ISO 27001, Explained Clause by Clause

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Rather than a checklist, it’s a structured, risk-based way of running security across your whole organisation. This breakdown walks through the seven management clauses that form the backbone of the standard, then the four control themes from Annex A. For a shorter overview, see our ISO 27001 guide.

How to read this breakdown:
In black — what the standard asks for, in plain summary.
In blue — what it actually means for your business.
In red — the risk if you leave it unaddressed.

The management system (Clauses 4–10)

1. Context of the organisation (Clause 4)

The standard: Understand your business and the people who care about your security (customers, regulators, partners), and define a clear scope for your ISMS.

What it means: You decide what the management system needs to achieve and what’s in and out of scope — you can’t protect everything to the same degree.

Risk if ignored: Without context and scope, security effort is scattered: you over-protect trivial things and miss what customers and regulators actually require of you.

2. Leadership (Clause 5)

The standard: Top management owns information security, approves the policy, and assigns clear roles and responsibilities.

What it means: Security is treated as a leadership commitment with real accountability, not just an IT side-task.

Risk if ignored: When leaders aren’t visibly behind it, security is under-funded and deprioritised — the single most common reason security programs quietly fail.

3. Planning (Clause 6)

The standard: Identify and assess your information security risks, decide how to treat each one, and set measurable security objectives.

What it means: A structured risk assessment tells you what to fix first, and why — so spending follows actual exposure.

Risk if ignored: Skip risk-based planning and you invest in the wrong controls while your biggest, most likely exposures stay wide open.

4. Support (Clause 7)

The standard: Provide the resources, skills, training, awareness, communication and documentation the ISMS needs to run.

What it means: People need the tools, competence and clear records to actually follow the policies you set.

Risk if ignored: Policies nobody is trained on or aware of live only on paper — and staff keep making the everyday mistakes that cause breaches.

5. Operation (Clause 8)

The standard: Put your risk treatment plan into practice and run the controls as ongoing, day-to-day activity.

What it means: This is where the plan becomes real, repeatable operations rather than a document.

Risk if ignored: A plan that’s written but never operationalised gives false confidence while the real-world exposure remains untouched.

6. Performance evaluation (Clause 9)

The standard: Monitor, measure, internally audit and formally review whether the ISMS and its controls are actually working.

What it means: You check effectiveness with metrics, internal audits and management reviews — not assumptions.

Risk if ignored: Without measurement, a control that has silently stopped working stays broken until a breach proves it.

7. Improvement (Clause 10)

The standard: Address nonconformities, take corrective action at the root cause, and continually improve.

What it means: When something goes wrong or a gap is found, you fix the underlying cause and get measurably better.

Risk if ignored: Skip this and you keep suffering the same incidents, because lessons are never captured or acted on.

The controls (Annex A)

The 2022 version of Annex A groups 93 controls into four themes. You select the controls relevant to your risks and justify any you leave out.

8. Organisational controls

The standard: Security policies, defined responsibilities, supplier and cloud-service security, incident management, business continuity, and threat intelligence.

What it means: These are the governance and process controls that frame everything else you do.

Risk if ignored: Gaps here — no incident-response plan, unvetted suppliers — turn a small issue into a major, drawn-out and expensive breach.

9. People controls

The standard: Background screening, security-awareness training, clearly defined responsibilities, and managing access as people join, change roles or leave.

What it means: Your staff are both your first line of defence and one of the most common ways attackers get in.

Risk if ignored: Untrained staff fall for phishing and scams; a departed employee whose accounts stay active becomes a ready-made back door.

10. Physical controls

The standard: Secure areas, equipment protection, clear-desk and clear-screen practices, and safe disposal of old media and devices.

What it means: Digital security fails the moment someone can physically walk in, plug in, or walk out with a device.

Risk if ignored: A stolen unencrypted laptop, or an unlocked server cupboard, can undo every digital safeguard you’ve invested in.

11. Technological controls

The standard: Access control and MFA, encryption, logging and monitoring, secure configuration, malware protection, backups, and secure software development.

What it means: These are the technical safeguards most people picture when they think ‘cyber security’.

Risk if ignored: Weak technical controls — no MFA, poor logging, unencrypted data — are exactly what attackers probe for and exploit first.

Certification against ISO 27001 is carried out by an accredited body through a two-stage audit and ongoing surveillance — but you don’t have to be certified to benefit from running security this way.

See how your current controls stack up — in about five minutes.