Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 10 July 2026

ISO 27001 Requirements Explained: Clauses 4–10 and 93 Controls

ISO 27001 requirements explained clearly: the management system, risk process, clauses 4 to 10 and the 93 Annex A controls.

ISO/IEC 27001 combines mandatory management-system requirements in clauses 4 to 10 with a reference set of 93 information-security controls in Annex A. The controls are not a universal shopping list. Each organisation selects necessary controls from risks, legal duties and customer requirements and records its reasoning in the Statement of Applicability.

How the standard works

The standard connects leadership, planning, operations and improvement with a risk-based security process. It covers far more than firewalls and passwords: roles, suppliers, people, physical security, documented decisions and system effectiveness are equally important.

Clauses 4 to 10 at a glance

Table 1: ISO 27001 Requirements Explained: Clauses 4–10 and 93 Controls
ClauseCore question
4 ContextWhich internal and external issues and interested parties affect the ISMS?
5 LeadershipWho owns the system, approves policy and provides resources?
6 PlanningHow are risks, opportunities, objectives and treatment managed?
7 SupportWhich competence, communication and documented information are needed?
8 OperationHow are risk assessment and treatment carried out?
9 EvaluationHow are monitoring, internal audit and management review used?
10 ImprovementHow are nonconformities corrected and the ISMS improved?

What the 93 controls mean

Annex A groups controls into organisational, people, physical and technological themes. Detailed implementation guidance is mainly provided by ISO/IEC 27002. For each control, the organisation decides whether it is necessary, how it is implemented and what evidence demonstrates effectiveness.

Controls outside Annex A may also be needed. The goal is a traceable link between risk, treatment, controls and evidence, rather than mechanically ticking a list.

Evidence auditors commonly expect

  • Approved scope and information-security policy
  • Traceable risk assessment and treatment plan
  • Statement of Applicability with clear rationale
  • Roles, competence and training records
  • Operational evidence such as tickets, logs, tests and reviews
  • Internal audit, management review and corrective actions

How Sternberg Consulting supports you

We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.

Discuss your project

Frequently asked questions

Are all 93 controls mandatory?

All must be considered. Applicability depends on risks, obligations and requirements and is justified in the SoA.

Is a document library enough?

No. Auditors test whether described processes are implemented and effective.

How is ISO 27002 different?

ISO 27001 contains certifiable requirements, while ISO 27002 gives more detailed guidance for information-security controls.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.