Skip to content
GRC, ISO 27001 and SOC 2

ISO 27001 explained for beginners: clauses, Annex A and the ISMS

What is ISO 27001? A beginner's guide to the 2022 standard: the ISMS, clauses 4 to 10, the 93 Annex A controls in four themes, and how certification works.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

ISO 27001 (formally ISO/IEC 27001:2022) is an international standard that sets out the requirements for an information security management system, or ISMS: the policies, processes, roles and controls an organisation uses to manage information security risk in a repeatable way. An organisation can be independently audited against it and, if it meets the requirements, receive a certificate showing that its ISMS conforms to the standard.

The most important idea for a beginner is that ISO 27001 is about managing security, not about a specific technology. It doesn’t tell you which firewall to buy. It tells you to understand your risks, decide how to treat them, prove you’ve done what you said, and keep improving. If you’re heading towards a GRC role, this is the framework you’ll meet most often, and our guide to what a GRC analyst does shows where it fits in the job.

What is an ISMS, in plain English?

An ISMS is the management system around security. Think of it as the answer to “how does this organisation make sure security keeps happening, even when people leave, systems change and new threats appear?”

It usually includes:

  • A defined scope: which parts of the organisation, locations, systems and services are covered.
  • An information security policy, approved by top management.
  • A risk assessment method and a record of the risks it found.
  • A risk treatment plan: what you’ll do about each risk.
  • Controls, both technical and organisational, that carry out that plan.
  • Evidence: records, logs, training registers, meeting minutes, review notes.
  • A cycle of checking and improving: internal audits, management reviews and corrective actions.

ISO’s page for ISO/IEC 27001 describes the standard as providing requirements for establishing, implementing, maintaining and continually improving an ISMS. That last word, continually, is the heart of it. An ISMS is never “finished”.

How is ISO 27001 structured?

The standard has two parts that beginners need to understand: the clauses (the mandatory requirements for the management system) and Annex A (a reference list of security controls).

Clauses 0 to 3: the introduction

Clauses 0 to 3 cover the introduction, scope, normative references, and terms and definitions. They set context but don’t contain requirements you’ll be audited on.

Clauses 4 to 10: the requirements

These are the “shall” statements an auditor checks. Every organisation seeking certification must meet all of them; none can be excluded.

Clause Title What it asks in practice
4 Context of the organisation What internal and external issues affect your security? Who are the interested parties and what do they need? What’s in scope?
5 Leadership Does top management own the ISMS, approve the policy and assign roles and responsibilities?
6 Planning How do you assess and treat risk? What are your security objectives and how will you achieve them?
7 Support Do you have the resources, competent people, awareness, communication and controlled documentation the ISMS needs?
8 Operation Are you actually carrying out the risk assessments and treatment plans, and controlling changes?
9 Performance evaluation How do you monitor and measure? Do you run internal audits and management reviews?
10 Improvement How do you handle nonconformities, take corrective action and keep improving?

If you’ve met other ISO management system standards such as ISO 9001, this structure will look familiar. ISO uses a common high-level structure across its management system standards so organisations can run several together.

A 2024 update to know about: in February 2024, ISO published Amendment 1 to ISO/IEC 27001:2022 on climate action. It adds text so that, when an organisation looks at its context in clause 4, it determines whether climate change is a relevant issue. It’s a small change, but auditors may ask about it.

Clause 6 is where risk lives

Clause 6.1.2 requires a documented information security risk assessment process, and 6.1.3 requires a risk treatment process. For each risk, the typical treatment options are to modify it (apply controls), retain it (accept it, with justification), avoid it (stop the activity), or share it (for example, insurance or outsourcing).

Here’s what a couple of rows in a risk register might look like for a fictional company, Acme Fintech:

Risk Likelihood Impact Treatment Controls (Annex A) Owner
Staff laptop lost with unencrypted customer data Medium High Modify 8.1 User endpoint devices; 8.24 Use of cryptography IT manager
Phishing leads to compromise of finance mailbox High High Modify 6.3 Awareness, education and training; 5.17 Authentication information; 8.23 Web filtering CISO
Office flood damages paper archive Low Medium Share and modify 7.5 Protecting against physical and environmental threats; insurance Facilities lead

The ratings and treatments here are illustrative. Each organisation defines its own scales and its own risk appetite, and the auditor checks that you followed your method consistently.

What is Annex A in ISO 27001:2022?

Annex A is a list of 93 controls grouped into four themes. It’s a reference set: after your risk assessment, you compare the controls you’ve chosen against Annex A to make sure you haven’t overlooked anything.

Theme Section Number of controls Examples
Organisational 5 37 5.1 Policies for information security; 5.7 Threat intelligence; 5.23 Information security for use of cloud services
People 6 8 6.1 Screening; 6.3 Information security awareness, education and training; 6.7 Remote working
Physical 7 14 7.1 Physical security perimeters; 7.4 Physical security monitoring; 7.10 Storage media
Technological 8 34 8.5 Secure authentication; 8.13 Information backup; 8.28 Secure coding

What changed from the 2013 version?

If you read older material, you’ll see references to 114 controls in 14 domains (A.5 to A.18). That was ISO/IEC 27001:2013. The 2022 edition reorganised the controls into the four themes above, merged many of the old ones and added 11 new controls:

  • 5.7 Threat intelligence
  • 5.23 Information security for use of cloud services
  • 5.30 ICT readiness for business continuity
  • 7.4 Physical security monitoring
  • 8.9 Configuration management
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.16 Monitoring activities
  • 8.23 Web filtering
  • 8.28 Secure coding

So if a job advert or course still talks about “A.12.4 logging”, it’s using the 2013 numbering. Organisations certified to the 2013 version have had to transition to the 2022 edition, so the 2022 structure is the one to learn.

ISO 27001 vs ISO 27002

Annex A gives each control a one-line description. ISO/IEC 27002:2022 is the companion standard that explains each of those controls in detail, with purpose and implementation guidance. You certify against 27001; you use 27002 to understand how to implement the controls. Both belong to the wider ISO/IEC 27000 family.

What is a Statement of Applicability (SoA)?

The Statement of Applicability is one of the most important ISMS documents, and one that GRC beginners are often asked to help maintain. Required by clause 6.1.3, it lists every Annex A control and records:

  • whether the control is applicable,
  • why it’s included or excluded,
  • whether it’s implemented.

An extract for Acme Fintech might look like this:

Control Applicable? Justification Status
5.23 Information security for use of cloud services Yes Core platform hosted with a cloud provider Implemented
7.4 Physical security monitoring Yes Office houses network equipment Partially implemented
8.28 Secure coding Yes In-house development of customer app Implemented
8.11 Data masking Yes Production data used for support analytics Planned Q1

Excluding a control is allowed, but only with a sound justification. “We don’t write software” is a reasonable justification for excluding secure coding; “it’s too much work” is not.

How does ISO 27001 certification work?

ISO itself doesn’t certify anyone. As ISO explains, certification is carried out by independent certification bodies, and organisations can use a standard without being certified at all. When choosing a certification body, organisations usually look for one that is accredited by a national accreditation body.

A typical certification journey looks like this:

  1. Define scope and build the ISMS. Context, risk assessment, SoA, policies, controls, evidence.
  2. Run it for a while. Auditors want to see the system operating, not just documents.
  3. Internal audit and management review. Both are clause 9 requirements and must happen before certification.
  4. Stage 1 audit. The certification body reviews documentation and readiness.
  5. Stage 2 audit. The auditor tests whether the ISMS is implemented and effective, sampling evidence and interviewing staff.
  6. Certificate issued, followed by periodic surveillance audits and a recertification audit at the end of the certificate’s cycle (commonly three years).

An auditor raises nonconformities where a requirement isn’t met. Major nonconformities generally have to be resolved before a certificate is issued; minor ones need a corrective action plan.

Organisations pursue certification for several reasons: customer and partner requirements, procurement tenders, regulatory expectations, or simply as a structured way to run security. Note that ISO 27001 doesn’t replace legal obligations. In Nigeria, for example, organisations processing personal data also have duties under the Nigeria Data Protection Act, overseen by the Nigeria Data Protection Commission. An ISMS can help meet those duties, but it isn’t the same thing.

ISO 27001 vs SOC 2: a quick distinction

Beginners often confuse the two. ISO 27001 is an international standard with a certificate issued by a certification body. SOC 2 is an attestation report issued by a CPA firm under the AICPA’s framework, common with US customers. Our plain-English guide to what SOC 2 is covers it in detail. Many organisations end up doing both, and there’s a lot of overlap in the controls.

Where do beginners fit in ISO 27001 work?

Entry-level GRC staff typically work on:

  • Collecting and organising audit evidence (screenshots, logs, training records, access reviews).
  • Maintaining the risk register and following up with risk owners.
  • Updating the SoA and policy documents after changes.
  • Tracking corrective actions from internal and external audits.
  • Running or supporting security awareness training.

None of these need deep technical skills on day one, but they reward people who are organised, write clearly and can talk to both engineers and managers. Later, many people take a Lead Implementer or Lead Auditor course; our comparison of ISO 27001 Lead Implementer vs Lead Auditor explains which suits which career stage.

Try this today

Pick a small organisation you know well, such as a family business, a church office or a student society. Write down five information assets (customer list, accounts spreadsheet, email, website, payment records), one risk for each, and the Annex A control you’d pick to treat it. You’ve just done a mini risk assessment, and it’s a great thing to talk through in a GRC interview.

Questions

Is ISO 27001 a certification for people or for organisations?

ISO 27001 certification is for an organisation's ISMS. Individuals can earn personal credentials such as ISO 27001 Lead Implementer or Lead Auditor through training providers and personnel certification bodies, but that's a separate thing from an organisation being certified.

How many controls are in ISO 27001:2022?

Annex A of ISO/IEC 27001:2022 contains 93 controls in four themes: Organisational (37), People (8), Physical (14) and Technological (34).

Do you have to implement all 93 Annex A controls?

No. You select controls based on your risk assessment and justify any exclusions in the Statement of Applicability. What you can't exclude are the requirements in clauses 4 to 10.

Is ISO 27001 mandatory?

It's voluntary in general. Some customers, contracts or sector rules may require or expect it, so check the specific requirements that apply to an organisation.