

The mandatory documents

The documented information ISO 27001 explicitly requires across clauses 4 to 10:

  • Scope of the ISMS (4.3)
  • Information security policy (5.2)
  • Risk assessment process (6.1.2)
  • Statement of Applicability (6.1.3)
  • Risk treatment plan (6.1.3)
  • Information security objectives (6.2)
  • Evidence of competence (7.2)
  • Documented information required by the standard and by the organisation (7.5)
  • Operational planning evidence (8.1)
  • Risk assessment results (8.2)
  • Risk treatment results (8.3)
  • Monitoring and measurement results (9.1)
  • Internal audit programme and results (9.2)
  • Management review results (9.3)
  • Nature of nonconformities and actions taken (10.2)
  • Results of corrective actions (10.2)

Get a head start with our ISO 27001 templates.

Audit-ready next steps

ISO 27001 documents, evidence, and software path

SoA, risk register, access, supplier, incident, backup, crypto, endpoint, and secure development records.