Anyone opening the standard for the first time finds a document that is short, dense and written in a style that assumes you already know the vocabulary. This page has ISO 27001 clauses explained in ordinary language, clause by clause, with the evidence an auditor will actually ask to see.
The standard has ten clauses. Clauses 1 to 3 cover scope, references and terms, and carry no requirements you can be audited against. The requirements sit in Clauses 4 to 10, and all seven are mandatory. You cannot exclude one because it feels heavy or because your organisation is small.
With the ISO 27001 clauses explained properly, one pattern becomes clear: each clause produces records, and those records are what certification is built on. A control that works but leaves no trace cannot be audited. This page covers what each clause asks for and where teams most often slip.
If you need the wider picture first, the information security management system pillar explains how these clauses fit into a working ISMS.
Clause 4: Context of the Organisation
This clause sets the boundaries. You identify internal and external issues that affect information security, list interested parties and their requirements, then define the ISMS scope.
Interested parties are wider than most teams expect. Customers, regulators, employees, cloud providers and shareholders all belong on the list if their expectations affect your security decisions.
The scope statement is the output that matters most. It names which locations, business units, systems and services the ISMS covers, and which are excluded. Auditors read it first because it defines what they are entitled to examine.
Common slip: writing a scope so broad that nothing inside it is fully controlled. A narrower scope that genuinely works certifies faster.
Clause 5: Leadership
Top management must show involvement, not just approval. That means allocating resources, integrating security requirements into business processes and holding people accountable.
Three outputs sit here: the information security policy, assigned roles with defined authority, and evidence that leadership is engaged. Management review minutes, approved budgets and signed policies all serve as proof.
Auditors frequently interview senior managers directly. If a director cannot describe the organisation's security objectives, the clause is weak regardless of the paperwork.
Clause 6: Planning
This is the heaviest clause and the one that shapes everything else.

Risk Assessment and Risk Treatment
You must define a risk assessment method that is repeatable, apply it, and record the results. Then you select treatment options, choose controls, and compare your selection against Annex A to check nothing has been missed.
Two documents come out of this: the Statement of Applicability and the risk treatment plan. The Statement of Applicability lists every Annex A control with a decision to include or exclude, plus justification. Sound information security risk management is what makes these documents defensible rather than decorative.
Objectives and Planning of Changes
Security objectives must be measurable, resourced and assigned. "Improve security awareness" fails. "Achieve 95 percent training completion within 30 days of joining" works.
The 2022 version added a requirement to plan changes to the ISMS rather than making them informally.
Common slip: assessing risk once and never revisiting it. Risks move when systems, vendors and staff move.
Clause 7: Support
Four areas sit under this clause: resources, competence, awareness and communication, plus documented information.
Competence means proving that people doing security work are capable of it. Certificates, training records and experience summaries all count.
Awareness is different. Every employee within scope needs to understand the policy, their own contribution and the consequences of not following it. This is tested through interviews, not documents.
Documented information covers control of your records: approval, version, distribution and protection from unauthorised change. Weak document control is one of the most common sources of minor findings, usually through outdated policies still in circulation.
Want to see how these records connect in one place? Get a Free Personalized Demo and walk through a live risk register and Statement of Applicability.
Clause 8: Operation
Clause 8 asks you to run what you planned and keep proof.
Three sub-clauses apply. Operational planning and control requires documented processes and control of outsourced activities. Then the risk assessment must be performed at planned intervals and after significant change. Finally, the risk treatment plan must be implemented, with records retained.
This clause is where the gap between paper and practice shows up. A documented access review process with no completed review records fails here, even if the process itself is well written.
Common slip: outsourced processes left undocumented. If a supplier handles data within your scope, their controls fall under your responsibility.
Clause 9: Performance Evaluation
Monitoring, Measurement, Analysis and Evaluation
You decide what to measure, how, when and by whom. The standard does not prescribe metrics, but it does require that your chosen measures produce valid, comparable results.
A short set reviewed monthly beats twenty measures collected once. Incident containment time, overdue risk treatments and training completion are practical starting points.
Internal Audit
An internal audit programme must cover the full ISMS, run at planned intervals, and be carried out by people independent of the area being audited. You need the programme, the criteria, the results and the follow-up actions.
At least one complete internal audit cycle must finish before your certification audit. Understanding how the ISO 27001 audit process works helps teams prepare the right evidence.
Management Review
Leadership reviews the ISMS at planned intervals. The standard lists required inputs including audit results, risk status, objective performance, incident data and improvement opportunities.
Common slip: a review that discusses only incidents. Missing inputs are an easy finding for an auditor to raise.
Clause 10: Improvement
The 2022 version reordered this clause so continual improvement comes first, followed by nonconformity and corrective action.
When something goes wrong, you react to it, evaluate whether the cause could recur elsewhere, act on the cause, and check the action worked. Records of the nonconformity and the outcome are mandatory. A structured corrective action plan turns this from a paperwork chore into something that actually reduces repeat problems.
Common slip: correcting the symptom without addressing the cause. The same finding then appears at the next surveillance audit.
How the Clauses Connect
Reading them in isolation hides the logic. Clause 4 sets the boundary. Clause 5 provides authority. Clause 6 identifies what needs protecting and decides how. Clause 8 does the work. Clause 9 checks it. Clause 10 fixes what the check found, and the cycle restarts.
This is the Plan-Do-Check-Act structure shared with ISO 9001, ISO 14001 and ISO 45001. Organisations already running an integrated management system can reuse existing document control, audit and management review processes rather than duplicating them.

Keeping Clause Evidence Audit-Ready
Every clause generates records that must stay current across a three-year certification cycle. Spreadsheets handle the first year. By the second surveillance audit, version confusion and missed review dates usually creep in.
ISMS software links the risk register, Statement of Applicability, policies, training logs, audit findings and corrective actions so each clause has traceable evidence with reminders and version history. Effivity supports ISO 27001 alongside ISO 9001, ISO 14001, ISO 45001 and ISO 22000 in one platform.
Try Effivity for Free and map your clause evidence in a single afternoon.
Frequently Asked Questions
The standard has ten clauses. Clauses 4 to 10 contain auditable requirements, while Clauses 1 to 3 cover scope, references and terms.
Yes. Clauses 4 to 10 must all be met. Only Annex A controls can be excluded, with justification recorded.
Clause 6 covers risk assessment and treatment. Clause 8 requires you to repeat the assessment at planned intervals and after major change.
Clauses define how the management system runs and are mandatory. Annex A lists 93 reference controls selected based on your risk assessment.
Clause 9 findings are common, usually incomplete internal audit coverage or management reviews missing required inputs.