Internal Reference

ISO 27001:2022

Interactive reference covering all mandatory clauses (4–10) and all 93 Annex A controls from the current ISO/IEC 27001:2022 standard. Click any clause or control to expand its requirements.

7
Mandatory Clauses
Clauses 4–10
93
Annex A Controls
vs 114 in 2013
11
New Controls
Added in 2022
4
Control Themes
Org, People, Physical, Tech

What the mandatory clauses require

Clauses 4–10 are mandatory for every organisation seeking ISO 27001:2022 certification — there are no exceptions. Together they form the Plan-Do-Check-Act (PDCA) cycle that drives the ISMS. Annex A controls are selected and justified in the Statement of Applicability (SoA).

Key ISMS Deliverables (Certification Essentials)

Statement of Applicability (SoA)

Every Annex A control listed with applicability decision and justification

Risk Assessment Report

Documented risk assessment methodology, results, and risk register

Risk Treatment Plan (RTP)

Selected treatments, controls mapped, residual risk accepted

Information Security Policy

Top management approved; communicated to all personnel

ISMS Scope Document

Defined boundaries — systems, locations, processes, exclusions justified

Internal Audit Reports

Evidence of planned internal audit programme execution

Management Review Minutes

Top management review of ISMS performance at planned intervals

Corrective Action Records

Documented nonconformities, root cause analysis, and corrective actions

2013 → 2022 Key Changes

Controls reduced

114 controls

93 controls

24 merged, 1 deleted, 11 new added

Categories restructured

14 domains

4 themes

Org / People / Physical / Technological

Clause 6.3 added

Not present

Planning of changes

Formalises ISMS change management

Feisty Fox Logo
Feisty Fox Security

© 2026 Feisty Fox Security. Internal reference only.