Annex A gets the attention, but the mandatory requirements of ISO 27001 live in Clauses 4 to 10 — the management-system core. You can't be excluded from these the way you can exclude an Annex A control; every certified ISMS must satisfy all of them. This hub walks through each clause, plus the three foundational activities they demand: defining your interested parties, setting your scope, and building your Statement of Applicability.
← Back to ISO 27001: The Complete Guide
The seven clauses
Clause | Guide | Covers |
|---|---|---|
4 | Internal/external issues, interested parties, scope, the ISMS | |
5 | Top-management commitment, policy, roles | |
6 | Risk assessment/treatment, SoA, objectives, change planning | |
7 | Resources, competence, awareness, communication, documented information | |
8 | Operational planning, running the risk assessment and treatment | |
9 | Monitoring, measurement, internal audit, management review | |
10 | Continual improvement, nonconformity, corrective action |
The foundational activities
Guide | Why it matters |
|---|---|
Clause 4.2 — the requirements your ISMS must meet | |
Clause 4.3 — the single most consequential early decision | |
Clause 6.1.3 — the bridge from risk to controls | |
Clause 9.3 — how leadership stays engaged | |
Clause 5.3 — who is accountable for what |
