ISO 27001 implementation library

ISO 27001 clause guides

Build the management-system foundations that connect context, leadership, risk, documented information, assurance and improvement.

How to use these clause guides

Each guide explains the practical outcome, implementation sequence, ownership, evidence and auditor testing for each covered ISO 27001 clause. Use the pages alongside your own licensed copy of the standard; AuditPrepared provides independent implementation guidance rather than reproducing ISO text.

Clause implementation guides

Clause 4.1 · Context of the organization

Understanding the organization and its context

Identify the internal and external conditions that can shape the ISMS, then keep that view current as the organization and its environment change.

Read the full guide →

Clause 4.2 · Context of the organization

Understanding the needs and expectations of interested parties

Determine who can affect, or is affected by, the ISMS and identify which of their legal, contractual, regulatory or business expectations need to be managed.

Read the full guide →

Clause 4.3 · Context of the organization

Determining the scope of the information security management system

Define and document the organizational and operational boundaries within which the ISMS is managed and assessed.

Read the full guide →

Clause 4.4 · Context of the organization

Information security management system

Establish, operate and continually improve an integrated management system that connects governance, risk, controls, assurance and improvement.

Read the full guide →

Clause 5.1 · Leadership

Leadership and commitment

Top management must actively direct and support the ISMS so information security becomes part of business priorities, resources and decisions.

Read the full guide →

Clause 5.2 · Leadership

Policy

Set an approved information-security direction that fits the organization and gives a stable basis for objectives and day-to-day decisions.

Read the full guide →

Clause 5.3 · Leadership

Organizational roles, responsibilities and authorities

Allocate and communicate who owns ISMS work, who can make decisions and how performance is reported to management.

Read the full guide →

Clause 6.1 · Planning

Actions to address risks and opportunities

Plan the ISMS response to uncertainty by connecting organizational context, security risk and improvement opportunities to controlled action.

Read the full guide →

Clause 6.1.1 · Planning

General

Decide how the ISMS will address relevant risks and opportunities so it can achieve intended outcomes, reduce unwanted effects and improve.

Read the full guide →

Clause 6.1.2 · Planning

Information security risk assessment

Define and apply a repeatable method for identifying, analysing and evaluating information-security risks so results remain reasonably consistent over time.

Read the full guide →

Clause 6.1.3 · Planning

Information security risk treatment

Define how evaluated risks will be modified, retained, avoided or shared, select necessary controls and document the resulting treatment decisions.

Read the full guide →

Clause 6.2 · Planning

Information security objectives and planning to achieve them

Translate policy and business priorities into clear security outcomes with ownership, resources, measures and delivery plans.

Read the full guide →

Clause 6.3 · Planning

Planning of changes

Plan material ISMS changes deliberately so responsibilities, resources, dependencies and unintended effects are understood before implementation.

Read the full guide →

Clause 7.1 · Support

Resources

Provide the people, time, technology, information and budget needed to establish, operate and improve the ISMS.

Read the full guide →

Clause 7.2 · Support

Competence

Ensure people performing work that affects information-security performance can demonstrate the knowledge, skill and judgement their roles require.

Read the full guide →

Clause 7.3 · Support

Awareness

Make sure personnel understand relevant security expectations, their contribution and the consequences of ignoring agreed requirements.

Read the full guide →

Clause 7.4 · Support

Communication

Plan what ISMS information must be communicated, when, by whom, to whom and through which reliable channel.

Read the full guide →

Clause 7.5 · Support

Documented information

Maintain the information the ISMS needs to operate and the records needed to demonstrate that work was performed and decisions were made.

Read the full guide →

Clause 7.5.1 · Support

General

Determine the documented information needed by the standard and by the organization for an effective, usable ISMS.

Read the full guide →

Clause 7.5.2 · Support

Creating and updating

Create and revise ISMS information so it is identifiable, suitable for its audience and appropriately reviewed before use.

Read the full guide →

Clause 7.5.3 · Support

Control of documented information

Protect and manage documented information throughout its lifecycle so authorized users can find reliable content when needed.

Read the full guide →

Clause 8.1 · Operation

Operational planning and control

Translate ISMS plans into controlled day-to-day work, manage planned changes and oversee relevant externally provided processes.

Read the full guide →

Clause 8.2 · Operation

Information security risk assessment

Perform risk assessments using the established method at planned intervals and when significant changes could alter the risk picture.

Read the full guide →

Clause 8.3 · Operation

Information security risk treatment

Implement the approved treatment plan, track delivery and maintain evidence that selected responses and controls are operating.

Read the full guide →

Clause 9.1 · Performance evaluation

Monitoring, measurement, analysis and evaluation

Decide what information is needed to judge ISMS performance and control effectiveness, then collect, analyse and evaluate it consistently.

Read the full guide →

Clause 9.2 · Performance evaluation

Internal audit

Use independent, evidence-based review to determine whether the ISMS conforms to planned arrangements and is effectively maintained.

Read the full guide →

Clause 9.2.1 · Performance evaluation

General

Conduct internal audits at planned intervals to provide credible evidence about whether the ISMS is implemented, maintained and working as intended.

Read the full guide →

Clause 9.2.2 · Performance evaluation

Internal audit programme

Plan and manage a risk-informed programme that defines audit frequency, methods, responsibilities, scope, criteria, reporting and follow-up.

Read the full guide →

Clause 9.3 · Performance evaluation

Management review

Enable top management to evaluate whether the ISMS remains suitable, adequate and effective and to make informed decisions about its direction.

Read the full guide →

Clause 9.3.1 · Performance evaluation

General

Run management reviews as a recurring governance process that evaluates the ISMS and directs necessary action.

Read the full guide →

Clause 9.3.2 · Performance evaluation

Management review inputs

Bring together the information management needs to evaluate change, obligations, performance, risk, audit results and improvement opportunities.

Read the full guide →

Clause 9.3.3 · Performance evaluation

Management review results

Capture management decisions about improvement, ISMS changes, resources and other actions arising from the review.

Read the full guide →

Clause 10.1 · Improvement

Continual improvement

Use evidence and learning to make the ISMS progressively more suitable, adequate and effective rather than merely maintaining its current state.

Read the full guide →

Clause 10.2 · Improvement

Nonconformity and corrective action

Respond to a failure by controlling its immediate effect, understanding why it happened, removing relevant causes and checking that the response worked.

Read the full guide →

Browse the complete clause reference

The free interactive explainer covers Clauses 4–10 with actions, evidence, audit questions and connections.

Open the ISO 27001 Clause Explainer →